Last updated: September 12, 2026

What Should You Do If Your Information Is in a Data Breach?

Change the password on the breached account and anywhere you reused it, turn on two-factor authentication, and freeze your credit if identifying information like a SIN or Social Security number was exposed. Then watch for phishing messages that reference the breach by name. Those four steps cover most of your real risk.

Everything below explains how to do each one properly, which steps are worth your time, and which widely repeated advice does nothing.

The short version

  1. Confirm the breach is real and find out what was exposed.

  2. Change the password on that account, and on every account where you reused it.

  3. Turn on two-factor authentication, ideally an app or a passkey rather than SMS.

  4. Freeze your credit if identity data was exposed. It is free.

  5. Lock your phone number against SIM swapping if your mobile number was in the leak.

  6. Watch your statements and set up alerts.

  7. Expect a wave of scams that name the breach. Treat every one of them as hostile.

If you only have ten minutes, do steps 2, 3 and 4.

Why this keeps happening to you

This is not a rare event, and it is not a sign you did something wrong.

The Identity Theft Resource Center, a US non-profit that has tracked publicly reported breaches since 2005, recorded 3,322 data compromises in 2025, a record and a 79 percent jump over five years. Financial services was the most-breached sector with 739 incidents, followed by healthcare with 534 and professional services with 478. ITRC president James E. Lee described the pattern as attacks that are "more precise, more automated and more difficult to detect."

The more troubling trend for you as a consumer is disclosure. Seventy percent of breach notices in 2025 gave no information about how the attack happened, up from 65 percent in 2024 and 45 percent in 2023. Companies increasingly tell you that something happened without telling you what. That shifts the burden of assessing your own risk onto you, which is exactly why a checklist like this one matters.

On the company side, IBM's Cost of a Data Breach Report 2026 puts the global average breach cost at USD 4.99 million, a 12 percent increase and a record high. Those numbers explain why breached organizations lawyer up before they email you, and why the notice you receive is usually vague.

How do I know if my information was actually in a breach?

Check Have I Been Pwned, a free service that lets you search your email address or phone number against known breach datasets. It was built in 2013 by Australian security researcher Troy Hunt and is used by security teams and national governments, including through a free service for government domains.

Enter your email address. Do not enter your password into any breach-checking site. Have I Been Pwned has a separate password tool that uses a partial-hash method so your full password never leaves your device, but as a general habit, a site asking for your actual password is a site to walk away from.

Two limits worth understanding:

  • A clean result is not a guarantee. The service indexes known, publicly disclosed breaches. Credentials often circulate privately among criminals for months before a dataset surfaces.

  • It tells you the breach, not the damage. Knowing your address was in a 2023 retailer breach does not tell you whether anyone has used it.

You can also subscribe to alerts so you find out the next time your address appears, rather than finding out from a news story.

Is the notification email I received real?

Fake breach notices are one of the most effective phishing lures in circulation, because they arrive when you are already expecting one.

The tell: a legitimate breach notification does not require you to log in through a link in the email. Real companies say what happened, what was taken and what they are doing. They may offer monitoring, but the sign-up flow should be something you can reach by typing the company's domain into your browser yourself.

If you get a notice, open a new tab, go to the company's website directly, and look for the incident notice there. If there isn't one, you have your answer.

What was exposed, and how bad is it?

Not all breached data carries equal risk. Sort what was taken into three tiers.

Tier 1: low direct risk, high phishing value. Name, email address, phone number, postal address, purchase history. None of this lets someone take over an account or borrow money in your name. All of it makes the next phishing message far more convincing. A scam text that already knows your name, your city and what you bought last month clears most people's suspicion filter.

Tier 2: account takeover risk. Passwords (hashed or otherwise), security question answers, session tokens, account numbers. This is the tier that requires action today. Attackers take username-and-password pairs from one breach and try them in bulk against other sites, a technique called credential stuffing. It works because password reuse is common.

Tier 3: identity theft risk. Social Insurance Number, Social Security number, date of birth, driver's licence number, passport number, banking details, health or medical records. This tier is the reason credit freezes exist. Unlike a password, you cannot change your SIN or your date of birth.

ITRC found that breaches involving Social Security numbers have climbed sharply as criminals shift toward static identifiers. Static is the operative word. A stolen SIN stays useful to a fraudster for decades, which is why the response to Tier 3 is structural rather than a one-time cleanup.

If the notice doesn't tell you which tier applies, contact the company and ask directly what data elements relating to you were involved. In Canada, you have a right to that answer.

What do I do in the first hour?

Change the password, and follow the reuse

Change the password on the breached account first. Then change it everywhere you used that same password or a close variation of it.

That second part is the one people skip, and it is the one that matters most. Attackers automate the reuse check. If your gym app password was also your email password, the gym breach is now an email breach.

A useful distinction from NIST, the US National Institute of Standards and Technology, in its Special Publication 800-63B digital identity guidelines: passwords should be changed when there is evidence of compromise, not on a fixed schedule. Forced 90-day rotations push people toward predictable patterns. A breach is evidence of compromise. This is precisely the moment to change.

Priority order for the reuse sweep:

  1. Your primary email account. It is the reset mechanism for everything else.

  2. Banking and financial accounts.

  3. Anything holding payment details or a stored card.

  4. Social media and cloud storage.

  5. Everything else.

If you cannot remember where you reused a password, that is the argument for a password manager. Most will audit your saved logins and flag reused and breached credentials in one pass.

Turn on two-factor authentication

Two-factor authentication means a password alone isn't enough to get in. A second factor is required, usually a code or a tap.

Not all second factors are equal:

  • Passkeys or hardware security keys are the strongest option, because they are phishing-resistant. A fake login page gets nothing usable. NIST's current guidance formally recognizes passkeys as legitimate authenticators.

  • Authenticator apps generate codes on your device. Strong, widely supported, free.

  • SMS codes are better than nothing and much better than no second factor. They are also the weakest option, because a phone number can be hijacked. NIST removed SMS one-time passcodes from the methods that satisfy its AAL2 assurance level.

Start with your email and financial accounts. Every major platform has this under account settings, usually labelled "security" or "sign-in."

Check for sessions and devices you don't recognize

Most major services have a security page listing active sessions and logged-in devices. Sign out of everything you don't recognize, then change the password again so the old sessions can't be re-established. Check for forwarding rules on your email while you're there. A mail rule quietly copying your inbox to an attacker is a common, and commonly missed, persistence trick.

Should I freeze my credit?

If Tier 3 data was exposed, yes. A credit freeze is the single most effective preventive step available to an individual, and it is free.

A freeze, sometimes called a security freeze or credit lock, blocks lenders from pulling your credit file. Most lenders will not approve a new account without pulling a file, so a freeze stops new credit being opened in your name. It does not affect your credit score, and existing creditors can still access your file and report activity as normal.

In Canada

Availability depends on your province, and it changed meaningfully in 2026.

Ontario. Free credit freezes became available to Ontario residents on July 1, 2026, under the province's Better for Consumers, Better for Businesses Act (Bill 142). Equifax Canada launched its Credit Lock product for all Ontario residents on that date, having run the same functionality for Quebec since 2023. Ontarians can place, remove or suspend the lock through the myEquifax platform, by phone or by mail. Ontario's law applies to TransUnion as well, though TransUnion has until July 1, 2027 to meet the security freeze suspension requirements. Place a freeze at both bureaus and confirm status with each, since lenders may pull from either.

Quebec. Equifax and TransUnion have been required to offer free credit freezes to Quebec residents since February 2023 under the Credit Assessment Agents Act (Bill 53). Requests made online or by phone take effect immediately and have no expiry date; requests by mail can take up to 30 days.

British Columbia. The province has announced consumer-protection amendments that would require credit reporting agencies to place a security alert or freeze on request, which the government has said would bring B.C. in line with Quebec and Ontario. Check current status before assuming it is live.

Everywhere else. No freeze is available yet. Your options are fraud alerts at both Equifax Canada and TransUnion Canada, which are free. Be realistic about what they do: an alert flags your file and instructs lenders to verify identity, but it does not block a pull. Legislation in Ontario, Manitoba and New Brunswick requires lenders to take reasonable steps to verify identity when an alert is present; elsewhere, compliance is voluntary. A CBC Marketplace investigation found alerts performed inconsistently in practice. Place them anyway. They raise the bar. Just don't treat them as a wall.

Note that Experian does not operate a consumer credit bureau in Canada. Equifax and TransUnion are the two files that matter.

In the United States

Freezes are free nationwide at all three bureaus. Under a 2018 federal law, you can freeze and unfreeze your credit file for free, including free freezes for children under 16. You must contact all three bureaus separately: Equifax, Experian and TransUnion. A freeze requested online or by phone must be placed within one business day, and a lift requested online or by phone must be actioned within one hour. A fraud alert only requires contacting one bureau, which then notifies the other two.

If fraud has already occurred, report it at IdentityTheft.gov, the FTC's official recovery site, which generates an Identity Theft Report and a personalized recovery plan you can use to dispute fraudulent accounts.

Watch for the lock-versus-freeze upsell

Some bureaus market a "lock" product bundled into a paid monitoring subscription. In the US, the statutory freeze is free and governed by federal law. If you asked for a freeze and were routed to a paid subscription, you were sold a different product with weaker guarantees. Ask again for the free security freeze.

What if my SIN or Social Security number was exposed?

This is where most advice goes wrong, so read this section carefully.

Do not apply for a new SIN. Employment and Social Development Canada, which administers the program, does not recommend it. ESDC spokesperson Saskia Rodenburg told CBC that "Having multiple SINs can increase fraud risk," adding that a new SIN does not erase the old one or protect it from future abuse. Your old number stays in every database it was ever entered into. You end up managing two identities instead of one.

What to do instead, per Service Canada and the Office of the Privacy Commissioner:

  • File a police report. It creates a record you will need later.

  • Contact both credit bureaus and place a freeze or fraud alert.

  • Contact the Canada Revenue Agency to secure your CRA account, since tax-refund fraud is a common downstream use.

  • Report to any affected government programs.

  • Pull your credit report from both bureaus and check for employers you never worked for and accounts you never opened.

Service Canada's guidance on a compromised SIN is the authoritative reference.

Scale note: Canadians reported losing more than $704 million to fraud in 2025, bringing reported losses since 2022 past $2.4 billion, and only an estimated 5 to 10 percent of incidents are ever reported. Identity fraud was the single most-reported fraud type, with 8,403 cases. The real figure is several times the reported one.

In the US, the equivalent move is a freeze at all three bureaus plus an IdentityTheft.gov report, and, if tax fraud is a concern, an IRS Identity Protection PIN.

What if my phone number was exposed?

An exposed mobile number raises your risk of SIM swapping, where an attacker convinces your carrier to move your number to a SIM they control. Your phone loses service, and every SMS code, including password resets, goes to them.

Two things to do:

  1. Enable your carrier's port-out lock or number lock. All major carriers now offer a free account-level protection that blocks number transfers and SIM changes until you turn it off. Names vary by provider. Ask for "port-out protection" or "number lock" and confirm it is active.

  2. Set a strong, unique account PIN with the carrier. Do not reuse a banking PIN. Do not use a date anyone could look up.

Then move your most sensitive accounts off SMS two-factor and onto an authenticator app or passkey. If SMS is your only second factor and your number is hijacked, the second factor is now the attacker's.


What if payment card or banking details were exposed?

Card numbers are the least alarming item on the list, because the fix is mechanical and the liability protections are strong. Call your bank, report the exposure, and ask for a replacement card. Most issuers will do this without argument.

Bank account and transit numbers are more awkward, since changing an account number means updating every direct deposit and pre-authorized payment. Talk to your bank about what monitoring or account-level protections they can apply before you decide to move accounts.

Either way, turn on transaction alerts. Fraud on a payment card frequently begins with a small test charge, often a few dollars at an unfamiliar merchant, to confirm the card is live before larger charges follow. An alert on every transaction catches that test.

Is the free credit monitoring worth taking?

Take it, because it costs nothing, but understand what you are getting.

Credit monitoring is detection, not prevention. It tells you after someone has tried to use your identity. A freeze is preventive: it stops the attempt. If you have to choose one, choose the freeze.

Two additional cautions. Monitoring offers usually expire after 12 or 24 months, while a stolen SIN stays useful indefinitely, so don't treat the offer as the end of the matter. And a CBC Marketplace test found Canadian bureau monitoring services to be inconsistent in practice.

Enrol, set a calendar reminder for when the coverage lapses, and rely on the freeze for the actual protection.

What scams should I expect after a breach?

A predictable second wave follows every large breach, and it is often more damaging than the breach itself.

Fake breach notifications. Emails or texts claiming to be from the breached company, with a link to "verify your account" or "claim your free monitoring." The tell: real breach notices don't ask you to log in through an emailed link.

Recovery and refund scams. Someone contacts you offering to recover money you lost or remove your data from the dark web, for a fee. Fraudsters also impersonate the Canadian Anti-Fraud Centre itself, claiming to investigate your case or recover your funds while requesting personal and financial information. The CAFC does not operate that way.

Government impersonation. In Canada, this usually means CRA or Service Canada messages claiming your SIN has been compromised, offering to replace it, or threatening to lock or cancel it. Service Canada explicitly lists these as scam indicators, because none of those things are how the agency operates.

Voice and video impersonation. IBM's 2026 report documents a 56 percent increase in AI-driven attacks, led by AI deepfake impersonations and AI-enabled malware. A caller who knows your name, address, recent purchases and which breach you were in is no longer implausible. Breached data is the raw material for that credibility.

The general rule that survives all of these: end the inbound contact and initiate a new one yourself, through a number or address you looked up independently. Legitimate organizations will never object.

What if I'm the business owner and my company was breached?

Your obligations are legal, not optional, and the clock starts immediately.

In Canada, organizations subject to PIPEDA, the federal private-sector privacy law, must report to the Office of the Privacy Commissioner any breach of security safeguards that poses a real risk of significant harm, notify affected individuals and relevant third parties, and keep records of all breaches regardless of whether they meet that threshold. Breach records must be retained for 24 months. PIPEDA defines significant harm broadly, including humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on the credit record, and bodily harm.

The OPC published a real risk of significant harm assessment tool in March 2025 to help organizations work through the analysis.

The operational trap is timing. Both the OPC report and the individual notification run "as soon as feasible." Do not hold the customer notice until the forensic picture is complete. Notify on the facts you have, then follow up.

In the US, breach notification is governed by state law plus sector rules, and the FTC's Data Breach Response: A Guide for Business is the standard starting reference. It includes a model notification letter.

Practically, in the first 24 hours: secure the affected systems and revoke credentials, preserve logs before anything is rebuilt, bring in legal counsel and forensics, and decide on notification timing with counsel. If you don't have a written plan for this, build one before you need it.

image 12

How long does the risk last?

Longer than the news cycle.

Data from a breach circulates for years. Some datasets surface publicly months or years after the incident. Others are traded privately and never surface at all. Stolen identifiers that cannot be changed, SIN, date of birth, address history, retain their value indefinitely.

The practical implication is that your response should shift from a burst of activity to a low-effort steady state:

  • Leave the credit freeze on as your default. Lift it temporarily when you apply for credit, then re-freeze. Both actions are free.

  • Check your credit report periodically. Ontario's reforms include guaranteed free monthly electronic reports and scores; in the US, weekly free reports are available through AnnualCreditReport.com.

  • Keep breach alerts running on your email addresses.

  • Keep transaction alerts on.

That is perhaps 20 minutes of setup and near-zero ongoing effort.

What doesn't help

Five things people reach for that do not earn their effort:

Applying for a new SIN or Social Security number. Covered above. It creates problems rather than solving them.

Changing your email address. Your address is the least sensitive item in most breaches, and abandoning it costs you access to account recovery across dozens of services.

Paying a service to remove your data from the dark web. Data cannot be recalled once copied. Legitimate services monitor for appearances; they cannot delete. Treat "removal" claims as a marketing artifact.

Assuming it's hopeless. "My data's already out there" is the most expensive sentence in personal security. It is true that some of your data is exposed. It is not true that this makes a credit freeze pointless. The freeze blocks the fraud attempt regardless of how the fraudster got your details.

Rotating all your passwords every 90 days. NIST abandoned this recommendation because it produces predictable variations. Change on evidence of compromise, use unique passwords everywhere, and let the password manager carry the memory burden.

Frequently asked questions

Is it safe to type my email address into Have I Been Pwned?

Yes. Checking an email address is the intended use of the service, which is free, requires no account, and is used by security teams and multiple national governments. Never enter your actual password into any breach-checking site. Have I Been Pwned's separate password tool uses a partial-hash method so your full password is never transmitted.

Does freezing my credit hurt my credit score?

No. A freeze restricts who can pull your file. It does not change the contents of the file or how the score is calculated. Equifax Canada states explicitly that Credit Lock does not affect credit score calculations. Your existing creditors continue to report activity normally, so your score can still move up or down as usual.

How do I apply for a mortgage or car loan with a freeze on?

Lift or suspend the freeze before you apply, then re-place it afterward. In the US, bureaus must action an online or phone lift within one hour. In Canada, Quebec and Ontario residents can suspend and re-place through the bureau's online portal. Lifting and re-placing are both free, so the process is designed to be repeatable. Ask the lender which bureau they pull from if you want to lift only one.

What is credential stuffing, and why does password reuse matter so much?

Credential stuffing is when attackers take username-and-password pairs stolen from one breach and automatically try them against hundreds of other sites. It requires no skill and costs almost nothing. It works because reuse is widespread. This is why a breach at a service you barely use can end with your email account compromised, and why the reuse sweep is the highest-value step in this guide.

My data was breached. Can I sue, or join a class action?

Class actions do follow large breaches in both Canada and the US, and if one is certified for an incident that affected you, you may be eligible. Payouts are typically modest and arrive years later. Treat it as a footnote, not a remedy. Your protection comes from the freeze and the account hardening, not the litigation. This is general information, not legal advice; if the exposure caused you concrete financial harm, talk to a lawyer in your jurisdiction.

The company said the passwords were "hashed." Am I fine?

Not necessarily. Hashing converts a password into a fixed-length value that is difficult to reverse. How difficult depends entirely on the algorithm. Modern algorithms designed for passwords hold up well. Older, fast algorithms can be cracked at enormous scale, particularly for short or common passwords. Companies rarely specify which they used. Assume the password is compromised and change it.

Your next step

Pick one: if identity data was exposed, place the credit freeze today. If it was a password breach, run the reuse sweep and turn on two-factor authentication on your email account.

Then set one calendar reminder six months out to check your credit report and confirm your freeze is still in place. That single recurring task is what turns a panicked afternoon into durable protection.