Passwords and account credentials
Usernames, passwords, password hints, security questions, authentication tokens, and recovery details can help an attacker take over an account. A reused password also puts unrelated accounts at risk.
- Change the affected password and every reused version.
- Secure your email account first because it can reset other accounts.
- Turn on multi-factor authentication and review recovery methods.
- Sign out other sessions if the service offers that control.
Contact and online activity data
Names, email addresses, phone numbers, physical addresses, IP addresses, device details, location history, and account activity can make phishing more convincing. A scammer may combine accurate details from one incident with information from elsewhere.
Expect messages that refer to a real company or event. Verify unusual requests through a separate channel and avoid giving callers one-time codes.
Identity and government records
Dates of birth, Social Security numbers, driver’s license data, passport details, signatures, and identity-verification answers can support impersonation or new-account fraud. Unlike a password, many of these details cannot simply be replaced.
Review your credit reports and consider a free credit freeze with each nationwide credit bureau. Keep copies of the notice and any identity documents you replace.
Payment and financial information
Card numbers, expiration dates, bank account information, transaction history, tax records, and income details create different risks. A replacement card can address an exposed card number, while an exposed bank account or tax identity may require broader monitoring.
Use the number on your card or financial institution’s official site, review recent transactions, and ask what monitoring or replacement steps fit the information involved.
Health and insurance information
Medical history, diagnoses, prescriptions, insurance identifiers, claims, and patient-account data are sensitive because they can reveal private facts and may support medical identity theft. Review provider bills and explanations of benefits for unfamiliar services or changes.
An incident category is not proof about one person
Breach catalogues and company notices often list all data categories involved in an incident. That does not necessarily mean every category applied to every affected person. Look for a personalized notice, an account message, or a verified company representative who can explain what the organization determined about your record.
Likewise, an email match shows that the address appears in a supported breach record. It does not prove current identity theft, financial loss, or eligibility for a legal claim.
Sources and further reading
- Federal Trade Commission: What To Do After a Data Breach ↗
- Federal Trade Commission: Credit Freezes and Fraud Alerts ↗
- Federal Trade Commission: Use Two-Factor Authentication ↗
Reviewed September 14, 2026. This guide provides general information.
Review a specific breach record.
Each detail page lists the information categories reported for that incident and actions matched to those categories.
Browse data breaches →