A breach notification tells you something leaked, but rarely tells you what to do in which order. Here is the checklist we use, ordered by urgency. First, find out what actually leaked - run our free exposure check to see which breaches include your email and what data types they exposed.
If passwords leaked (do this today)
A leaked password cannot be un-leaked. Change it on the breached site AND everywhere you reused it - attackers test leaked passwords against banks, email, and shops within hours ("credential stuffing"). Turn on two-factor authentication, and use a password manager so every site gets a unique password from now on.
If card or bank data leaked (this week)
Watch the affected statements closely and ask your bank for a replacement card - it takes minutes and removes the risk completely. Banks deal with this constantly; you will not be the strange one asking.
If your SSN leaked (this week, free, underused)
Freeze your credit at all three bureaus - Equifax, Experian, and TransUnion. It is free, takes about ten minutes total, and blocks anyone from opening accounts in your name. You can unfreeze temporarily whenever you actually need credit. This is the single most effective anti-identity-theft step that almost nobody takes.
The part that keeps hurting afterward
Breached data does not stay in criminal forums - it flows into the data broker economy, gets merged with public records, and resurfaces on people-search sites as your address, phone, and relatives, available to anyone. That is why scam calls get eerily specific after a breach. Removing yourself from those brokers is the cleanup step most people skip: do it yourself with our free guides, or have us run it with verified proof and ongoing monitoring.