A breach notification is worth reading closely, not skimming past: it tells you what data categories were exposed, the incident's timeline, and what help the company is offering — and those three facts decide everything you should do next. Most letters follow a template shaped by state breach-notification laws, which means the load-bearing details hide in predictable places. Your actions scale with what was taken: a leaked email address means watchful waiting; a leaked Social Security number means credit freezes at all three bureaus.
What must a notification contain?
All fifty states have breach-notification laws requiring companies to tell affected residents when unencrypted personal information is exposed — typically name plus data elements like Social Security number, driver's license, or financial account details, with deadlines that vary by state (often 30-60 days from discovery). The letter usually includes: what happened and when, the categories of data involved, the number of individuals affected (sometimes), what the company is doing, and remediation offers such as credit monitoring. Federal sectoral rules add healthcare (HIPAA) and payment-specific paths. Boilerplate paragraphs about the company's commitment to security are exactly that — skip to the facts.
Step 1: Identify what data was actually taken
The action ladder:
- Email address and account details only: expect phishing that references the service. Change that password, enable MFA, and watch for scams mentioning the breach. No catastrophe.
- Passwords (even hashed): change that password now, and everywhere it was reused. Hashing slows attackers; common passwords still fall to cracking given time.
- Payment card data: rare in modern breaches (PCI controls work), but if announced, watch statements, and let the issuer replace the card — zero-liability rules make this the most recoverable category.
- Social Security number: the serious tier. Freeze your credit at Equifax, Experian, and TransUnion; file your taxes early; consider an IRS IP PIN; take the offered monitoring. SSNs cannot be replaced, so the freeze stays indefinitely.
- Health or insurance records: long-lived and fraud-prone; review insurance statements for services you never received and request your medical records periodically.
Step 2: Read the timeline skeptically
Notifications legally can arrive weeks after discovery — companies investigate, notify regulators, and sometimes delay under law-enforcement request. The letter should state when the incident occurred and when it was discovered; a months-long gap between the two is a genuine red flag about the company's detection, and a reason to treat the offer of one or two years of credit monitoring as inadequate against multi-year SSN exposure (renewal is usually possible at your own cost, and freezes are free forever).
Step 3: Decode the offer
Free credit monitoring is the standard peace offering, typically one to two years through a monitoring firm. Accept it when offered — it costs you a registration — but understand what it is: alerts about new-account activity, useful but reactive. It does not replace a credit freeze, which prevents rather than reports. If the letter includes a claims deadline for a class settlement, note it; those letters arrive separately from breach notifications and easy money is left unclaimed constantly. Beware the follow-on scam wave too: phishers send fake "breach notification" emails with enrollment links that harvest exactly what the breach exposed — enroll only through the printed letter's address or the company's own domain typed by hand.
Step 4: Match your actions to your risk
For a typical notification with an exposed SSN:
- Freeze credit at all three bureaus (about 30 minutes, free).
- Change the affected service's password and any reuse; enable MFA.
- Accept the monitoring offer for the alert layer.
- File early taxes next season and consider the IRS IP PIN.
- Set a calendar note for 6-12 months out — fraud attempts on old breach data spike long after news coverage dies.
What if the notification is vague?
Letters sometimes say "data categories may have included" — hedging that means the investigation was incomplete at mailing time. Treat the worst plausible reading as the working assumption, check the company's breach-information page for updates, and if the data involved credentials or SSNs, act rather than wait for a clarifying letter that may never come. And if the "breach notification" arrives only by email with no company letterhead, postal follow-up, or regulator filing, treat it as phishing until proven otherwise — the single most common scam wearing this costume is the fake breach letter itself.
For more context, read How to shop online safely: card hygiene, fake shops, and the checkout checklist.
For more context, read personal security checklist.

