Why you got the letter
Every US state, along with the District of Columbia, Guam, Puerto Rico and the US Virgin Islands, has a law requiring organisations to tell people when their personal information is involved in a security breach. Some industries carry their own federal rules on top of that. The letter is a legal obligation, not a courtesy, and it is triggered by what the organisation believes was taken.
The letters read alike because they are drafted by the same handful of law firms and insurers. They are also written defensively, which is why the wording hedges so much.
What the vague wording is hiding
"May have been affected" and "unauthorised access to certain systems" are cautious phrasing, not a claim that nothing happened. A company often cannot prove which records an intruder actually copied. When a letter names a category of data, the safe reading is that your record was in the set that was accessible.
Timing is the other thing the letter will not make obvious. The gap between intrusion and notification is routinely months, because the investigation and the legal review take that long. The notification arrives long after any window in which you could have prevented the exposure.
"Dark web" appears in a lot of these letters. It means data was found being offered or traded somewhere illicit. It does not mean your identity has been used, and it does mean someone has a list with your details on it, which is what raises the risk of targeted phishing.
Verify the letter before you act on it
Breach letters are a favourite disguise for phishing, because they arrive when you are already anxious and already expecting bad news.
Do not use the links or phone numbers printed in the letter. Open the company's website yourself from a search or from your browser history, and use the customer service number on a statement, invoice or card you already have. If the breach is real, the company will have the same information on its own site. If it is a phishing attempt, that is where the trail ends.
Check whether the sender domain matches the company rather than a lookalike, and be sceptical of any letter that asks you to confirm a password, a card number or a one-time code in order to "complete" the notification.
What to do depends on what was exposed
Work out what was in the set the letter describes, then act on that and nothing else. Doing everything is not better than doing the right things, and it burns attention you will want later.
Passwords: change the password on that account, then change it anywhere you reused it. Reuse is what turns one breached account into ten.
Card or bank account numbers: watch the account, and expect the issuer to reissue. If a card number was in the set, it is compromised whether or not it has been used yet.
Social security or tax identifiers: this is the case that justifies a credit freeze and a tax identity protection PIN, because those are the two doors a stolen identifier is most often used to open.
Government identity documents: you may need to ask the issuing agency for advice, because those documents can be used to impersonate you in ways credit monitoring will never see.
Health records: check the explanation of benefits statements you get from your insurer. Fraud against a medical plan shows up there first.
Contact details only: the risk is phishing, not financial. Expect targeted messages that reference the breach, and treat unsolicited contact with suspicion.
Credit monitoring is not a credit freeze
Almost every breach letter offers a year of free credit monitoring, and it is worth taking, but it is worth understanding what you accepted. Monitoring watches your reports and alerts you after something appears on them. It is detection.
A credit freeze is prevention. It blocks new lenders from pulling your file, so an account cannot be opened in your name while the freeze is in place. It is free by federal law, it takes minutes, and it is the stronger action whenever a social security number or a government identifier was exposed.
If you are not sure which one the situation calls for, place the freeze and keep the monitoring. Freezing a file does not stop you from using the credit you already have, and it does not affect your credit score.
Turning the letter into a checklist
Once you have verified the letter is genuine, work through this in order. The whole thing takes an evening.
- 01Write down what the letter says was exposed, and the date range it covers, in your own notes.
- 02Change the password on the affected account and on every account that shares it, and turn on two factor authentication wherever it is offered.
- 03If identifiers were exposed, place a freeze at all three credit bureaus, and set a tax identity protection PIN with the IRS.
- 04Pull your credit reports and read them for accounts and inquiries you do not recognise. You are entitled to free reports from each bureau.
- 05Check whether the exposed email address, phone number or password shows up in other breach records, because a set that is circulating is usually in more than one place.
- 06Keep the letter and your notes. If you do end up reporting identity theft, the timeline you wrote down is the evidence.
What a lookup can and cannot tell you
A breach and exposure lookup answers one narrow question well: which records containing this identifier are in circulation, and which source each record came from. That is useful for prioritising, because it tells you whether the letter you received is the only place your address appears.
It cannot tell you whether anyone has used your data, and no legitimate service can. Usage shows up in your accounts, your credit file and your tax records, which is where you should be looking next.