Home
Blog
What to Do After a Data Breach: Your Calm, Step-by-Step Guide for the First 48 Hours

What to Do After a Data Breach: Your Calm, Step-by-Step Guide for the First 48 Hours

Reviewed by
Table of Contents

Key Takeaways

You got the email. Or maybe you saw the news headline. Or your bank flagged a suspicious charge. No matter how you found out, your personal data may have been exposed in a breach.

Take a breath. Seriously.

The worst thing you can do right now is panic and make hasty moves. The second worst thing? Do nothing. This guide will help you do neither. It's a calm, practical playbook for the first 48 hours after a data breach, the window that matters most.

Why the first 48 hours actually matter

The clock starts ticking the moment a breach becomes known. Cybercriminals don't wait. Stolen credentials, Social Security numbers, and financial data can be listed on dark web marketplaces within hours of a breach occurring.

Here's how serious the landscape is right now:

  • In 2024, the Identity Theft Resource Center (ITRC) tracked over 3,158 reported data compromises, generating nearly 1.73 billion victim notices, a staggering 312% increase from 2023. (ITRC 2024 Annual Data Breach Report)
  • The global average cost of a data breach reached $4.44 million in 2025, according to IBM's Cost of a Data Breach Report 2025. U.S. breach costs rose even higher, to $10.22 million per incident.
  • The average time to identify and contain a breach fell to 241 days in 2025, meaning millions of people's data can be circulating for months before they even know to act.

The good news: most identity theft and financial fraud is preventable when you move quickly and methodically. Here's exactly what to do.

Step 1 (hours 0-2): don't panic, but do verify

Before you do anything else, confirm the breach is real. Cybercriminals routinely send fake "data breach notifications" meant to steal the very information they're pretending to protect.

How to verify a legitimate breach notification:

  • Go directly to the company's official website. Don't click links in the email.
  • Search news outlets for coverage of the breach (e.g., "[Company name] data breach 2025")
  • Check HaveIBeenPwned.com, a free, trusted tool that shows whether your email has appeared in known breaches

What to look for in the notification itself:

  • What type of data was exposed? (Passwords, SSN, financial info, medical records, email only?)
  • When did the breach occur?
  • What is the company doing in response?
  • Are they offering free credit monitoring or identity protection services?
Warning: A notification that asks you to "verify your identity" by entering your Social Security number or credit card information is almost certainly a scam. Legitimate breach notices never ask for this.

Step 2 (hours 2-6): change your passwords strategically

If passwords or login credentials were among the exposed data, this is your most urgent action item.

Start with these accounts first:

  1. The breached account. Change it immediately.
  2. Your email. This is the master key to everything else.
  3. Financial accounts. Banking, investment, payment apps (Venmo, PayPal, Cash App).
  4. Any account where you used the same password as the breached one.

Best practices for new passwords:

  • Use a unique password for every account. This is non-negotiable after a breach.
  • Make them long (16+ characters), mixing letters, numbers, and symbols.
  • Use a password manager (like 1Password or Bitwarden) to generate and store them securely. You only need to remember one master password.

Enable Two-Factor Authentication (2FA):

Once passwords are changed, turn on 2FA everywhere it's offered, especially email, banking, and social media. An authenticator app (like Google Authenticator or Authy) is stronger than SMS codes, though SMS 2FA is still better than nothing.

Step 3 (hours 6-12): lock down your credit

If your Social Security number, date of birth, or financial account numbers were exposed, this step is critical.

Option A: Place a Fraud Alert (Free)

A fraud alert tells lenders to take extra steps to verify your identity before extending credit. You only need to contact one bureau. They're required to notify the others.

  • Equifax: equifax.com/personal/credit-report-services/ or 1-800-685-1111
  • Experian: experian.com/help/fraud-alert/ or 1-888-397-3742
  • TransUnion: transunion.com/credit-freeze or 1-800-916-8800

An initial fraud alert lasts one year and is free.

Option B: Place a Credit Freeze (Free, Stronger Protection)

A credit freeze completely prevents new credit accounts from being opened in your name. It's the gold standard if your SSN was exposed.

You must contact all three bureaus separately:

Bureau Online Phone
Equifax equifax.com 1-800-685-1111
Experian experian.com 1-888-397-3742
TransUnion transunion.com 1-888-909-8872

A credit freeze is free, lasts until you lift it, and does not affect your credit score. (FTC guidance on credit freezes)

Pro tip: If you have minor children, consider freezing their credit too. Child identity theft often goes undetected for years because no one is monitoring their credit.

Step 4 (hours 12-24): monitor your financial accounts

Log in to every financial account and scrutinize recent transactions, even small ones. Fraudsters often test stolen card numbers with small charges before making larger purchases.

What to do:

  • Review the last 30 days of all bank, credit card, and investment account activity.
  • Set up transaction alerts on every financial account (most banks offer free real-time SMS or email alerts).
  • Request your free credit reports at AnnualCreditReport.com. All three bureaus are now required to provide free weekly reports.

If you see fraudulent charges:

  • Contact your bank or card issuer immediately. You have stronger fraud protections when you act quickly (within 60 days under the Fair Credit Billing Act for credit cards, two days for debit cards under the Electronic Funds Transfer Act).
  • Ask for a new card number and account number, not just a replacement card.

Step 5 (hours 24-36): watch for phishing and scams targeting you

Here's something many people don't anticipate: a data breach makes you a more attractive target for follow-on scams.

Criminals who buy stolen data on dark web markets often use it to craft hyper-personalized phishing attacks. Because they already know your name, employer, or last four digits of your card, these messages look shockingly real.

Common post-breach scams to watch for:

  • Phishing emails pretending to be from the breached company, your bank, or the IRS
  • Phone calls claiming to be from fraud departments, asking you to "verify" your identity
  • Text messages with urgent links about suspicious account activity
  • Fake credit monitoring services trying to capitalize on the chaos

The rule: Hang up and call back on a number you look up yourself. Never click links in unsolicited messages. Go directly to the company's website.

Step 6 (hours 36-48): report it and get official help

Don't try to navigate this alone. The federal government offers free resources specifically designed for data breach victims.

IdentityTheft.gov (run by the FTC)

The most important resource for U.S. victims. Visit IdentityTheft.gov/databreach. The site creates a personalized recovery plan based on exactly what type of information was exposed.

File a report with the FTC

If you've experienced actual identity theft (fraudulent accounts, unauthorized charges), file a report at ReportFraud.ftc.gov. An FTC Identity Theft Report is official documentation that can help you dispute fraudulent accounts.

File a police report (if needed)

For major fraud, like new accounts opened in your name or tax fraud, file a local police report. You'll need it when disputing fraudulent accounts with creditors.

For medical record breaches:

Contact the breached healthcare provider and your health insurer. You can also file a complaint with the U.S. Department of Health and Human Services at hhs.gov/hipaa.

Step 7: set up long-term monitoring

You've made it through the most critical window. Now it's about sustained vigilance, because the data from a breach can resurface months or even years later.

Set these up before the 48-hour mark is over:

Free credit monitoring. Many breach notifications include an offer for free monitoring services (like Experian IdentityWorks or Equifax Complete). Accept it. It's free and covers you for 1-2 years.

Dark web monitoring. Services that scan dark web forums and marketplaces for your personal data. Many credit monitoring services include this; free limited scans are available at Experian's site.

Google Alerts for your name. A simple, free way to catch if your name appears in public records or news connected to fraud.

IRS Identity Protection PIN. If your SSN was exposed, enroll in the IRS IP PIN program at IRS.gov/ippin. This prevents anyone else from filing a tax return using your Social Security number.

Your 48-hour action checklist

Here's a quick-reference summary of everything covered above:

Hours 0-6:

  • Verify the breach is real (don't click notification links)
  • Identify exactly what data was exposed
  • Change passwords starting with email and financial accounts
  • Enable two-factor authentication everywhere
  • Place a fraud alert or credit freeze at all three bureaus

Hours 6-24:

  • Review all financial accounts for unauthorized activity
  • Set up real-time transaction alerts at your bank
  • Pull free credit reports at AnnualCreditReport.com
  • Report fraudulent charges to your card issuer immediately

Hours 24-48:

  • Be hyper-vigilant for phishing attempts
  • Visit IdentityTheft.gov/databreach for a personalized recovery plan
  • File an FTC report if identity theft has already occurred
  • Set up credit monitoring and dark web monitoring
  • Enroll in the IRS IP PIN program if your SSN was exposed

The bottom line

A data breach is unsettling, but it doesn't have to become a crisis. The people who fare best aren't the ones who react the fastest in a panic. They're the ones who take measured, methodical steps in the right order.

You now have that order.

Bookmark this guide. Share it with family members, especially older relatives or teenagers who may not know what to do when a notification lands in their inbox. The best time to take action is now, in the first 48 hours, when your steps carry the most weight.

Stay protected before the next breach happens

Responding quickly after a breach is important. But the better position to be in is catching threats before they cause damage.

Guardio works quietly in the background across your browser and your phone, detecting phishing pages, malicious links, and sites known to be connected to data theft. If a site you visit is flagged, you'll know before you hand anything over. Guardio achieved 100% detection in independent phishing tests, and the research team has uncovered real-world threat campaigns that evaded standard security tools entirely.

Over 1.5 million people use it. It takes about two minutes to set up.

Conclusion

A data breach is unsettling, but it doesn't have to become a crisis. Move methodically through these steps, and you'll dramatically reduce the risk of lasting harm.

Get a free security scan with Guardio today and stay protected from the threats you can't always see.

CMS-based CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What should I do first after a data breach?

Verify the breach is real by going directly to the company's official website. Don't click any links in the notification email. Then identify exactly what type of data was exposed, since that determines which steps are most urgent for you.

Should I freeze my credit after a data breach?

Yes, especially if your Social Security number or financial account details were exposed. A credit freeze is free, doesn't affect your credit score, and prevents anyone from opening new accounts in your name. You'll need to contact all three bureaus: Equifax, Experian, and TransUnion.

How long do I have to report fraudulent charges after a breach?

For credit cards, you have up to 60 days under the Fair Credit Billing Act. For debit cards, you should report within two days to limit your liability under the Electronic Funds Transfer Act. The sooner you report, the stronger your protections.

Can criminals use my data years after a breach?

Yes. Stolen data from a breach can circulate on dark web markets for months or even years. This is why long-term monitoring matters. Set up credit monitoring, dark web alerts, and consider enrolling in the IRS Identity Protection PIN program if your SSN was exposed.

What is a fraud alert and how is it different from a credit freeze?

A fraud alert asks lenders to take extra steps to verify your identity before extending credit. A credit freeze goes further by completely blocking new credit applications in your name. Both are free. A credit freeze offers stronger protection but requires you to temporarily lift it when you want to apply for credit yourself.

Will I get scammed more after a data breach?

You're at higher risk of targeted phishing attacks after a breach. Criminals who purchase stolen data use personal details like your name, employer, or partial card numbers to craft convincing fake messages. Be especially cautious of unsolicited emails, texts, or calls in the weeks after a breach.

Is HaveIBeenPwned.com safe to use?

Yes. HaveIBeenPwned.com is a legitimate, widely trusted tool run by security researcher Troy Hunt. It checks your email address against a database of known breaches and tells you which ones you've appeared in. You don't need to enter a password to use it.

What if my child's information was exposed in a data breach?

Children are common targets for identity theft because no one monitors their credit. If your child's information may have been exposed, place a credit freeze on their credit file with all three bureaus. Child identity theft often goes undetected for years, so acting early is especially important.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now