Updated July 2026 · 7 min read · By Silent Erase | ICO Registered C1971457
Discovering your personal data has been exposed in a breach is alarming — but acting quickly can significantly reduce the damage. This step by step guide tells you exactly what to do in the first 24 hours and the weeks after a data breach.
Act immediately:
The faster you respond to a data breach the better. Criminals can begin using breached data within hours. Every minute counts.
Step by Step — What to Do After a Data Breach
1
Find out what was exposed Read the breach notification carefully. What type of data was exposed? Passwords, email addresses, payment details, national insurance numbers or physical addresses all carry different risks. Check haveibeenpwned.com to see all known breaches containing your email.
2
Change your password immediately Change the password for the breached service right now. Use a strong unique password — at least 12 characters with a mix of letters, numbers and symbols. If you used the same password on any other service change it there too.
3
Enable two-factor authentication If the breached service offers two-factor authentication enable it immediately. Also enable it on your email account — this is the most critical account to secure as it is used to reset everything else.
4
Contact your bank if financial data was exposed If payment card details, bank account numbers or sort codes were exposed call your bank immediately. Ask them to monitor your account and consider requesting a new card number.
5
Check your credit report Sign up for free credit monitoring with ClearScore (Equifax) and Credit Karma (TransUnion). Check for any accounts or credit applications you did not make. If you find anything contact the lender and the credit reference agency immediately.
6
Register with CIFAS If sensitive personal data was exposed consider a CIFAS Protective Registration (£25 for 2 years) at cifas.org.uk. This adds a warning to your credit file making it harder for criminals to open accounts in your name.
7
Report to the ICO If a UK organisation failed to notify you of a breach affecting you or handled your data irresponsibly you can report them to the ICO at ico.org.uk or call 0303 123 1113.
8
Remove your data from broker sites After a breach your data often spreads to data broker sites making you easier to target. Silent Erase removes your data from 500+ broker sites automatically under your GDPR rights.
What Different Types of Breached Data Mean
Email and Password Change the password immediately on the breached site and every other site where you use the same password. Enable 2FA everywhere possible.
Payment Card Details Contact your bank immediately to cancel the card and request a replacement. Monitor your statements for unauthorised transactions for at least 3 months.
National Insurance Number Report to Report Fraud and HMRC. Monitor for fraudulent tax returns or benefit claims in your name. Register with CIFAS immediately.
Name and Address Monitor for identity theft attempts. Register with CIFAS. Remove your data from data broker sites which may now list it more prominently.
Medical or Sensitive Data Report to the ICO who takes healthcare breaches very seriously. Consider specialist legal advice as you may be entitled to compensation.
Your right to compensation:
Under UK GDPR you may be entitled to compensation if an organisation's failure to protect your data caused you financial loss or distress. Consider contacting a data protection solicitor if you suffered significant harm.
Get Instant Breach Alerts
Silent Erase monitors the dark web daily and alerts you the moment your email appears in a new breach
Protect Yourself After a Breach
Remove your data from broker sites and monitor for new breaches automatically