Last Checked: Jul 12, 2026Next Check: Jul 12, 2028
Government and primary sources (46 references · 18 cited in article)
- ftc.gov×6cited ×1
- consumer.ftc.gov×4cited ×2
- ic3.gov×3cited ×1
- legiscan.com×3cited ×2
- gao.gov×2
- irs.gov×2cited ×2
- ag.state.mn.us
- annualcreditreport.comcited ×1
- atg.wa.govcited ×1
- codes.findlaw.com
- complaint.ic3.gov
- congress.gov
- courtlistener.comcited ×1
- docs.house.govcited ×1
- documentcloud.org
- dos.ny.gov
- fbi.gov
- hsgac.senate.gov
- identitytheft.govcited ×1
- illinoisattorneygeneral.govcited ×1
- justice.gov
- klrd.gov
- leginfo.legislature.ca.gov
- mn.gov
- ncdoj.gov
- nysenate.gov
- oag.maryland.govcited ×1
- ocrportal.hhs.govcited ×1
- regmedia.co.uk
- scribd.com
- ssa.govcited ×1
- usa.govcited ×1
Research and academic (7 references · 1 cited in article)
Organizations and advocacy (8 references · 1 cited in article)
Industry and standards (38 references · 2 cited in article)
- alstonprivacy.com×2
- huntress.com×2
- verizon.com×2
- advisor.morganstanley.com
- amtrustfinancial.com
- blog.barracuda.com
- blog.qualys.com
- bpslaw.com
- bricker.com
- bytebacklaw.com
- constangy.com
- cybersaint.io
- dataprotectionreport.com
- dexpose.io
- foxgrp.com
- hunton.com
- hyperproof.io
- ibm.comcited ×1
- itech-solutions.com
- jdsupra.com
- khlaw.com
- mcdonaldhopkins.comcited ×1
- murphywall.com
- mvalaw.com
- ogletree.com
- perkinscoie.com
- plainscommerce.com
- reallawgroup.com
- schneiderdowns.com
- security.org
- talli.ai
- transunion.co.uk
- transunion.com
- troutmanprivacy.com
- usi.com
Last updated 4 weeks ago. Our resources are updated regularly but please keep in mind that links, programs, policies, and contact information do change.
Someone found a letter in their mailbox: a company called Conduent, telling them that their personal information had been compromised.
In a personal LinkedIn post, the recipient described receiving a letter from Conduent saying they were compromised, and asked how the company had come to have their information.
That is a solid question.
A breach notice means your information was exposed. It does not mean someone has already stolen your money or opened accounts in your name.
Those two things feel identical when you are holding the letter. They are not. A notification does not necessarily mean your identity has been stolen, but it should still be taken seriously. Exposure is a risk you now have to manage, not a disaster that has already happened.
The rest of this piece is about managing that risk: what the notice actually tells you, what to do in the first days, and how to lock down your credit. And what to do if the scariest line is the one about your Social Security number.
Exposure Is Not the Same as Fraud
Start with the vocabulary, because the news blurs it constantly.
The FBI’s Internet Crime Complaint Center defines a data breach as an intrusion into an organization’s system, network, or database that results in unauthorized access to protected information. That is the event. Someone got into a place they were not supposed to be, and your data was sitting there.
A hack is the technical break-in itself. Identity theft is what happens later, if a criminal actually uses your information to commit fraud. The breach sits in the middle: it is the moment your data left the building.
Think of it like a burglary at a warehouse that stores your belongings. The break-in is real. Whether the thief ever sells your specific box is a separate question.
The scale of these break-ins is climbing. According to the Identity Theft Resource Center, there were 3,322 data compromises in the United States in 2025, a 79 percent increase over five years.
What triggers the letter is usually law. The Federal Trade Commission’s breach response guide for businesses treats data breaches and security breaches involving personal information as events that can require notifying affected individuals. Health providers face a separate rule: entities covered by the federal health privacy law (HIPAA) must report breaches of protected health information to the Department of Health and Human Services, which lists incidents affecting 500 or more people on a public breach portal.
Here is the part that trips people up. A notice sometimes arrives months after the incident, and often tells you little. According to the ITRC, notices offering enough detail to act on fell from 93 percent in 2021 to 30 percent in 2025, while the share withholding how the attack happened rose to 70 percent.
So treat the letter as a starting gun, not a full map.
Your First Few Days
The first move is not dramatic. It is careful.
Breaches breed follow-on scams. A letter or email that pushes you to click a link, call an unfamiliar number, or hand over your Social Security number to “verify” is itself a common trick. Confirm the notice independently by going to the company’s real website or a government resource like IdentityTheft.gov, rather than trusting the message in front of you.
Once you know the notice is real, read what data was involved. That single detail drives everything else.
The FTC’s post-breach guidance points people to IdentityTheft.gov/databreach, which asks what was exposed and returns tailored steps. If a password was involved, change it, and change it anywhere else you reused it. Turn on multi-factor authentication, which means a login needs a second code beyond your password, so a stolen password alone does not open the door.
The practical arc for residents who get these letters generally runs: change usernames and passwords, request new card numbers where accounts were exposed, close compromised accounts if you must, and keep records of every call and letter along the way, per the Maryland Office of the Attorney General’s Identity Theft Program. Documentation is what proves you were a victim if problems surface later.
Then check whether anything has already gone wrong. USA.gov lists the warning signs of identity theft: bills for things you did not buy, debt collectors calling about accounts you never opened, unfamiliar accounts on your credit report, loan denials, and mail that suddenly stops arriving.
Pull your credit reports to look. AnnualCreditReport.com gives you free weekly online reports from Equifax, Experian, and TransUnion. If you spot an account you do not recognize, that is no longer a breach. That is identity theft, and you report it at IdentityTheft.gov, which builds you a recovery plan and generates the letters you will need to send; you can also call 1-877-438-4338 to reach the FTC.
What you generally should not do is panic-close every account you own. Federal guidance advises closing clearly compromised credit card accounts immediately while consulting your financial institution about whether to close or monitor other accounts, alongside placing fraud alerts and watching your credit reports.
Freezes, Alerts, and Monitoring: What Each One Actually Does
Three tools get thrown at breach victims, and they are not interchangeable. Two are barriers you control. One is a smoke detector.
A credit freeze is the strongest of the three. When it is on, “nobody can open a new credit account in your name, including you,” the FTC explains, because lenders cannot pull your frozen report.
It does not touch your existing cards, and it does not dent your credit score. Under federal law, placing and lifting a freeze is free. You set one up separately with each of the three bureaus.
A fraud alert is lighter. It tells lenders to verify your identity before opening credit, but it does not block them from seeing your report.
You place one by contacting a single bureau, which must notify the other two. Initial alerts last a year. Extended alerts, for confirmed identity theft victims who provide documentation like a police report, run about seven years.
Credit monitoring, the service companies love to hand out after a breach, is the smoke detector. It watches for new accounts and inquiries and tells you when they appear. It does not prevent.
| Feature | Credit freeze | Fraud alert | Credit monitoring |
|---|---|---|---|
| Primary function | Blocks most new credit accounts | Requires lenders to verify your identity | Alerts you to changes on your report |
| Who sets it up | You, with all three bureaus | You, with one bureau that tells the others | A company, often after a breach |
| Cost under federal law | Free to place or lift | Free to place | Often free when offered; otherwise a subscription |
| Effect on credit score | None | None | None |
| Effect on new credit | Must lift to apply | Applications proceed with extra checks | No barrier |
Source: FTC consumer guidance on credit freezes and fraud alerts and AnnualCreditReport.com.
The practical takeaway: after a serious breach, a freeze plus any free monitoring on offer gives you a barrier and an alarm. The monitoring alone gives you only the alarm.
If Your Social Security Number Was Exposed
This is the line that keeps people up at night, and for a reason a credit card number never will: you cannot change your Social Security number, and criminals can reuse it for years.
The largest illustration is the breach at National Public Data, a private data broker. IBM reported that a criminal group known as USDoD allegedly posted a database containing 2.9 billion records, including names, Social Security numbers, addresses, and details about relatives, some stretching back decades. That figure counts database rows, not people; duplicate entries inflate it well beyond the US population, and researchers who examined the data found a far smaller number of unique individuals.
Christopher Hofmann sued the company behind it, Jerico Pictures, in a class action filed August 1, 2024, in the Southern District of Florida.
The complaint alleges the exposed data was not scrambled for protection and not blacked out, and argues that the risk to victims will last their whole lives. That phrase reflects a plaintiff’s argument, not a court’s finding, but it names something real.
None of that means you are helpless. It means you use tools built for a permanent identifier.
The Social Security Administration directs people who suspect their number was stolen to report it through the FTC at IdentityTheft.gov, and it generally will not issue a new number solely because of a breach. So you protect the number where it is used.
Freeze your credit, which blocks the new-account fraud a stolen number enables. Then handle the tax angle.
The IRS offers an Identity Protection PIN, a six-digit number that must appear on your tax return for the IRS to accept it, which stops someone else from filing in your name. It is valid for one calendar year, a new one is generated annually, and the IRS will never ask for it by phone, email, or text. If you cannot set up an online account and your income is below $84,000 for individuals or $168,000 for joint filers, you can apply using Form 15227.
Watch for the tax red flags too: a return rejected because one already exists under your number, a W-2 from an employer you never worked for, or a notice about income you never earned. Any of those, and the IRS points you to Form 14039, the Identity Theft Affidavit, which invalidates a fraudulent return filed with your information.
Why the Standard Remedies Feel Thin
Here is the uncomfortable truth underneath the free monitoring.
The Equifax breach is the reference point. It exposed Social Security numbers, birth dates, and addresses for roughly 147 million people.
The breach resulted from Equifax’s failure to fix a known software security flaw, and the company waited roughly six weeks after discovering the intrusion before disclosing it to the public.
The settlement was valued at up to $700 million, with reimbursement up to $20,000 per person and pay for up to 20 hours of time at $25 an hour. Yet many claimants who chose the cash option received only about $5 to $6 each, because the $31 million cash pool was split pro rata across millions of people.
Breaches inflict harm through ongoing risk and anxiety even when no fraud has yet occurred, according to the Texas Law Review article “Risk and Anxiety: A Theory of Data‑Breach Harms,” by law professors Daniel Solove of George Washington University and Danielle Keats Citron, now the Jefferson Scholars Foundation Schenck Distinguished Professor in Law at the University of Virginia after previously teaching at Boston University. The law, the article contends, tends to recognize only completed financial loss, which leaves the lived experience of exposure uncompensated.
Breached organizations tell a different story. Notification is constrained by law and by forensics.
Washington State, for instance, requires notice “in the most expedient time possible” and within 30 days, but allows delay to determine the breach’s scope or when law enforcement asks.
Larry Ponemon of the Ponemon Institute runs annual studies with IBM. Its 2025 report puts the global average breach cost at $4.44 million, with the US average at an all-time high of $10.22 million, and the average time to identify and contain a breach at 241 days. From that vantage, free monitoring is a scalable minimum standard that regulators accept, not a complete fix.
Both things can be true. The remedy is standardized and defensible, and it still leaves the individual left carrying most of the long-term risk.
The Patchwork Nobody Designed
The reason breach letters vary so wildly is that no single federal law governs them. Notification is a state-by-state quilt, and even the strong states disagree with each other.
California’s SB 446, signed into law in October 2025, replaced a vague reasonableness standard with a hard rule. In the bill’s own words: This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach…
New York got there first. Its amendment to General Business Law 899-aa, approved in late December 2024, set a 30-day deadline for businesses and closed with the line “§ 3. This act shall take effect immediately.” But it left state agencies on the older, open-ended standard, so even within one state, public and private actors run on different clocks.
California was joining Colorado, Florida, Maine, New York, and Washington in adopting a 30-day rule. Convergence, yes. Uniformity, no.
Testimony submitted to the House Energy and Commerce Committee has described the state-by-state approach as a patchwork of rules that is burdensome and confusing for organizations and individuals alike. For a company hit by a breach spanning every state, good-faith compliance means reconciling dozens of triggers and timelines before a single notice goes out. Every day spent on that reconciliation is a day you do not know.
The Question That Outlasts the Freeze
The tools in this piece work. A freeze does stop new-account fraud, and an IP PIN does block a fraudulent tax return. What none of them resolve is the structural problem underneath.
You did not choose to be in most of these databases. National Public Data aggregated information on people who had never heard of it.
That is the tension the current system leaves unanswered. The people bearing the lifelong risk are the ones with the least say over how their data was collected, stored, or protected. Jen Easterly, who led CISA from 2021 until stepping down in January 2025 and now serves as chief executive of the RSA Conference, has argued that responsibility for security should move to the companies that build the technology, not the end users who are left patching insecure design at their own expense.
Whether Congress ever builds the single federal standard that both advocates and industry keep circling remains an open question. Until it does, your protection is mostly your own to assemble, letter by letter, freeze by freeze.
So when the next notice arrives, and for most people it will, the useful reaction is not the panic in that first question. It is the quieter one that comes after: not how do they have my information, but which specific steps do I take now.
Our articles make government information more accessible. Please consult a qualified professional for financial, legal, or health advice specific to your circumstances.