Planning 30-60-90 Day Follow-Ups After a Major Data Breach

A major data breach can feel overwhelming in the first 24–48 hours. After you complete urgent steps like changing passwords and freezing credit, you still need a plan for the next three months. Many criminals wait weeks or months to use stolen data, so the period after a breach is when careful follow-up makes the biggest difference. This guide gives you a practical 30-60-90 day checklist to monitor for misuse, close new risks as they appear, and strengthen your long-term privacy posture.

Why a 30-60-90 Day Plan Matters

Breaches unfold on a different timeline than immediate hacks. Stolen data is often traded, combined with other leaks, and used later. A structured plan helps you:

  • Catch delayed fraud: New-account fraud and synthetic identity activity frequently surface weeks later.
  • Stay consistent: Regular check-ins reduce blind spots and help you notice small changes early.
  • Harden defenses: Spreading tasks over 90 days avoids fatigue and makes improvements stick.

Before Day 1: Immediate Stabilization (Quick Recap)

If you have not completed these steps yet, do them as soon as possible:

  • Change passwords for the breached account and any accounts that share the same or similar passwords. Use a unique, strong password for every account.
  • Turn on multi-factor authentication (MFA) everywhere you can, preferably using an authenticator app or security key rather than SMS when possible.
  • Place a security freeze at all three major credit bureaus (Experian, Equifax, and TransUnion). Freezes are free and the strongest protection against new-account fraud.
  • Enable transaction alerts from banks, credit cards, and payment apps.
  • Back up and secure email since email is the recovery key for many accounts. Review forwarding rules and recovery info.

Day 1–30: Monitor and Contain

The first month focuses on detecting misuse and sealing immediate gaps. Expect to spend a little time weekly.

Week 1

  • Inventory what was exposed: Identify whether the breach included passwords, Social Security number, driver’s license, bank info, insurance IDs, or answers to security questions. Prioritize accounts linked to those data types.
  • Reset critical account credentials: Banking, brokerage, email, password manager, cloud storage, tax, payroll/HR, health portals, carriers, and e-commerce logins used often.
  • Review account recovery settings: Confirm recovery emails, phone numbers, backup codes, and trusted devices. Remove old devices and sessions you don’t recognize.
  • Activate alerts everywhere: Banking and credit card transaction alerts, sign-in alerts for email and cloud services, and login notifications for financial and shopping accounts.

Week 2

  • Rotate passwords by risk tier: High-risk (financial, email, cloud, work) first; then medium (shopping, travel, subscriptions). Use a password manager to generate and store unique passwords.
  • Check credit reports: Pull reports from Experian, Equifax, and TransUnion. Look for unfamiliar accounts, inquiries, or addresses.
  • Consider extended fraud alert if SSN exposed: A fraud alert tells lenders to take extra steps to verify your identity.

Week 3

  • Audit devices and apps: Remove unneeded apps, update operating systems, patch browsers, and review browser extensions. Revoke app permissions you no longer need.
  • Secure SMS and voicemail: Set a carrier PIN, turn on account lock features, and disable voicemail call forwarding if active.
  • Replace security questions: If your breach included personal details, change security questions to non-obvious answers (consider using randomized answers stored in your password manager).

Week 4

  • Check financial statements line-by-line: Flag small “test” charges. Dispute anything unfamiliar immediately.
  • Scan for your data online: Search for your name, phone, address, and email together; look for profiles on people-search sites. Remove what you can and note sites to revisit later.
  • Document everything: Keep a simple log of actions you take, dates, and any suspicious items. This helps if you file reports.

Day 31–60: Deepen Monitoring and Remediate

The second month is about confirming stability and addressing medium-risk exposures that could fuel future fraud.

Week 5

  • Recheck credit and inquiries: Compare to Day-30 reports. New hard inquiries or accounts you didn’t open are red flags.
  • Tighten email security: Enable advanced phishing protection if available, turn on email provider’s security alerts, and review third-party app access (OAuth connections).
  • Refresh passwords on medium-risk accounts: Travel, delivery, loyalty programs, utilities, and carriers. Lock down auto-reload and stored payment methods.

Week 6

  • Replace exposed IDs if advised: If a driver’s license or state ID is known to be compromised, follow your state’s guidance on replacement and monitoring.
  • Harden tax and government accounts: Create or secure IRS and state tax accounts, Social Security online accounts, and unemployment portals to prevent fraudulent claims. Turn on MFA.
  • Review health and insurance portals: Check for address or beneficiary changes and unfamiliar claims.

Week 7

  • Evaluate recurring payments: Remove saved cards from merchants you rarely use. Consider using virtual card numbers for online purchases.
  • Segment email addresses: Use separate addresses for banking, shopping, and newsletters to reduce cross-risk and improve tracking of where spam begins.
  • Refresh device security hygiene: Update firmware on routers, enable WPA3 or strong Wi‑Fi passwords, and turn on automatic updates where possible.

Week 8

  • Review data broker exposure: Continue opt-outs from major people-search sites. Set a monthly reminder to revisit removals since listings can reappear.
  • Check for SIM swap risk: Confirm your carrier account lock/PIN is still active and ask about additional high-security flags.
  • Run another financial review: Compare statements across the past two months for patterns.

Day 61–90: Harden for the Long Term

The final month consolidates long-term protection so you are safer even if your data circulates on criminal markets.

Week 9

  • Rotate remaining low-risk passwords: Forums, newsletters, and older accounts you still use. Close accounts you no longer need to shrink your exposure.
  • Set renewal calendar entries: Create reminders for quarterly credit report checks, biannual password audits, and annual data broker cleanups.
  • Review account recovery fallback: Verify backup codes are stored securely and update recovery emails to addresses you control and monitor.

Week 10

  • Evaluate additional protections: Consider security keys for primary accounts, passkeys where supported, and virtual numbers for phone or payments.
  • Train your “phishing radar”: Practice verifying sender domains, previewing links, and ignoring pressure tactics. When in doubt, visit the site directly.
  • Scan for credential reuse: If any password was reused, change it everywhere and enable MFA. Commit to unique passwords going forward.

Week 11

  • Reconcile all alerts and logs: Review your action log, notification history, and any unresolved anomalies. Escalate anything suspicious with your bank, carrier, or service provider.
  • Confirm credit freeze status: Ensure freezes remain in place at all bureaus. Keep your PINs handy for any future temporary lifts.
  • Lock down children’s or dependents’ credit: If minors’ data may be exposed, place freezes for them as well to block synthetic identity fraud.

Week 12

  • Conduct a full privacy checkup: Review browser privacy settings, tracking protections, ad personalization controls, and data-sharing preferences across major accounts.
  • Finalize a steady-state routine: Decide on your ongoing cadence for credit checks, statement reviews, password maintenance, and data removal.
  • Store documentation: Keep all records of the breach, notifications, disputes, and your remediation steps in a secure folder.

What to Watch For During Each Phase

  • New accounts you didn’t open: Banking, loans, buy-now-pay-later, retail cards.
  • Hard credit inquiries you don’t recognize: Especially clustered attempts.
  • Change-of-address or SIM swap attempts: Alerts from carriers, USPS, or account notifications about recovery changes.
  • Tax or benefits fraud: Unexpected IRS transcripts, unemployment claims, or healthcare activity.
  • Credential-stuffing signs: Login alerts from unfamiliar devices or locations.

When and How to Escalate

  • Unauthorized transactions: Contact your bank or card issuer immediately; follow their dispute process and request a new card number.
  • Confirmed identity theft: File an identity theft report and create a recovery plan using official guidance. Keep copies of all correspondence.
  • Persistent credit issues: If incorrect accounts or inquiries remain, file disputes with credit bureaus and the furnishing creditor. Provide documentation and your action log.
  • Compromised government benefits or taxes: Notify the relevant agency, secure your account, and follow their fraud remediation steps.

Building Your Monitoring Stack

Ongoing monitoring is what turns a one-time response into lasting protection. Combine these layers:

  • Bank and card alerts: Real-time push or SMS for transactions, new payees, transfers, and large purchases.
  • Credit monitoring and reports: Watch for new accounts, inquiries, and changes in personal information tied to your credit files.
  • Dark web and credential exposure checks: Helpful for early warning, though you should still rotate passwords and use MFA regardless.
  • Data broker removals: Reduce the personal details that criminals use for social engineering, account recovery abuse, or targeted scams.

If you want a single place to track credit-related changes while you work your 30-60-90 plan, consider using a dedicated service for privacy, credit monitoring, and identity protection. One option is SmartCredit, which can help you watch for new-account activity, changes to your reports, and other financial-identity signals during and after a breach.

Practical Password and MFA Strategy

  • Use a password manager: Generate 16+ character unique passwords and store them securely.
  • Prefer phishing-resistant factors: Security keys or passkeys where supported; otherwise an authenticator app is stronger than SMS.
  • Create a rotation pattern: High-risk accounts during Days 1–14, medium-risk during Days 15–45, remaining accounts by Day 75.
  • Record backup codes: Store offline in a secure place to avoid getting locked out.

Protecting Non-Financial Accounts

Attackers often start with accounts that seem harmless and pivot to sensitive ones.

  • Email: The master key for password resets. Turn on MFA, remove old forwarding, and check filters and app access.
  • Cloud storage and photo services: Audit shared folders and links; remove anything public you no longer need.
  • Social media: Lock privacy settings, remove phone numbers if not required, and enable login alerts.
  • Shopping and delivery: Remove stored cards and address books you no longer use; watch for orders to new addresses.

Data Minimization and Exposure Reduction

  • Close accounts you don’t use: Every idle account is another recovery path attackers can abuse.
  • Limit what you share: Avoid posting birth dates, travel plans, and family details that can answer security prompts.
  • Opt out of data brokers: Removing people-search listings reduces targeted phishing and social engineering attempts tied to the breach.
  • Use separate emails and virtual cards: Segmentation helps you trace and isolate future exposures quickly.

A Simple 90-Day Checklist

  1. Freeze credit and enable alerts on all financial accounts.
  2. Change passwords and enable MFA on primary accounts; secure email first.
  3. Check all three credit reports; dispute anything unfamiliar.
  4. Rotate remaining passwords by risk tier; remove saved cards at merchants.
  5. Secure devices, browsers, routers, and carrier accounts with PINs.
  6. Monitor weekly for new accounts, inquiries, and odd logins.
  7. Opt out from major people-search sites and recheck listings monthly.
  8. Document actions and outcomes; keep a simple remediation log.
  9. Reassess at 60 days; escalate verified fraud quickly.
  10. Establish a long-term routine for quarterly credit checks and privacy audits.

Conclusion

A data breach is not a one-day event—it unfolds over months. By following a structured 30-60-90 day plan, you give yourself multiple chances to detect misuse early, close lingering gaps, and build lasting protections. Start with freezes and strong authentication, review your credit and financial activity on a schedule, and reduce your public data footprint. With steady monitoring and incremental improvements, you turn a stressful incident into a catalyst for durable privacy and identity security.

Good to Know

Most identity misuse appears weeks to months after a breach, not immediately. Staying disciplined with scheduled check-ins often catches problems before they become costly.