A breach notice tells you where to start, not what has been taken. An exposed address is a different problem from an exposed password, active session, payment card, or identity document. Match the response to the data named in the notice.
Triage the exposure first
| What may be exposed | Do this first | What it does not prove |
|---|---|---|
| Email address only | Expect targeted phishing; verify messages through the service directly | It does not prove mailbox access |
| Reused or exposed password | Change it at the affected service and every place it was reused | It does not revoke existing sessions everywhere |
| Active session, reset token, or recovery code | Use the service’s sign-out/revoke controls, replace recovery material, and contact official support if scope is unclear | Changing a password alone may not end every session |
| Payment-card data | Contact the issuer through a trusted channel and review transactions | It does not prove a charge is fraudulent without checking the account |
| Government identifier or identity record | Follow the official identity-theft process for your country | US-specific remedies do not apply everywhere |
| Private messages or sensitive files | Preserve the notice and assess who could be affected before deleting evidence | It does not tell you the full audience or retention of copies |
If you cannot tell which row applies, start with the more protective path and ask the affected service what it can revoke.
Verify the notice without feeding a second attack
Do not sign in through a link in an unexpected breach email. Instead:
- Find the organization using a saved bookmark, a manually typed address, or a trusted app.
- Check its security notices, account messages, and support instructions there.
- Compare the notice with the organization’s known contact and domain. Do not rely on a logo or display name.
- Never provide a password, one-time code, recovery phrase, or payment detail to “confirm” the breach.
- Save the original message and headers when the event may involve fraud, workplace records, harassment, or legal reporting.
A real breach notice and a phishing email can arrive close together. The safest response path is the same: begin from the service, not from the message.
The first hour
0–10 minutes: contain access. Change an exposed or reused password from the official service. Review active devices and sessions. If the service offers sign out everywhere or token revocation, use it. Do not assume that a new password automatically invalidates every cookie, API token, remembered device, or recovery code.
10–25 minutes: restore the account boundary. Check the recovery email, phone number, MFA methods, forwarding rules, delegates, and connected applications. Remove anything you do not recognize. Add MFA where available; use a passkey or security key when the service supports it, with a protected fallback method.
25–40 minutes: follow the data trail. Look for password reuse, suspicious transactions, new account changes, and messages sent from the affected account. Change credentials in priority order: mailbox and identity provider first, then financial, work, health, and other accounts that reused the credential.
40–60 minutes: preserve and monitor. Keep the breach notice, case number, timeline, screenshots, and transaction records. Watch for reset requests, fake support, delivery failures, and messages that mention the incident to create urgency.
For prevention and address separation, read the complete email privacy guide. Treat a breach-themed message as untrusted until you verify it through the affected service’s own app or saved address.
Check breach databases with the right expectation
A breach-notification service can show whether an address appears in incidents loaded into its database. It cannot prove that an address has never been exposed, identify every record held by every company, or confirm that your mailbox was accessed. Treat a match as a reason to inspect the named service and data classes, not as proof of takeover.
When to escalate
Contact the service’s official support team when you see account changes you did not make, cannot revoke a session, lose access to MFA, or cannot determine what a token represented. Contact your card issuer for suspicious payment activity. For identity documents or government numbers, use the official process for your jurisdiction. If someone faces immediate safety risk, harassment, or extortion, preserve evidence before engaging and use an appropriate local support or reporting route.
After the incident
Give every account a distinct password. Protect the mailbox that receives resets with its own strong credential, MFA, current recovery details, and a review of forwarding and connected-app access. Close unused accounts only after saving records and checking recovery dependencies. The email aliases vs temporary email guide explains where address separation can reduce future exposure; it cannot repair a compromised account or make a risky service trustworthy.