What to Do After a Data Breach
Contain first: passwords, MFA, and freezes after a breach notice. Optional monitoring later with published prices; scores not assigned.
Bottom line
What to Do After a Data Breach: finish free controls first, then consider paid tools only for a leftover need you can name. This page does not publish a product score.
Urgent framing
Contain accounts first. Paid monitoring is a later optional step, not a substitute for password changes, MFA, and freezes.
Do these immediately
- Confirm the notice is real (official vendor channels, not a phishing clone)
- Change the breached account password to a unique one
- Change any other account that shared that password
- Enable MFA everywhere you still can
- Watch statements; consider freezes/fraud alerts if financial data was involved
- Only later evaluate monitoring products if residual risk remains
Response plan
-
1Free
Verify the notice, then contain the account
Phishing clones often ride real breach news. Confirm through official vendor channels, then reset credentials on the breached service and any reused passwords.
- Confirm the notice via bookmark or official status page
- Change password now to a unique one
- Revoke suspicious sessions
- Enable MFA
-
2Free
Protect identity rails when financial data may be involved
If SSN or similar data may be involved, use free credit freezes and fraud alerts where available. Bank and card alerts catch misuse faster than unread monitoring dashboards.
- Freeze credit at major bureaus when appropriate
- Watch bank and card activity
- File official reports only through trusted government channels when needed
-
3Free
Assume phishing follows breaches
Attackers know you are anxious. Be skeptical of messages that demand immediate payment, gift cards, or remote-access software. Use bookmarks to reach banks and vendors.
- Do not click urgent vault links in email without verifying
- Do not share one-time codes with callers
- Document what data types the notice claims were involved
-
4Free
Reduce public enrichment that worsens targeting
Broker listings can worsen fraud targeting after a breach. Free opt-outs help; paid removal is optional after containment.
- Search for fresh people-search listings
- Submit free opt-outs
- Consider automation only if volume is high
-
5Optional paid
Optional paid monitoring only after containment
After free steps, Aura may fit if you want ongoing monitoring alerts ($12/mo billed annually Individual, 2026-08-10). Incogni ($7.99/mo billed annually Standard) fits broker automation, not breach undo. Prefer the Aura deal link only deliberately after disclosure. Do not buy out of panic alone.
- Containment complete first
- Match monitoring vs removal jobs
- Read who should not buy
- Verify plan scope before purchase
-
6Optional paid
Product analysis: monitoring only after containment
Aura Individual $12/mo annual and Incogni Standard $7.99/mo annual (verified 2026-08-10) are optional after password rotation, MFA, and freezes where relevant. Buying either as step one usually wastes money.
- Rotate breached and reused passwords first
- Enable MFA everywhere still available
- Evaluate monitoring only for residual alert needs
-
7Free
Scenario: phishing clone of a breach notice
Confirm the notice via official vendor channels before clicking reset links in email. Panic shopping from a fake notice is a second compromise path.
- Open the vendor site from a bookmark
- Avoid attachments on unexpected breach emails
- Contain passwords from a clean device
-
8Free
Skip paid tools if the breached password is still reused elsewhere, if MFA is still off on email, if you expect a product to erase breach consequences, or if you require a published SecurityChecklist score first.
- Finish password rotation and MFA
- No panic purchases
- Affiliate CTAs are optional, not proof
-
9Free
Free remedies that must finish before shopping
Verify the notice, rotate passwords, enable MFA, watch statements, and freeze when financial identifiers may be involved. Panic shopping before those steps is usually waste.
- Notice verified via official channels
- Breached and reused passwords rotated
- Freezes considered when financial data may be involved
-
10Optional paid
Buyer guide: residual monitoring after containment
Aura Individual ($12/mo billed annually, 2026-08-09) can fit leftover alert needs after containment. Incogni Standard ($7.99/mo billed annually) can fit leftover broker listings. Neither undoes the breach.
- Containment checklist complete
- leftover need named in one sentence
- No panic deal-link clicks
-
11Free
Free remedies in the first hour after a breach notice
Change the affected password from a clean device, enable MFA on email, watch statements, and place credit freezes where available. Monitoring subscriptions are optional after containment.
- Free controls first
- Re-check same-day
-
12Free
Scenario: vendor offers free monitoring for a year
Take free containment steps first either way. A complimentary monitoring offer does not replace password rotation or freezes. Evaluate Aura Individual $12/mo annual verified 2026-08-10 only if a leftover alert job remains after the free period plan is clear.
- Free controls first
- Re-check same-day
What this response plan cannot fix
- Undo of data already stolen in the breach
- Guaranteed prevention of all follow-on fraud
- Requests for your passwords or banking data from SecurityChecklist
- A promise that any paid product erases breach consequences
- Invented victim counts or breach sizes
Sources
- Official breach notification / vendor status pages: Use primary sources for each incident; this guide stays generic on purpose
- Credit freeze / fraud alert public guidance: Country-specific processes; confirm with local agencies
- Aura sources: published pricing record starting price verified 2026-08-10
- Incogni sources: published pricing record starting price verified 2026-08-10
- SecurityChecklist methodology: How incident guides stay evidence-based, /methodology/
Final verdict
Contain first: change passwords, enable MFA, watch statements, and freeze credit where available. Shop monitoring only after containment. Overall score is not assigned. Commissions never set incident response.
FAQ
Frequently asked questions
Final verdict: what should I do first?
What should I do first after a data breach?
Should I pay for identity protection immediately?
How much do optional tools cost?
Who should not buy?
Update history
Price captures verified 2026-08-09. Re-check free OS controls and any listed prices same-day before purchase.
Related guides and tools
Hub, tools, and related reading.
- Data privacy hub Hub
- Open the Identity Protection Finder Tool
- Best Data Broker Removal Services Related
- Best Data Removal Services Related
- Are Data Removal Services Worth It? Guide
- Do I Need Identity Theft Protection? Guide
- How we evaluate security products Methodology
- Password managers hub Credential rotation
Expert guides & insights
Related guides
Stay in the same problem space without jumping brands.
Continue with Identity protection finder
Open a live tool or guide for the next practical step.
Ready for a clearer next step?
Continue with a live guide or tool on SecurityChecklist.
Page information & sources
About this page
Contain first: passwords, MFA, and freezes after a breach notice. Optional monitoring later with published prices; scores not assigned.
Corrections
Commercial disclosure
Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.