Home / Breach Guides / Verify a notice
Verify before you respond

How to tell if a data breach notice is legitimate

A convincing logo, case number, or urgent warning does not prove a message is real. Verify the incident through a separate channel before clicking, calling, paying, or sharing information.

Published September 14, 2026 · Reviewed September 14, 2026 · 5 min read

Start outside the notice

Do not begin with a link, QR code, email address, or phone number printed in the message. Search for the organization’s official website yourself, use the number on a card or statement you already had, or sign in through the app you normally use. Ask whether the organization sent the notice and whether your reference number is valid.

A safer verification sequence
  • Write down the sender, date, organization, and incident dates.
  • Find the organization through an independent source.
  • Ask whether it announced the incident and how affected people are being contacted.
  • Compare its official instructions with the message you received.

What a useful breach notice should explain

A real notice normally identifies the organization, describes the incident, gives relevant dates, lists the categories of information involved, and explains actions available to affected people. It should also offer a way to contact the organization. Details vary by incident and jurisdiction, so a missing item is a reason to verify rather than proof of fraud.

Check whether the notice speaks about your information specifically or describes categories for the incident as a whole. Those are different claims.

Warning signs that deserve extra scrutiny

Be cautious when a message demands immediate payment, asks for a password or verification code, requests remote access to your device, promises guaranteed compensation, or threatens arrest or account closure. Shortened links, unexpected attachments, mismatched sender domains, and pressure to keep the conversation secret are also warning signs.

Scammers can imitate a real breach announcement. Even if the incident itself is real, verify the specific message independently.

Respond without giving away more information

Use an independently verified website or phone number. A company that already has your account should not need your password. If credit monitoring is offered, confirm the enrollment address on the company’s official incident page before entering identifying information.

Keep the envelope, message headers, notice, and any confirmation page. These details help if you later need to document what you received or report impersonation.

If you already clicked or replied

Change any password you entered, starting with your email account, and change it anywhere else you reused it. Turn on multi-factor authentication, check account recovery settings, review recent activity, and contact your bank through a verified number if you disclosed financial information. If you shared identity information, consider a credit freeze and use IdentityTheft.gov for a recovery plan.

Sources and further reading

Reviewed September 14, 2026. This guide provides general information.

Check the incident

Look up the organization in the breach catalogue.

Compare the public record with the dates and information categories in your notice.

Browse data breaches →