What a Data Breach Notification Actually Means, and What to Do Next — Digital Moat
Digital Moat · Deep Dive

What a Data Breach Notification Actually Means, and What to Do Next

These emails are common and often vague. Here's how to judge real severity, and exactly what to do based on what was actually exposed.

At some point, nearly everyone gets an email that starts with some version of "we recently discovered unauthorized access to our systems." These notifications are common enough that it's easy to develop a kind of numbness to them — but they range from genuinely low-stakes to seriously urgent, and the notification itself often doesn't make that difference obvious.

What companies are actually required to tell you

Breach notification requirements vary by state and by the type of data involved, but the general pattern is similar: companies are typically required to disclose that a breach occurred and, in general terms, what categories of data were involved. What they're often vague about is scope and specifics — exactly how the breach happened, how many records were taken, and sometimes even which of your specific data was included versus other categories mentioned in the notice. Reading the notice carefully for what data type is actually named is the first real step.

How to judge real severity

Not all exposed data carries the same risk. Here's a rough framework for reading a notification and judging how urgently to act:

Lower Urgency
Email address only, or a hashed/encrypted password

Still worth a password change on that account as good hygiene, but a properly hashed password (one the company can't read even internally) is far less exploitable than one stored in plain text.

Moderate Urgency
Plaintext password, or a password reused elsewhere

Change that password immediately, and change it anywhere else you reused it — this is exactly the scenario credential-stuffing attacks rely on.

High Urgency
Social Security number, financial account details, or government ID

This category warrants stronger action — credit monitoring, and seriously considering a credit freeze, covered below.

A next-steps checklist, scaled to severity

For any breach involving a password: change it immediately, and change it anywhere else you reused the same one. This is also a good moment to move that account into a password manager if it isn't already, so this specific problem doesn't recur.

For any breach involving financial or identity data: consider a credit freeze, which restricts access to your credit report and makes it much harder for someone to open new accounts in your name. It's free, reversible, and one of the most underused protective steps available — mainly because it takes a few minutes of setup most people put off.

In either case: turn on multi-factor authentication for the affected account if it isn't already active, and keep an eye on account activity for the following few months rather than assuming the risk ends the day you read the notice.

If you're in the middle of an active, unfolding situation — money missing, accounts you don't recognize, signs of active identity theft right now — that's a different, more urgent scenario than a routine notification. Our companion article, "The First 60 Minutes After You Think Your Identity Has Been Stolen," is built specifically for that moment.
Where This Applies
Want to know before the notification even arrives?
Breach monitoring services alert you the moment your info shows up in a leak — see how Aura, LifeLock, Identity Guard, and IDShield compare.
See the comparison →

Digital Moat may earn a commission if you subscribe through links on this site, at no additional cost to you. See our Affiliate Disclosure for details.
Haven't checked your own Digital Moat Score yet? Take the free 2-minute assessment →