What to Do After a Data Breach: Breach Notices, Fraud Alerts, and Credit Reports

Last updated October 7, 2026 · 1,362 words · Identity Theft

A data breach does not automatically mean identity theft; a breach is an exposure of information, while identity theft is the misuse of it. After a breach notice, the usual process is to confirm which data was involved, review credit files for unfamiliar activity, and understand the fraud alert and security freeze options available under federal law.

This guide is general educational information for U.S. readers. It is not financial advice and does not describe your individual credit file. Figures such as score ranges and timeline estimates are typical examples, not promises.

Key takeaways

A data breach is a security incident in which information held by an organization is accessed, copied, or exposed without authorization. A breach does not automatically mean identity theft has occurred — identity theft describes the misuse of that information once someone acts on it. What follows a breach notice is mostly a process of verification: establishing what was exposed, checking credit files for unfamiliar activity, and understanding the protections that exist under federal law.

Does a data breach mean identity theft?

No. The two events are related but distinct. The Federal Trade Commission describes identity theft as the use of another person's personal information to commit fraud, such as opening an account or filing a tax return in that person's name. A breach is a potential exposure of information; misuse is what turns exposure into theft. Many breach notices are sent precisely because the organization cannot determine whose records were actually used.

How much risk a breach carries generally depends on what was exposed. Some data categories are far more useful to a fraudster than others.

Information exposedWhy it matters
Name and email addressUsually not enough on its own; commonly used to build convincing phishing messages.
Account passwordCredentials reused across sites can expose unrelated accounts.
Social Security numberCan support new-account fraud and tax-related fraud.
Driver's license or state ID numberCan support attempts to pass identity verification.
Payment card numberCan support unauthorized charges, which cardholders can generally dispute.
Bank or brokerage account numberCan support unauthorized transfers and account takeover attempts.

What typically happens after a breach notice

Breach notification duties come from a mix of state statutes and sector-specific federal rules, so the timing and contents of notices vary by state and industry. A notice generally explains when the incident happened, what categories of information were involved, and what the organization is offering, which is most often a period of monitoring at no cost to the recipient.

Notices also attract imitation. Messages that look like a breach alert but link to a lookalike website are a standard phishing pattern. Fraudulent messages commonly request a password, a one-time security code, or a payment. The Consumer Financial Protection Bureau maintains a fraud and scams resource that describes how these contacts are usually structured.

The general sequence after a notice tends to look like this:

  1. Identify which data categories the notice says were involved.
  2. Confirm the notice is genuine by reaching the organization through a phone number or website located independently of the message.
  3. Pull credit reports from Equifax, Experian, and TransUnion and compare them against known accounts.
  4. Review the available protections — fraud alerts, security freezes, and monitoring — and which ones fit the situation.
  5. Keep the notice, along with dates, reference numbers, and any correspondence.

Reviewing credit reports after a breach

A credit file is the record that fraud most often leaves behind, which is why reports are the usual starting point. Under the Fair Credit Reporting Act (FCRA, 15 U.S.C. section 1681), consumers have the right to a free credit report from each of the three nationwide credit reporting agencies every 12 months, and the three agencies currently provide free reports weekly through AnnualCreditReport.com.

Items that indicate a problem include:

Errors can be disputed directly with the credit reporting agency and with the company that furnished the information. Under the FCRA, an agency generally must investigate a dispute within 30 days; that period can extend to 45 days if the consumer provides additional information during the initial 30-day window.

More detail on reading a file appears in the credit reports hub and in the credit check overview.

Fraud alerts, security freezes, and credit locks

These protections are frequently confused with one another, but they operate differently and carry different durations.

ProtectionHow it worksDuration and cost
Initial fraud alertRequires businesses to take reasonable steps to verify identity before extending credit.1 year; no cost.
Extended fraud alertSame verification requirement, based on a filed identity theft report.7 years; no cost.
Security freezeRestricts access to the credit file, so most new credit inquiries cannot see it.Free to place, temporarily lift, or remove under federal law.
Credit lockA feature offered by an individual credit reporting agency, governed by contract rather than statute.Terms and availability vary by agency.

Fraud alerts are addressed in FCRA section 605A (15 U.S.C. section 1681c-1), and blocking of information resulting from identity theft is addressed in FCRA section 605B (15 U.S.C. section 1681c-2). The credit freeze guide and credit lock overview explain the mechanics of each.

Data breach credit monitoring: what it does and does not do

Credit monitoring is a notification service. It watches a credit file for changes — a new account, a new inquiry, a new address — and sends an alert when something appears. It does not block an account from being opened, and it does not correct inaccurate information. Its function is to shorten the interval between an event and the account holder learning about it.

Some monitoring products also watch other data sources, such as change-of-address records or documents traded online. Scope differs by provider, and a monitoring subscription is separate from the free protections available under federal law. Breach notices sometimes include a monitoring offer, which is optional; the same consumer rights apply whether or not the offer is accepted. The credit monitoring hub covers how these services are structured.

Does a data breach affect credit scores?

A breach is not an item on a credit report and is not a variable in any scoring model. Scores are calculated from the contents of a credit file, so a score moves only if the file itself changes — for example, if a fraudulent account goes unpaid and is reported as delinquent, or if a new inquiry is recorded.

Most credit scores, including FICO and VantageScore, use a range of 300 to 850. FICO publishes approximate weights for the factors it considers:

FICO factorApproximate weight
Payment history35%
Amounts owed30%
Length of credit history15%
New credit10%
Credit mix10%

VantageScore uses its own factor weighting and does not publish fixed percentages. How credit scores are calculated and FICO vs. VantageScore walk through both models, and the credit score hub covers ranges and factor definitions.

How long items remain on a report matters when a fraudulent account is involved, because a dispute and removal process can run alongside the normal retention period:

If identity theft does occur

Where information has actually been misused, the FTC's IdentityTheft.gov site provides a reporting path that produces an FTC Identity Theft Report and a recovery plan, and the same site explains reporting to the IRS using Form 14039 when the misuse involves a tax return. Identity theft can also be reported to local law enforcement; a police report is a separate document from the FTC report and may be requested by creditors or agencies.

The FTC Identity Theft Report is the document that supports FCRA section 605B blocking of fraudulent information from a credit file, as well as an extended fraud alert. The identity theft hub covers the reporting sequence and the records that are typically produced along the way.

Why breach records and timelines matter

Keeping dated records serves a practical purpose: disputes, fraud alerts, and blocking requests all depend on being able to show when the misuse was discovered and what was reported to whom. Correspondence with a credit reporting agency, a furnisher, or a police department is the evidence that moves a dispute forward under the FCRA framework.

This page is published for education only and is not financial advice.

Compare three-bureau credit scores and reports from a single place. Educational links, disclosed below.

Three Bureau Credit Scores and Reports

CreditMonitored.com may earn a commission from partner links at no additional cost to you.

Frequently asked questions

Does a data breach mean identity theft has happened?

Not necessarily. A breach is an exposure of information, while identity theft is the misuse of that information. Many organizations send notices because they cannot determine whether the exposed records were actually used, so a notice is a prompt to verify rather than evidence of fraud.

What happens first after a data breach notice arrives?

The standard sequence begins with identifying which data categories the notice covers and confirming the notice is genuine using contact details located independently of the message. Credit reports and existing account statements are then compared against known accounts to spot unfamiliar activity.

How is a breach checked against a credit report?

Free reports are available from each nationwide credit reporting agency through AnnualCreditReport.com, and the three agencies currently provide them weekly. Unfamiliar accounts, unauthorized hard inquiries, and incorrect personal information are the items that usually indicate misuse. Errors can be disputed under the FCRA, and an agency generally must investigate within 30 days, or 45 days if additional information is supplied during that period.

Is data breach credit monitoring necessary?

Credit monitoring is a notification service rather than a preventive one: it alerts a subscriber to changes in a credit file, but it does not stop an account from being opened or remove inaccurate items. Some breach notices include a monitoring offer at no cost, and the protections available under federal law, including fraud alerts and security freezes, exist whether or not that offer is accepted.

How long does a fraud alert last?

An initial fraud alert lasts 1 year. An extended fraud alert, which is based on a filed identity theft report, lasts 7 years. A security freeze has no fixed expiration and is free to place, temporarily lift, or remove under federal law.

Does a data breach lower a credit score?

A breach itself is not recorded on a credit report and is not part of any scoring model. Scores are calculated from the contents of a credit file, so a change occurs only if the file changes, for example when a fraudulent account is reported as delinquent. Most credit scores use a range of 300 to 850.

Related guides

Related terms

Sources