Start outside the notice
Do not begin with a link, QR code, email address, or phone number printed in the message. Search for the organization’s official website yourself, use the number on a card or statement you already had, or sign in through the app you normally use. Ask whether the organization sent the notice and whether your reference number is valid.
- Write down the sender, date, organization, and incident dates.
- Find the organization through an independent source.
- Ask whether it announced the incident and how affected people are being contacted.
- Compare its official instructions with the message you received.
What a useful breach notice should explain
A real notice normally identifies the organization, describes the incident, gives relevant dates, lists the categories of information involved, and explains actions available to affected people. It should also offer a way to contact the organization. Details vary by incident and jurisdiction, so a missing item is a reason to verify rather than proof of fraud.
Check whether the notice speaks about your information specifically or describes categories for the incident as a whole. Those are different claims.
Warning signs that deserve extra scrutiny
Be cautious when a message demands immediate payment, asks for a password or verification code, requests remote access to your device, promises guaranteed compensation, or threatens arrest or account closure. Shortened links, unexpected attachments, mismatched sender domains, and pressure to keep the conversation secret are also warning signs.
Scammers can imitate a real breach announcement. Even if the incident itself is real, verify the specific message independently.
Respond without giving away more information
Use an independently verified website or phone number. A company that already has your account should not need your password. If credit monitoring is offered, confirm the enrollment address on the company’s official incident page before entering identifying information.
Keep the envelope, message headers, notice, and any confirmation page. These details help if you later need to document what you received or report impersonation.
If you already clicked or replied
Change any password you entered, starting with your email account, and change it anywhere else you reused it. Turn on multi-factor authentication, check account recovery settings, review recent activity, and contact your bank through a verified number if you disclosed financial information. If you shared identity information, consider a credit freeze and use IdentityTheft.gov for a recovery plan.
Sources and further reading
- Federal Trade Commission: Protect Your Personal Information From Hackers and Scammers ↗
- Federal Trade Commission: What are the signs of a scam? ↗
- CISA: Recognize and Report Phishing ↗
Reviewed September 14, 2026. This guide provides general information.
Look up the organization in the breach catalogue.
Compare the public record with the dates and information categories in your notice.
Browse data breaches →