Home / Breach Guides / Information exposed
Match the risk to the data

What information can be exposed in a data breach?

“Personal information” can mean anything from an email address to a Social Security number. The right response depends on the specific categories involved and how they could be misused.

Published September 14, 2026 · Reviewed September 14, 2026 · 6 min read

Passwords and account credentials

Usernames, passwords, password hints, security questions, authentication tokens, and recovery details can help an attacker take over an account. A reused password also puts unrelated accounts at risk.

Useful response
  • Change the affected password and every reused version.
  • Secure your email account first because it can reset other accounts.
  • Turn on multi-factor authentication and review recovery methods.
  • Sign out other sessions if the service offers that control.

Contact and online activity data

Names, email addresses, phone numbers, physical addresses, IP addresses, device details, location history, and account activity can make phishing more convincing. A scammer may combine accurate details from one incident with information from elsewhere.

Expect messages that refer to a real company or event. Verify unusual requests through a separate channel and avoid giving callers one-time codes.

Identity and government records

Dates of birth, Social Security numbers, driver’s license data, passport details, signatures, and identity-verification answers can support impersonation or new-account fraud. Unlike a password, many of these details cannot simply be replaced.

Review your credit reports and consider a free credit freeze with each nationwide credit bureau. Keep copies of the notice and any identity documents you replace.

Payment and financial information

Card numbers, expiration dates, bank account information, transaction history, tax records, and income details create different risks. A replacement card can address an exposed card number, while an exposed bank account or tax identity may require broader monitoring.

Use the number on your card or financial institution’s official site, review recent transactions, and ask what monitoring or replacement steps fit the information involved.

Health and insurance information

Medical history, diagnoses, prescriptions, insurance identifiers, claims, and patient-account data are sensitive because they can reveal private facts and may support medical identity theft. Review provider bills and explanations of benefits for unfamiliar services or changes.

An incident category is not proof about one person

Breach catalogues and company notices often list all data categories involved in an incident. That does not necessarily mean every category applied to every affected person. Look for a personalized notice, an account message, or a verified company representative who can explain what the organization determined about your record.

Likewise, an email match shows that the address appears in a supported breach record. It does not prove current identity theft, financial loss, or eligibility for a legal claim.

Sources and further reading

Reviewed September 14, 2026. This guide provides general information.

Find the categories

Review a specific breach record.

Each detail page lists the information categories reported for that incident and actions matched to those categories.

Browse data breaches →