If you just received a breach notice—or you’re seeing suspicious activity—your first question is simple: what should I do now, and in what order? This guide gives you a practical 7-day action plan to stop the bleeding and a 30-day plan to stabilize and monitor, with steps you can actually complete. It’s written for beginners, prioritizes high-impact moves, and avoids busywork.
First, Understand What “Post-Breach” Really Means
A breach can expose different kinds of data: email and passwords, full names and addresses, phone numbers, answers to security questions, payment cards, bank details, or even SSNs. The type of data exposed determines your level of risk and which actions matter most. You won’t always get perfect details from a breach notice, so assume the worst version of whatever category it lists and act accordingly.
- Credentials (email + password) leaked: Highest risk for account takeovers, credential stuffing, and phishing.
- Contact info leaked (name, phone, address): Expect targeted scams, SIM-swap attempts, and social engineering.
- Financial info leaked (cards/bank): Fraud and unauthorized charges are possible; monitoring and card replacement matter.
- SSN leaked: Risk of new-account fraud; credit freeze and long-term monitoring are key.
Your 7-Day Post-Breach Checklist (Do These First)
This is your rapid response. If time is tight, complete the bolded tasks first. Expect to spend about 90–120 minutes total, split across a few sessions.
Day 1: Lock Down Access
- Reset the password for the breached site/app immediately. If you reused that password anywhere, change those too. Use unique passwords everywhere.
- Turn on two-factor authentication (2FA) for email, bank, and primary accounts. Prefer app-based codes (e.g., an authenticator app) or hardware keys over SMS when possible.
- Scan your primary email account’s security activity. Review recent logins, recovery email/phone, forwarding rules, and “app passwords.” Remove anything unfamiliar.
- Update your password manager master password if the email or master password might be compromised. Ensure 2FA is enabled on the manager itself.
Day 2: Contain Financial Risk
- Freeze your credit with Equifax, Experian, and TransUnion. It’s free and blocks new credit accounts in your name. Don’t skip this if your SSN or identity info was part of the breach.
- Place a one-year fraud alert (optional but useful). Lenders must take extra steps to verify identity before opening credit.
- Replace exposed payment cards. If card numbers, expiration dates, or CVV were leaked, contact the issuer for a new card and turn on real-time transaction alerts.
- Enable account alerts on bank and credit card apps. Turn on push/SMS/email alerts for sign-ins, password changes, and any transaction over a small amount you choose.
Day 3: Secure Your Phone and Carrier
- Add a carrier PIN or passphrase to your mobile account to reduce SIM-swap risk.
- Audit installed apps on your phone and browser extensions on your computer. Remove apps/extensions you don’t use or don’t recognize.
- Update your OS and browsers to the latest version; enable automatic updates.
Day 4: Shut Down Easy Attack Paths
- Rotate “high-value” passwords: Email, bank/brokerage, password manager, cloud storage, tax, healthcare, and primary social accounts.
- Update recovery options: Ensure your recovery email and phone are current and themselves secured with strong passwords and 2FA.
- Change answers to security questions to random, non-guessable phrases stored in your password manager. Don’t use real facts.
Day 5: Reduce Public Exposure
- Remove or lock down public data points on social profiles that can aid impersonation (phone number, birthday, hometown, school, pet names).
- Unlist your phone number where possible and opt out of major data brokers over time. Start with the biggest people-search sites you find when you search your name and city.
Day 6: Train Your Inbox and Yourself
- Mark phishing emails as spam and block SMS senders who send suspicious links.
- Slow down on links and attachments for the next 30 days. When in doubt, navigate directly to the site instead of clicking.
- Use a “burner” alias email for new signups going forward to reduce the impact of future leaks.
Day 7: Set Up Ongoing Monitoring
- Enable ongoing credit and identity monitoring so you get alerts for new accounts, inquiries, or suspicious activity. This is especially helpful after SSN or financial-data exposure. Consider a consolidated service like SmartCredit to centralize credit monitoring and identity-related alerts.
- Create a monthly “security calendar” reminder (15 minutes) to review alerts, check recent logins, and update any weak passwords flagged by your manager.
The 30-Day Stabilization Plan (Build Durable Habits)
After the urgent week, these steps minimize long-term risk and close any remaining gaps.
Week 2: Confirm Nothing Slipped Through
- Check your credit reports from Equifax, Experian, and TransUnion. Look for unfamiliar accounts, addresses, or inquiries.
- Review bank and card statements for small “test” charges or odd recurring subscriptions.
- Audit account recovery settings again after changes settle—breached sites sometimes reset options.
Week 3: Strengthen Core Defenses
- Migrate SMS-based 2FA to app-based where possible. Keep SMS as backup only.
- Segment your email addresses: one for banking/taxes, one for shopping/newsletters, one alias for throwaway signups.
- Create a dedicated “money device profile” habit: Only do banking on a device you keep updated and minimal—no sketchy apps, minimal extensions, strong screen lock.
Week 4: Reduce Future Blast Radius
- Prune old accounts you no longer use. Delete or deactivate, and remove stored payment methods.
- Opt out from major data brokers and people-search sites. Fewer public data points reduce targeted scams.
- Back up your important data securely with encrypted backups and a restore test. Ransomware and account lockouts hurt less when recovery is easy.
Priority Mapping: What Matters Most Based on What Leaked
Tailor your effort to the data type exposed. Use this to triage if you can’t do everything right away.
- If passwords leaked: Immediate password resets; enable 2FA; check email account security; review login history; rotate high-value passwords.
- If email only leaked: Expect targeted phishing and password reset attempts; enable 2FA everywhere; watch for suspicious password-reset emails; tighten spam filters.
- If phone number leaked: Add a carrier PIN; watch for smishing (SMS phishing) and SIM-swap red flags; consider removing phone from public profiles.
- If payment card leaked: Replace card; turn on transaction alerts; scrutinize statements for micro-charges.
- If SSN leaked: Freeze credit with all three bureaus; consider a one-year fraud alert; start continuous credit and identity monitoring; keep an eye on IRS/tax transcripts during filing season.
How to Freeze Your Credit (Free and Fast)
Freezing your credit is one of the most effective, no-cost protections if your identifying information is exposed. You must place the freeze separately at each bureau, and you can lift it temporarily when needed.
- Go to Equifax, Experian, and TransUnion online credit freeze pages.
- Verify your identity and set a secure PIN/passphrase (store it in your password manager).
- Confirm the freeze is active at all three. Repeat for any state-specific bureaus if applicable.
Freezing doesn’t affect your credit score, and you can still use existing credit cards and loans.
Signs of Trouble to Watch For
- Unexpected password reset emails you didn’t request.
- Account login alerts from unfamiliar locations or devices.
- New credit inquiries or accounts you don’t recognize.
- Bank alerts for unusual transactions, even small ones.
- Phone loses service unexpectedly (possible SIM swap).
- Mail for accounts you didn’t open, or IRS notices about unfamiliar filings.
If You Suspect Identity Theft
- Document everything: Keep a simple timeline with dates, screenshots, and call logs.
- File an identity theft report with the FTC (IdentityTheft.gov) and follow their recovery plan steps.
- Contact affected institutions (banks, card issuers, mobile carrier) and ask for their fraud process and added safeguards.
- Consider a police report if creditors need one for disputes.
- Preserve evidence: Don’t delete suspicious emails or texts; capture screenshots.
Make It Stick: Small Habits That Pay Off
- Use a password manager to create and store unique passwords for every account.
- Keep software auto-updates on for your device, browser, and apps.
- Limit extensions and third-party apps to those you truly need.
- Review security once a month: 15 minutes to check alerts, logins, and any weak/reused passwords.
- Be deliberate with email: Separate addresses and use aliases to reduce future breach impact.
FAQs
Do I need credit monitoring if I froze my credit?
Yes. A freeze blocks new credit accounts, but monitoring can alert you to attempts, changes in your credit files, or other identity misuse. Consolidated tools can save time and reduce missed warnings.
How long should I keep the credit freeze?
Indefinitely. Unfreeze temporarily when you need to apply for credit, then re-freeze. It takes just a few minutes.
What if the breached company offers free monitoring?
Use it, but read the scope carefully—some services only cover certain bureaus or limited alerts. You can layer your own monitoring and a credit freeze for stronger protection.
I changed my password—am I done?
Not quite. Turn on 2FA, review recovery options, and monitor for suspicious activity. If you reused that password, change it everywhere it was used.
A Realistic Weekly Plan You Can Repeat
Security isn’t a one-time sprint. After your 7-day push, your 30-day stabilization plan forms a simple routine: monthly alert checks, quarterly password audits for high-value accounts, and annual credit report reviews. Centralized monitoring and smart alerts help you catch small problems before they become big ones.
Conclusion
A breach is stressful, but it doesn’t have to spiral. In your first week, focus on account control (passwords and 2FA), financial safeguards (freezes and alerts), and quick wins that block attackers. Over the next month, stabilize with monitoring, pruning old accounts, and reducing public exposure. With a short monthly check-in and a tool that centralizes credit and identity alerts, you’ll stay ahead of most risks and finish what you start.
Good to Know
You don’t have to do everything in one sitting. Knock out the highest impact actions first—like password resets and credit freezes—then schedule the rest across the month so you actually finish.