Business
Individual
Partners
Intelligence
How we work
Sign in Check my address
Guide · Updated 30 Sep 2026

What to do after a data breach

Your address was in a breach, or a company has told you your details were exposed. These are the first steps, in the order that matters.

Updated 30 Sep 2026Reading time 5 minBy LeakTrace

First, the account itself

  1. Change the password on the account named in the notice. Use a new password you have not used anywhere else.
  2. Change it everywhere you reused it. Exposed passwords are tried on other sites, email first. Any account that shared the password should be treated as exposed.
  3. Turn on two-step sign-in for your email, your bank and any account that can reset other passwords.

Then, what was taken

Read the notice for the kinds of data involved. An email address and an encrypted password carry less risk than a readable password, security answers or card and bank details.

  • Payment details: watch card and bank statements for charges you do not recognise, and ask your bank about a new card.
  • Government ID or date of birth: ask the credit bureaus about a fraud alert, and watch for accounts opened in your name.
  • Email and phone: expect messages that mention the breach and ask you to confirm details. Do not use the links in them; go to the company’s site yourself.

Check for signs someone got in

In your email settings, look for forwarding rules or recovery addresses you did not set. Review recent sign-ins where the service shows them. If you find anything you did not do, change the password again and sign out of all devices.

Keep a short record

Note the date you learned of the breach, what you changed and when. It helps if you need to dispute a charge or report fraud later.

If you run a firm

If staff addresses were in the breach, the same steps apply to each of them, and your IT provider should review sign-ins to email and remote access. If personal information your firm holds was accessed, a reporting duty may apply: under PIPEDA, a breach that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner and to the people affected, as soon as feasible. In the United States, notification rules are set by each state.

Old breaches come back

Breach data is copied, combined and re-shared for years. An address exposed today can appear again in a new collection months later. Checking again from time to time, or a daily re-check under monitoring, catches the new appearance.

Sources
  1. PIPEDA, s. 10.1, and the Breach of Security Safeguards Regulations (SOR/2018-64), Government of Canada
  2. Office of the Privacy Commissioner of Canada, what to do after a privacy breach