Explainer
What happens to your data after a breach
Where leaked data actually goes, why the scam calls start months later, and what is genuinely worth doing about it.
Being caught in a breach is not something you did. A company you trusted with your details failed to protect them. The useful question is what happens next, and which of the things you could do are actually worth the effort.
Where it goes
Breached data does not sit in one place. It is copied, combined and resold, which is why the effects arrive long after the news coverage stops.
- It gets combined with older breaches. On its own an email address is worth little. Matched against a name, a date of birth and a phone number from three other leaks, it becomes a profile.
- Passwords get tested everywhere else. Automated tools try your leaked password against hundreds of other services, which is why reuse is so costly.
- It gets sold as a targeting list. A leak from an airline is worth real money precisely because those people expect to hear about flights.
- It stays available indefinitely. There is no deleting it once it is out, which is the uncomfortable part.
What is actually worth doing
In order of value
Change the password, and anywhere you reused it
This is most of the benefit right here. Credential stuffing against other sites is the most common consequence of any breach.
Turn on two-factor authentication
It makes the leaked password insufficient on its own.
Expect targeted approaches, and slow down
Someone contacting you who already knows your name, your account number and your recent activity is not proof they are genuine. It is what a breach buys them.
Freeze your credit if identity documents were exposed
Worth doing when the breach included dates of birth, addresses or identity numbers rather than just email addresses.
You can check which breaches include your address at haveibeenpwned.com, which is free, well established, and does not require you to hand over anything you have not already lost.
Should I close the account with the company that was breached?
Usually not, and it rarely helps. Your data has already left, and closing the account does not recall it. Changing the password and enabling two-factor authentication protects you far more. Closing it can even make things harder, since you lose the ability to monitor the account for misuse.
The company offered me free credit monitoring. Is it worth taking?
It is worth accepting since it costs you nothing, but understand what it is. Monitoring tells you after something has happened. A credit freeze prevents it happening at all, and is also free. Take the monitoring, and freeze your credit as well.
Can I make them delete my data?
In many countries you have a legal right to request deletion, and it is worth exercising. It will not affect copies already circulating, which is the frustrating limit of it, but it does reduce what they hold for next time and creates a record.
This happened to them too
First-hand accounts from people who went through the same thing.
I lent my phone hotspot to a stranger at the airport
“I was sitting at Ngurah Rai airport in Bali, just killing time before my flight back. This guy walks up to me pretty…”
A fake alert inside my crypto app cost me $28,000
“I'm still reeling from this, but I need to get the story out there because it’s honestly terrifying how easily it…”
I clicked a fake Fair Work email and my account emailed our suppliers
“Honestly, I still feel like a total muppet over this. I was the restaurant manager of a massive buffet in Sydney CBD.…”