All articles

What to do after a data breach

Kent — founder, former banking CTO/CIO · August 22, 2026

Stay calm

Sooner or later the email arrives: a company you'd half-forgotten you had an account with was breached, and your data "may have been involved." Unsettling — but not a crisis if you work through it in order.

Most of the damage comes not from the breach itself but from what you reused elsewhere. So the response is mostly containment. Here's the calm version, first things first.

Contain it

The first hour

Three moves, in order — this is where a breach is contained or spreads.

01
Change the breached password

Start there, then every account sharing it or a close variant. This step is where a breach stops — or doesn't.

02
Turn on two-factor (or a passkey)

A leaked password is far less useful with a second factor behind it. Prioritize email and bank.

03
If identity data leaked, freeze your credit

SSN, date of birth, or full address exposed? A credit freeze is free, reversible, and blocks new accounts opened in your name.

Keep watch

Then, over the next week

The urgent part is done. Now watch for the fallout — and close the habit that let it spread.

Watch for follow-on scams

Breaches feed convincing phishing — "confirm your account" messages that use real details. Assume it, and verify separately.

Check statements and logins

Skim bank and card activity, and review recent-login lists on your key accounts for anything you don't recognize.

Retire the reused password for good

Make each new one unique. The goal: the next breach touches one account, not twelve.

A shiny new brass padlock beside an older weathered one on a table

The quieter lesson

Why some breaches cost less

A breach is scary because your data is everywhere — every signup left a copy of the same details with another company, each its own breach waiting to happen. That's the scattered-identity problem in its least fun form. You can't un-give what you already handed over, but you can stop widening the blast radius — and make sure the place holding your most sensitive information is one a breach can't read.

That's the real payoff of zero-knowledge encryption: breach the vault holding your identity and attackers get scrambled bytes with no key — nothing usable. Less to lose is the best breach plan there is.

The best breach plan is less to lose

Simply Once keeps your identity and documents in a zero-knowledge vault — so if it's ever breached, there's nothing readable to take.

Part of the guide to protecting your personal data online →

Get the monthly note

One useful, jargon-free email a month on keeping your digital life organized and protected — no spam, unsubscribe anytime.

No spam, ever. Unsubscribe anytime.