What to Do After a Data Breach
(A Calm, Step-by-Step Plan)
You got the email: "We're writing to inform you of a security incident." Your stomach drops. Here's the first thing I want you to know after over 30 years of walking people through exactly this moment — a data breach is not your fault, and it's almost never a five-alarm emergency if you act steadily over the next day or two. The company that got breached is the one that slipped up; your job now is simply to close the doors before anyone can use what leaked. Let's do it in order, calmly.
1 First, Confirm the Notice Is Real
Before you do anything the email tells you to, make sure the email itself is legitimate. Scammers love a breach — they'll send their own fake "breach alerts" designed to look like the real thing, because they know you're rattled and ready to click. Don't click any link or button inside the notice.
Open a fresh browser tab, type the company's real website address yourself, and log in the way you normally would. Any genuine breach notice and instructions will be waiting for you inside your real account. If there's nothing there, the "alert" you received was probably the scam.
2 Change That Password — and Every Twin of It
Change the password on the breached account first. Then comes the part most people skip, and it's the one that matters most: if you used that same password (or a close cousin of it) anywhere else, change it there too. This is how a single breach snowballs. Attackers take a leaked email-and-password pair and try it on banks, email, shopping sites, everywhere — a trick called credential stuffing. One reused password can unlock a dozen accounts.
Make each new password long, unique, and unrelated to the old one. A short phrase you can picture works better than a scramble of symbols you'll forget.
3 Turn On Two-Factor Authentication
This is the single best thing you can do, and I wish everyone did it before a breach instead of after. Two-factor authentication (2FA) means that even if someone has your password, they still can't get in without a second code — usually from an app on your phone. It turns a stolen password from a master key into a useless string of characters.
Switch it on for your email account first of all. Your email is the master key to everything else — password resets for your other accounts all land there — so protecting it protects the whole set.
4 Brace for the Follow-Up Scams
Here's what people don't expect: the breach is often just the opening move. Once your email and phone number are out there, a wave of very convincing scams tends to follow — fake "security team" calls, texts about the very company that was breached, emails that name real details to sound authentic.
Treat every unexpected message over the next while as guilty until proven innocent, especially anything referencing the breach itself. This is the perfect moment to sharpen up on how to spot a phishing email, because you're now a marked target and they're counting on your nerves being frayed.
A classic follow-up: someone phones claiming to be from your bank's "fraud department," says they've spotted the breach, and offers to "secure" your account — if you'll just confirm your password or read back a code. Your real bank will never ask for that. Hang up, then call the bank back using the number printed on your card. Always let the person offering to help be the one you called, not the one who called you.
5 Find Out What Actually Leaked
Not all breaches are equal. A leaked email address is a nuisance. A leaked password is serious. A leaked card number or government ID is serious in a different way and needs the extra steps below. The breach notice should tell you what was exposed — read that part carefully, because it decides how far you need to go.
A free, well-respected site called Have I Been Pwned (haveibeenpwned.com) lets you type in your email address and see which known breaches it has turned up in. It's run by a trusted security researcher, it's safe to use, and it's a good gut-check for which of your accounts deserve a fresh password today.
6 If Financial or ID Information Leaked
If a card number, bank detail, or something like your Social Insurance Number was part of the breach, take these extra steps. Call your bank or card issuer, tell them your details were in a breach, and ask them to watch for fraud — they can flag the account or reissue the card. Keep an eye on your statements over the next few months for charges you don't recognize, even tiny ones, since scammers often test a card with a small purchase first.
For a leaked SIN or similar ID here in Canada, you can contact the credit bureaus (Equifax and TransUnion) to place a fraud alert on your file, which makes it harder for someone to open credit in your name. This is a "better safe than sorry" move when your ID is involved.
7 Set Yourself Up So the Next One Barely Matters
Breaches will keep happening — that part is out of your hands. What you can control is how much damage each one can do. The single biggest upgrade is a password manager: a program that creates and remembers a different strong password for every account, so a leak at one site can't touch any other. You only remember one master password; it handles the rest.
Pair that with 2FA on your important accounts, and a breach goes from a scary night to a minor chore — change one password, done. That's the whole goal here: not to never be breached, but to make it so that when you are, it's no big deal.
Feeling Overwhelmed? You Don't Have to Sort It Alone
A breach notice can leave you staring at a dozen accounts, unsure which to lock down first or whether something nasty made it onto your computer. That's a completely normal place to feel stuck — and it's exactly the kind of thing that's far quicker with someone who's done it many times over.
If you're in the Nanaimo, BC area, BigMike Computer Services can help you change and organize your passwords, get two-factor set up, check your machine for anything that shouldn't be there, and make sure the doors are truly shut. Peace of mind is worth a quick call.
Visit BigMike Computer Services →— BigMike | Computer Repair Technician, Nanaimo BC
📧 BigMikeNanaimo@gmail.com