Individual awareness course · approximately 50 minutes · 7 modules
After the
Breach
What to do when your personal data has been accessed, exposed or stolen—and how to stay alert to convincing calls, emails, texts and identity fraud.
This course is for anyone who has received a breach notification, discovered that someone accessed their account, or believes an organisation exposed their personal information. It is written for UK learners and uses current guidance from the ICO, NCSC, Ofcom and the UK Government’s national fraud campaign.
Understand what has happened
A breach means personal information was lost, altered, destroyed or accessed or disclosed without authorisation. It does not, by itself, prove that someone has used your identity or stolen money.
Exposure, compromise and fraud are different
Your job is to interrupt this chain as early as possible. The right response depends on which information was exposed, whether it was protected, and whether there are signs it has already been used.
Read the breach notice—but verify the notice itself
A genuine notification should help you understand what happened, what information was involved, the likely consequences, what the organisation is doing and what you can do. Criminals also imitate breach notifications to create urgency.
Write down five facts
- Which organisation and service were involved?
- Which of your data items were affected?
- Was the data merely exposed, or are there signs of account access or fraud?
- When did the event occur, and when did you learn about it?
- What contact route and reference number has the organisation provided?
Your first response
Do the urgent, high-value actions first. Do not try to change every password or contact every agency before you know what was exposed.
Pause and verify
Check the breach through an independent contact route. Do not provide more information just to “confirm” your identity to an unexpected caller.
Identify the exposed data
Credentials, payment details, identity documents and sensitive records call for different actions. Ask the organisation if the notice is unclear.
Protect the control points
Secure the affected service, your main email and any account using the same password. Use a passkey or turn on two-step verification where available.
Contain active harm
Contact your bank for suspicious payments, your provider for an account takeover, or your IT team if a work device or work account is involved.
Record and report
Keep the notice, dates, screenshots, transaction details, names and reference numbers. Report to the route that matches what actually happened.
What not to do
- Do not move money to a “safe account” because a caller tells you to.
- Do not read out a one-time code, password, PIN or recovery code.
- Do not install remote-access software at the request of an unexpected caller.
- Do not reuse one new password across all accounts.
- Do not post the full breach notice or exposed identifiers on social media.
- Do not pay a stranger who promises to recover data, money or an identity for an upfront fee.
Match the exposed data to the action
“My data was breached” is not specific enough to produce a safe plan. Start with the data type and the misuse it could enable.
| Data involved | Main risk | Priority response |
|---|---|---|
| Email and password | Credential testing, email takeover, password resets elsewhere | Secure email first; change affected and reused passwords; sign out other sessions; use passkeys or 2SV. |
| Card or bank details | Unauthorised payments and convincing bank impersonation | Contact the bank through its app, official site or number on the card; review transactions and alerts. |
| Name, address, phone, date of birth | Targeted phishing, account-opening attempts and identity checks | Expect personalised contact; check credit reports; verify every unexpected request independently. |
| Passport or driving-licence data | Identity impersonation or fraudulent applications | If the document itself is lost or stolen, report it to the issuer. If a copy or details were exposed, ask the issuer or breached organisation what action is recommended and monitor for misuse. |
| Medical, care, school or safeguarding records | Confidentiality harm, discrimination, distress or personal-safety risk | Ask exactly what was disclosed and to whom. Escalate urgent safety concerns to the police and seek appropriate specialist support. |
| Work or payroll information | Fake payroll changes, invoice fraud and workplace impersonation | Tell the employer; independently verify changes to pay, bank details and HR requests. |
| Biometric information | A lasting identifier cannot be changed like a password | Ask what representation was exposed, what safeguards protected it and what alternatives or monitoring the provider offers. Secure any password or recovery method linked to the service. |
Your priority actions
Calls, emails, texts and social messages
After a breach, a criminal may know your name, provider, address, transaction history or part of an account number. Knowledge is not proof of identity.
Phone calls: break the script
- Caller ID can be spoofed, including a number that appears to belong to your bank or a government body.
- A genuine organisation will allow you time to verify. Pressure, secrecy and panic are warning signs.
- Never share a one-time passcode, PIN, full password or recovery code.
- Never transfer money to a “safe account” or give an unexpected caller remote control of a device.
- Hang up. Find the number in the official app, on the back of the card, on a statement or on the official website.
Messages: inspect the behaviour, not just the spelling
Modern scam messages can be well written and may use real logos, names and facts. Look for what the message is trying to make you do.
How to report suspicious contact
| Contact | Action |
|---|---|
| Forward it to report@phishing.gov.uk before deleting it. | |
| SMS text | Forward it to 7726 free of charge. Follow the provider’s reply asking for the sender number. |
| Scam mobile call | Send a text to 7726 with the word “Call” followed by the scam caller’s number. |
| App message | Use the app’s own block and report controls; app messages usually cannot be forwarded to 7726. |
| Money lost or account hacked | Contact the bank or provider immediately, then report through Report Fraud; in Scotland call Police Scotland on 101. |
Secure and recover your accounts
A password change is useful only if the attacker cannot remain signed in, reset it again or read the recovery messages.
Secure the email account first
Your main email is often the recovery route for banking, shopping, social media and cloud accounts. If it may have been accessed:
- Use the provider’s official account-recovery process.
- Check for forwarding rules, filters or recovery addresses you did not create.
- Change the password and replace the same password anywhere else it was used.
- Use “sign out of all devices” or remove unfamiliar sessions and connected apps.
- Turn on two-step verification, or use a passkey if the service supports it.
- Check sent, deleted and archived folders for activity you do not recognise.
Use the strongest practical sign-in
The NCSC recommends passkeys over passwords where available because passkeys are resistant to phishing. If a passkey is not available, use a unique password generated or stored by a password manager and enable two-step verification.
If you clicked a link or installed software
- Stop entering passwords or using banking apps on the affected device until it is checked.
- If it is a work device, contact the IT or security team promptly.
- Run a full scan with the device’s supported security software and allow it to remediate findings.
- Apply operating-system, browser and app updates.
- Change important passwords from a different trusted device if compromise is suspected.
Money, identity, evidence and reporting
Reporting a breach, a suspicious message and an actual fraud are three different tasks. Choose the route that matches the event.
Protect money and credit
- Review bank, card, payment-app and shopping-account activity for anything you do not recognise.
- Turn on transaction and login alerts where available.
- Contact the provider immediately about an unfamiliar transaction—use its app, official website, the number on the card or 159 if your bank supports it.
- Check your credit information with all three main UK credit reference agencies: Experian, Equifax and TransUnion. A check of your own report does not reduce your credit score.
- Report unfamiliar applications to the credit reference agency and lender.
- Consider additional identity protection such as Cifas Protective Registration. It is optional, has a fee and can mean extra checks when you legitimately apply for products.
Preserve evidence
Keep the original breach notice, email or text; dates and times; sender addresses and phone numbers; screenshots; relevant statements; website addresses; names of people spoken to; complaint copies; and every reference or crime number. Do not publish full identifiers or sensitive screenshots.
Choose the right route
The breached organisation
Ask what happened, exactly which data was involved, what it has done, what it recommends and how it will help. Make clear when you are making a data-protection complaint.
ICO complaint template →Information Commissioner’s Office
If the organisation has not kept your information safe or you remain dissatisfied, you can complain to the ICO. The ICO recommends giving the organisation an opportunity to investigate first.
Make an ICO complaint →Report Fraud
Use for cyber crime or fraud in England, Wales and Northern Ireland. Call 0300 123 2040 or report online. In Scotland, contact Police Scotland on 101.
Report fraud or cyber crime →Issuer, lender or provider
Tell the bank about suspicious money, the lender about credit in your name, and the issuing body about a document that is actually lost or stolen. Ask for a case reference.
Identity recovery guidance →Stay vigilant without living on alert
Vigilance is a routine, not a permanent state of panic. Use alerts and scheduled checks so you do not have to react to every message.
A practical monitoring rhythm
This is a practical routine, not a legal deadline. Increase or reduce it to match the data exposed, the organisation’s advice and any signs of misuse.
Watch for delayed and repeat targeting
- Password-reset or one-time-code messages you did not request.
- New payees, purchases, credit searches, accounts or bills you do not recognise.
- Changes to contact details, recovery methods or mail delivery.
- A sudden loss of mobile service alongside security alerts—contact the mobile provider from another phone.
- Friends receiving unusual messages from your account.
- “Recovery agents” who know about the original event and ask for a fee or remote access. Victims can be targeted again.
Help children and people who need support
If the data belongs to a child, a person at risk or someone who finds digital processes difficult, agree a simple rule: no money, code, password or account change is made during unexpected contact. Nominate a trusted person to check first. Tell the organisation about age, accessibility or communication needs when complaining.
Look after the impact
People can feel embarrassed, angry or anxious after a breach or scam. Criminals design pressure tactics to work on ordinary human reactions. Record what happened, ask a trusted person for help and use free support rather than hiding the incident.
Your after-breach action card
Stop · Verify · Secure · Watch · Report
- Stop: do not act inside unexpected contact.
- Verify: use an app, statement, card or official website you trust.
- Secure: protect email, affected accounts, reused credentials and active financial access.
- Watch: use alerts and planned checks for account, payment and identity activity.
- Report: tell the organisation, bank or provider, reporting centre, police or ICO according to what happened.
Five truths to keep
- A data breach is not automatic proof of fraud, but it can make future scams far more convincing.
- Caller ID, logos and knowledge about you do not prove who is contacting you.
- Your main email, recovery settings and active sessions matter as much as the password.
- Contact the bank or provider immediately when money or account access is at risk.
- Keep evidence and complain through the correct route; do not publish sensitive details while seeking help.
Primary sources used
- ICO — steps for people affected by a personal data breach
- ICO — how to make a data-protection complaint
- NCSC — data-breach guidance for individuals and families
- NCSC — recognise and report phishing
- NCSC — recovering a hacked account
- NCSC — passkeys and secure sign-in
- Ofcom — what to do about a scam call, text or message
- Stop! Think Fraud — reporting fraud and suspicious contact
- Stop! Think Fraud — identity recovery and credit checks
- Report Fraud — cyber-crime and fraud reporting for England, Wales and Northern Ireland