If a breach report or leak includes a “data dictionary” or field list related to your account, it can feel confusing. You may see column names like full_name, dob, last4_ssn, phone_mobile, address_line1, ip_address, or security_question without always seeing the actual values. Even if the breach redacts or partially masks values, a published field list reveals what an attacker could know about you and which accounts or recovery paths they might try to exploit. This guide explains what those lists mean, how to evaluate your risk, and what to do next—step by step.
What a Data Dictionary or Field List Really Means
A data dictionary (or schema/field list) describes the types of information a breached system collected and stored. It might be published in a breach notice, a security researcher’s write-up, or a leak on a forum. Key points:
- It maps your exposure scope. Even if values are masked, the presence of specific fields (for example, “password_hash,” “dob,” “mothers_maiden_name,” “2fa_enabled”) shows what the system stored about you.
- Attackers learn what to target. Knowing that security questions, partial SSN, or multiple phone numbers exist helps attackers craft convincing phishing lures or attempt account recovery flows.
- Values may exist elsewhere. A field list can hint that third-party partners, backups, logs, or analytics tools also hold the same data, widening your exposure surface.
How to Read the Field List: A Quick Reference
Use this checklist to interpret common fields and what they imply:
- Contact fields: email, phone_mobile, phone_home, address_line1/2, city, state, postal_code. These enable targeted phishing, SMS scams, SIM-swap attempts, and physical mail scams.
- Identity fields: full_name, dob, ssn (or last4_ssn), driver_license, passport_number. These raise identity theft and account-opening risks. Even partials can be combined with other leaks.
- Authentication fields: password_hash, password_salt, security_question, security_answer, 2fa_enabled, backup_codes. These threaten account takeover, especially if you reuse passwords or rely on knowledge-based questions.
- Financial fields: card_last4, card_type, billing_address, bank_account_last4, routing_number, payout_email. These enable financial fraud, social engineering at banks, or spear-phishing.
- Technical/session fields: ip_address, device_id, user_agent, session_token, reset_token, login_timestamp. These aid targeted attacks, location profiling, and session hijacking if tokens were exposed.
- Behavioral/marketing fields: interests, segments, referral_source, consent_flags. These improve scam believability because attackers know what you like, when you joined, or how you were onboarded.
- Health/education fields (regulated): diagnosis_codes, treatment_dates, student_id, grades. These require extra vigilance due to sensitivity and potential regulatory remedies.
Immediate Actions (First 24–48 Hours)
Move quickly to limit downstream harm:
- Change passwords for the breached service and any reused accounts. Use a strong, unique password for every account. Turn on app-based 2FA (authenticator app), not SMS, whenever possible.
- Update security questions and recovery options. If the field list includes security questions, assume they’re compromised. Replace them with answers that are fictitious but memorable to you.
- Invalidate sessions and reset tokens. Log out of all devices and reset API keys, backup codes, and app passwords if those fields exist in the list.
- Watch for targeted phishing and smishing. Expect messages that reference breached details (your city, last purchase, or partial card digits). Verify independently before clicking or responding.
- Check the breach notice for offered protections. Some organizations provide free credit monitoring or identity restoration support. Enroll promptly if appropriate.
Strengthen Financial and Identity Defenses
If identity or financial fields appear in the dictionary, add formal protections:
- Place a security freeze at all three major credit bureaus (and any regional bureaus if applicable). A freeze helps block new-account fraud and can be lifted temporarily when you need credit.
- Enable transaction alerts on bank, card, and payment apps. Set low thresholds so you see unusual charges quickly.
- Monitor credit and identity signals for unexpected inquiries, new accounts, or changes to your personal information. If you want ongoing, centralized monitoring and alerts for financial identity risks, consider a resource like SmartCredit for privacy, credit monitoring, and identity protection.
- Replace at-risk credentials with passkeys or strong, unique passwords managed by a reputable password manager.
Customize Your Response by Exposure Type
Tailor your next steps to what the field list shows:
If contact info is listed (email, phone, address)
- Set up email filters and spam protections; consider aliases for high-risk accounts.
- Enable SMS filtering and report smishing; avoid tapping links in texts.
- Opt out of major data brokers to reduce future contact-based targeting and doxxing risks.
If identity data is listed (DOB, SSN/last4, driver’s license)
- Freeze credit at Equifax, Experian, and TransUnion; add ChexSystems and Innovis if available in your region.
- Request driver’s license or state ID replacement if your jurisdiction offers new numbers after exposure.
- File an Identity Theft Report with the appropriate authority if you see fraudulent activity; keep documentation.
If authentication data is listed (password_hash, security_question, backup_codes)
- Immediately change passwords and revoke remembered devices/sessions.
- Switch to app-based 2FA or hardware keys; regenerate backup codes and store them offline.
- Audit other accounts for password reuse; change them proactively.
If financial data is listed (card_last4, bank_account_last4)
- Call your bank/card issuer to add an extra verification word or PIN for phone-based support.
- Turn on purchase alerts and daily balance notifications.
- Replace cards or accounts if full numbers might have been exposed elsewhere.
If technical/session data is listed (ip_address, device_id, tokens)
- Reinstall or update apps, sign out everywhere, and reset tokens/API keys.
- Review connected apps and integrations; remove those you don’t use.
- Update routers, enable automatic updates, and review your device security posture.
Validate What Was Actually Exposed
Not every field in a data dictionary applies to you. Confirm what the company stored for your account:
- Request a copy of your data via a privacy request if available. Ask specifically which fields, values, and date ranges are linked to your account.
- Ask about salts and hashing if password_hash appears. A strong, unique hash with proper salting is better than none, but you should still reset passwords.
- Clarify token expirations for reset_token or session_token fields. If tokens were exposed, when were they invalidated?
- Confirm third-party sharing if the dictionary references partners, analytics, or payment processors. Your data may live in multiple places.
Reduce Future Exposure
Field lists often reveal data you didn’t realize you were providing. Use the moment to minimize future risk:
- Trim optional fields in profiles—remove saved IDs, secondary emails, extra phone numbers, and stored addresses you don’t need.
- Limit recovery vectors by turning off SMS recovery if you use an authenticator app or passkeys.
- Rotate identifiers where possible—use email aliases for different services to compartmentalize exposure.
- Opt out of data brokers and marketing lists; reduce the trail scammers can use to validate information about you.
Document Everything
Keep a simple record of your response. Documentation helps with disputes, restoration, or legal remedies:
- Timeline: note the breach date, when you were notified, and actions you took.
- Evidence: save emails, screenshots of the field list, and support ticket numbers.
- Financial notes: record fraudulent charges, merchant names, and claim outcomes.
- Agency filings: track any reports you file with consumer protection or law enforcement.
Spot and Block Common Post-Breach Scams
After a field list is published, scams become more believable. Be alert for:
- Impersonation calls referencing your address or last4 of a card to “verify” identity. Hang up and call the institution directly using a known number.
- Password reset lures urging you to click a link. Instead, go directly to the service website and initiate your own reset.
- Refund or overpayment scams exploiting your purchase history. Verify claims inside your account portal, not via links.
When to Seek Additional Help
Escalate if you see any of the following:
- New credit inquiries or accounts you don’t recognize.
- Denied credit due to unknown accounts or collections.
- Account takeovers or repeated login notices you didn’t initiate.
- Medical, education, or government benefits fraud involving your identity.
Contact affected institutions, file appropriate reports, and consider identity restoration assistance if provided by the breached company or a trusted service. Keep your documentation up to date as you resolve incidents.
Build a Resilient Baseline Going Forward
Turn lessons from this breach into lasting habits:
- Unique passwords + app-based 2FA or passkeys on all important accounts.
- Quarterly account audit to remove unused apps, review recovery options, and prune stored data.
- Credit freezes by default and temporary thaws only when needed.
- Real-time alerts for sign-ins, financial transactions, and password changes.
- Minimize data exhaust: fewer sign-ups, fewer saved cards, and careful permission settings.
Conclusion
A published data dictionary or field list is more than a technical artifact—it’s a map of what attackers might try next. Treat it as a meaningful exposure, even when values are partially masked. Start with immediate hygiene (passwords, 2FA, token resets), strengthen financial and identity defenses (freezes, alerts, monitoring), and tailor your response to the specific fields listed. Validate what was truly stored about you, remove optional data going forward, and document your actions. With a clear plan and the right safeguards, you can reduce the risk of account takeover and identity fraud and turn an unsettling disclosure into a practical privacy upgrade for the long run.
Good to Know
A data dictionary tells attackers which specific data points exist about you, even if values are masked; that knowledge alone can fuel targeted phishing and account reset attempts, so treat field lists as a meaningful exposure.