
What to do after a data breach is harder to work out than it should be. The notice arrives months after the event, uses language written by lawyers, and offers you something free that may or may not be worth taking. Then a settlement notice may arrive years later asking you to make a decision with a deadline attached. This page routes you to the right answer based on where you actually are.
Before you enter anything anywhere. A legitimate settlement administrator never asks you to pay to file a claim, and never contacts you first to request your Social Security number by phone or email. Use only the settlement website named in the official notice you received.
What to Do After a Data Breach Depends on Where You Are
What to do after a data breach depends entirely on your situation. Four bring people to a page like this, and they need completely different answers. Find yours below rather than reading everything.
Start Here
- A letter arrived saying my data was exposed → Your notification letter, explained
- I think I was affected but heard nothing → How to check whether your data was breached
- A settlement notice arrived and I have to choose something → Cash or credit monitoring: which to claim
- Someone is using my information → What identity theft actually looks like, and what to do
- Something about this feels like a scam → How to spot a fake claim site
What to Do After a Data Breach Letter Arrives
What to do after a data breach letter turns on one sentence: the list of what data was involved, because everything you should do next follows from it.
A name and email address is a low-grade problem, and the sensible response is to expect more convincing phishing attempts. Card numbers mean watching statements and getting the card reissued. A Social Security number is the serious category, because unlike a password it cannot meaningfully be changed, and that is the case where a credit freeze rather than monitoring alone is warranted.
Take any free credit monitoring the company offers. It costs nothing, and accepting it does not waive your rights. Then keep the letter: if a settlement follows years later, that letter records which breach, which data and when.
Read more: Your Data Breach Notification Letter, Explained
What to Do After a Data Breach You Were Never Told About
This is common, and the usual explanation is mundane: the company wrote to an address you have left or an email account you no longer check. Notices go to whatever contact details the breached company held.
Free services let you check whether an email address appears in known breached datasets, which gives you a rough answer. The more consequential check is your credit report, free from all three bureaus, where accounts you do not recognise are the signal that actually matters.
Note that “was my data exposed” and “has my data been misused” are different questions. The credit report answers the second one, which is usually what people want to know.
Read more: Was My Data Breached? How to Find Out
A Settlement Notice Arrived
What to do after a data breach settlement notice starts with a fact: if your information was involved in the breach the case covers, you are already a class member. Nothing you do creates that and nothing you fail to do removes it. What you choose is whether to claim, opt out, or do nothing.
Doing nothing is the option most people take by accident, and it is the only one with no upside: you stay bound by the settlement and receive nothing. Filing a claim usually takes a few minutes.
The choice on the form is normally between a cash payment and free credit monitoring, and which is worth more depends entirely on your situation. If you already have monitoring, or your credit is frozen, the monitoring option is worth little to you. Most settlements also have a third option, claimed far less often, that is frequently worth the most.
📨 Get Free Mass Tort Guides Alerts
Free · No spam · Unsubscribe anytime
- Am I a data breach class member?
- Cash or credit monitoring: choosing a benefit
- Documented losses: the claim most people skip
- What a claim form actually asks for
What to Expect From the Money and the Timing
Two parts of what to do after a data breach settlement surprise almost everyone. The first is how small individual payments are: the headline figure is the whole fund before fees and administration, divided among everyone who claims, and a breach affecting tens of millions produces modest individual shares.
The second is how long it takes. A year or more from filing to payment is normal, because the claim period runs for months, claims must then be validated, a court must give final approval, and an appeal window follows. The silence in between is not a sign anything has gone wrong.
Scams Follow Real Settlements: What to Do After a Data Breach Notice
Fake claim sites are a genuine part of what to do after a data breach, and they are a real problem, and they work precisely because the real thing sounds implausible. A stranger writes to say a company lost your data and you may be owed money, which is exactly how legitimate settlements begin.
Two rules catch almost every fake. You never pay to file a claim — not a fee, not a tax, not postage, since administrators are paid from the settlement fund. And they contact you, you do not verify to them — a real administrator already has the records that identified you and does not phone asking you to confirm a Social Security number.
Be careful with search results too. Fake portals advertise against the names of major settlements, so the first result is not necessarily the official one. Type the address printed on your notice.
Read more: Data Breach Settlement Scams: How to Spot a Fake Claim Site
Someone Is Using Your Information
What to do after a data breach becomes urgent here. Most exposed data is never used against the individual, but if it has been, early detection makes recovery considerably easier.
The usual first signs are an account you did not open appearing on your credit report, a credit inquiry from a lender you never approached, or a small unrecognised charge testing whether a card works. Tax and medical versions are harder to spot: a fraudulent tax return usually surfaces when your own is rejected as a duplicate, and medical identity theft appears only on insurance statements, never on a credit report.
If it has happened, the FTC’s IdentityTheft.gov produces a personalised recovery plan and the official report that banks and credit bureaus ask for. Keep records of everything, including time spent, because documented losses and time are usually reimbursable if a settlement follows.
Read more: What Identity Theft After a Data Breach Actually Looks Like
What to Do After a Data Breach Settlement Notice: Two Deadlines
Almost everything about what to do after a data breach can wait. Two things cannot.
Filing a claim has a deadline stated on the notice, and it is enforced. Opting out has an earlier one, and missing it means you stay in the class and are bound by the settlement whether or not you ever claim.
Opting out is right for a small minority: people with substantial, documented losses clearly larger than the settlement offers, who intend to bring their own case. For everyone else the settlement is the better route, because proving that one specific breach caused your particular harm is the genuinely hard part of this kind of litigation.
Every Guide on What to Do After a Data Breach
- How to spot a fake settlement claim site
- Was my data breached? How to check
- Breach notification letters explained
- Am I a class member?
- Cash or credit monitoring: which to claim
- What a claim form asks for
- Documented losses: the claim people skip
- Why payouts are smaller than headlines
- How long settlements take to pay
- Opting out: what you give up
- What identity theft looks like
- Lawsuit vs settlement: which route
Official Resources
- IdentityTheft.gov (FTC) — the official recovery plan tool and the report banks and bureaus ask for
- AnnualCreditReport.com — the only federally authorised source of free credit reports from all three bureaus
- FTC consumer guidance on identity theft — plain-language guidance and next steps
- IRS identity theft and fraud — the separate process for tax-related identity theft
Browse by Category
You May Also Like
Legal disclaimer. This page is general information about how data breach claims and settlements work. It is not legal advice and does not create an attorney-client relationship. Settlement terms, deadlines and eligibility differ in every case and change over time, so rely on the official notice and the settlement website named in it rather than on any general guide. For advice about your own situation, consult a lawyer licensed in your state. A legitimate settlement administrator never asks you to pay to file a claim, and never contacts you first to request your Social Security number by phone or email.