Skip to content
← All guides

Explainer

What happens to your data after a breach

Where leaked data actually goes, why the scam calls start months later, and what is genuinely worth doing about it.

3 min read

Being caught in a breach is not something you did. A company you trusted with your details failed to protect them. The useful question is what happens next, and which of the things you could do are actually worth the effort.

Where it goes

Breached data does not sit in one place. It is copied, combined and resold, which is why the effects arrive long after the news coverage stops.

  • It gets combined with older breaches. On its own an email address is worth little. Matched against a name, a date of birth and a phone number from three other leaks, it becomes a profile.
  • Passwords get tested everywhere else. Automated tools try your leaked password against hundreds of other services, which is why reuse is so costly.
  • It gets sold as a targeting list. A leak from an airline is worth real money precisely because those people expect to hear about flights.
  • It stays available indefinitely. There is no deleting it once it is out, which is the uncomfortable part.

What is actually worth doing

In order of value

  1. Change the password, and anywhere you reused it

    This is most of the benefit right here. Credential stuffing against other sites is the most common consequence of any breach.

  2. Turn on two-factor authentication

    It makes the leaked password insufficient on its own.

  3. Expect targeted approaches, and slow down

    Someone contacting you who already knows your name, your account number and your recent activity is not proof they are genuine. It is what a breach buys them.

  4. Freeze your credit if identity documents were exposed

    Worth doing when the breach included dates of birth, addresses or identity numbers rather than just email addresses.

You can check which breaches include your address at haveibeenpwned.com, which is free, well established, and does not require you to hand over anything you have not already lost.

Should I close the account with the company that was breached?

Usually not, and it rarely helps. Your data has already left, and closing the account does not recall it. Changing the password and enabling two-factor authentication protects you far more. Closing it can even make things harder, since you lose the ability to monitor the account for misuse.

The company offered me free credit monitoring. Is it worth taking?

It is worth accepting since it costs you nothing, but understand what it is. Monitoring tells you after something has happened. A credit freeze prevents it happening at all, and is also free. Take the monitoring, and freeze your credit as well.

Can I make them delete my data?

In many countries you have a legal right to request deletion, and it is worth exercising. It will not affect copies already circulating, which is the frustrating limit of it, but it does reduce what they hold for next time and creates a record.

Need to report this?

Where to report cyber crime in your country, and where to find support.

Get help

This happened to them too

First-hand accounts from people who went through the same thing.

Related guides