After the Breach · Orvanta Open College
Start
← Back to Short Course Library

Individual awareness course · approximately 50 minutes · 7 modules

After the
Breach

What to do when your personal data has been accessed, exposed or stolen—and how to stay alert to convincing calls, emails, texts and identity fraud.

STOPDo not act inside an unexpected call, email or message.
CHECKUse a trusted app, statement or official website to verify.
ACTSecure accounts, monitor activity and report the right incident.

This course is for anyone who has received a breach notification, discovered that someone accessed their account, or believes an organisation exposed their personal information. It is written for UK learners and uses current guidance from the ICO, NCSC, Ofcom and the UK Government’s national fraud campaign.

If money is moving, an account is being taken over, or someone may be in danger, do not wait to finish the course. Contact the bank or account provider through a trusted channel now. Call 999 for immediate danger.
Each module ends with a short knowledge check. Answers stay in this browser page and are not sent or recorded. This is awareness training, not legal, financial or cybersecurity incident-response advice for a specific case.
Module 01 — of seven

Understand what has happened

A breach means personal information was lost, altered, destroyed or accessed or disclosed without authorisation. It does not, by itself, prove that someone has used your identity or stolen money.

Exposure, compromise and fraud are different

1 · EXPOSUREYour information becomes available to someone who should not have it.
2 · TARGETINGThe information is used to make a message, call or login attempt more convincing.
3 · COMPROMISEAn account, device or payment method is accessed or controlled.
4 · HARMMoney, identity, privacy, reputation, safety or wellbeing is affected.

Your job is to interrupt this chain as early as possible. The right response depends on which information was exposed, whether it was protected, and whether there are signs it has already been used.

Read the breach notice—but verify the notice itself

A genuine notification should help you understand what happened, what information was involved, the likely consequences, what the organisation is doing and what you can do. Criminals also imitate breach notifications to create urgency.

The independent-channel rule
Do not sign in, call, pay or download anything through an unexpected breach message. Open the organisation’s app yourself, type its known web address, use a number from a statement or card, or find the number on its official website.

Write down five facts

  1. Which organisation and service were involved?
  2. Which of your data items were affected?
  3. Was the data merely exposed, or are there signs of account access or fraud?
  4. When did the event occur, and when did you learn about it?
  5. What contact route and reference number has the organisation provided?
Official guidance The ICO says an affected person can ask the organisation what happened, what information was affected and what it plans to do to protect that information. Keep a record of every contact. ICO: steps after a personal data breach.
Knowledge check · 01
A breach notice says your email address and date of birth were exposed. What can you conclude?
Correct answer: Exposure increases risk but is not the same as compromise or fraud. Take proportionate protective steps and watch for signs of misuse.
An email about the breach contains a “secure your account now” button. What is the safest route?
Correct answer: Use a separate, trusted channel. A reply still keeps you inside contact that may be fraudulent.
Module 02 — of seven

Your first response

Do the urgent, high-value actions first. Do not try to change every password or contact every agency before you know what was exposed.

01
Pause and verify

Check the breach through an independent contact route. Do not provide more information just to “confirm” your identity to an unexpected caller.

02
Identify the exposed data

Credentials, payment details, identity documents and sensitive records call for different actions. Ask the organisation if the notice is unclear.

03
Protect the control points

Secure the affected service, your main email and any account using the same password. Use a passkey or turn on two-step verification where available.

04
Contain active harm

Contact your bank for suspicious payments, your provider for an account takeover, or your IT team if a work device or work account is involved.

05
Record and report

Keep the notice, dates, screenshots, transaction details, names and reference numbers. Report to the route that matches what actually happened.

What not to do

If a password is currently being changed by an attacker, money is leaving an account, or your phone suddenly loses service alongside account alerts, treat it as active compromise. Use a different trusted device if possible and contact the relevant provider immediately.
Official guidance The NCSC advises people who shared bank details to contact their bank; people who gave away a password to change it anywhere it was reused; and people who opened a link or installed software to run a full antivirus scan. Work-device incidents should be reported to the IT team. NCSC: if you shared sensitive information.
Knowledge check · 02
You learn that a password was exposed and you used it on three websites. What should you do?
Correct answer: Criminals test exposed credentials on other services. Replace every reused instance with a unique credential.
You clicked a suspicious link on a work laptop. What is the first appropriate escalation?
Correct answer: The organisation needs the opportunity to contain the incident and preserve evidence. Follow its authorised process.
Module 03 — of seven

Match the exposed data to the action

“My data was breached” is not specific enough to produce a safe plan. Start with the data type and the misuse it could enable.

Data involvedMain riskPriority response
Email and passwordCredential testing, email takeover, password resets elsewhereSecure email first; change affected and reused passwords; sign out other sessions; use passkeys or 2SV.
Card or bank detailsUnauthorised payments and convincing bank impersonationContact the bank through its app, official site or number on the card; review transactions and alerts.
Name, address, phone, date of birthTargeted phishing, account-opening attempts and identity checksExpect personalised contact; check credit reports; verify every unexpected request independently.
Passport or driving-licence dataIdentity impersonation or fraudulent applicationsIf the document itself is lost or stolen, report it to the issuer. If a copy or details were exposed, ask the issuer or breached organisation what action is recommended and monitor for misuse.
Medical, care, school or safeguarding recordsConfidentiality harm, discrimination, distress or personal-safety riskAsk exactly what was disclosed and to whom. Escalate urgent safety concerns to the police and seek appropriate specialist support.
Work or payroll informationFake payroll changes, invoice fraud and workplace impersonationTell the employer; independently verify changes to pay, bank details and HR requests.
Biometric informationA lasting identifier cannot be changed like a passwordAsk what representation was exposed, what safeguards protected it and what alternatives or monitoring the provider offers. Secure any password or recovery method linked to the service.
Build a private action listSelect categories only—never type real personal information into a training tool.

Your priority actions

    Do not overreact to an identifier alone. A National Insurance number, address or document number is not protected by changing every account password. Use the action that blocks the likely misuse, and ask the issuing body before cancelling or replacing a document that is still in your possession.
    Knowledge check · 03
    Only your name, address and phone number were exposed. Which response best matches the risk?
    Correct answer: The response should match the data. These identifiers can make scams credible and support identity misuse, but do not prove bank-account access.
    Why is the main email account a priority after credential exposure?
    Correct answer: Control of email can allow an attacker to reset other accounts and hide alerts.
    Module 04 — of seven

    Calls, emails, texts and social messages

    After a breach, a criminal may know your name, provider, address, transaction history or part of an account number. Knowledge is not proof of identity.

    The rule to remember
    The person who contacts you does not control the verification. End the contact and start a new one using details you trust.

    Phone calls: break the script

    INCOMING CALL · DISPLAY SHOWS YOUR BANK’S NAME
    “We are calling because your details were in yesterday’s breach. I know your postcode and the last four digits of your card. Read me the six-digit code we just sent so I can freeze the account.”

    Messages: inspect the behaviour, not just the spelling

    Modern scam messages can be well written and may use real logos, names and facts. Look for what the message is trying to make you do.

    How to report suspicious contact

    ContactAction
    EmailForward it to report@phishing.gov.uk before deleting it.
    SMS textForward it to 7726 free of charge. Follow the provider’s reply asking for the sender number.
    Scam mobile callSend a text to 7726 with the word “Call” followed by the scam caller’s number.
    App messageUse the app’s own block and report controls; app messages usually cannot be forwarded to 7726.
    Money lost or account hackedContact the bank or provider immediately, then report through Report Fraud; in Scotland call Police Scotland on 101.
    Official guidance Ofcom warns that even detailed knowledge about you does not make a caller genuine, because criminals obtain data from breaches and public sources. It advises using a checked number and reporting scam calls or texts to 7726. Ofcom: scam calls and messages.
    Knowledge check · 04
    A caller knows your full name, postcode and bank. What does that prove?
    Correct answer: Personal details can come from a breach, public records or previous scams. They do not authenticate the caller.
    A suspicious text asks you to reply “STOP” to opt out. The sender is unknown. What should you do?
    Correct answer: Replying can confirm that your number is active. Report through the recognised route.
    Module 05 — of seven

    Secure and recover your accounts

    A password change is useful only if the attacker cannot remain signed in, reset it again or read the recovery messages.

    Secure the email account first

    Your main email is often the recovery route for banking, shopping, social media and cloud accounts. If it may have been accessed:

    1. Use the provider’s official account-recovery process.
    2. Check for forwarding rules, filters or recovery addresses you did not create.
    3. Change the password and replace the same password anywhere else it was used.
    4. Use “sign out of all devices” or remove unfamiliar sessions and connected apps.
    5. Turn on two-step verification, or use a passkey if the service supports it.
    6. Check sent, deleted and archived folders for activity you do not recognise.

    Use the strongest practical sign-in

    The NCSC recommends passkeys over passwords where available because passkeys are resistant to phishing. If a passkey is not available, use a unique password generated or stored by a password manager and enable two-step verification.

    Never approve an unexpected sign-in prompt. If codes or approval requests arrive when you are not signing in, deny them and review the account. A criminal may already know the password and be trying to pass the second step.

    If you clicked a link or installed software

    Official guidance The NCSC account-recovery sequence includes checking email forwarding rules, changing hacked and reused passwords, signing all devices and apps out, enabling 2SV, updating devices and warning contacts. NCSC: recovering a hacked account. See also NCSC: passkeys.
    Knowledge check · 05
    You changed an exposed password. Which action helps remove an attacker who may already be inside?
    Correct answer: Existing sessions may survive a password change. Review and end them, and check recovery settings.
    Your phone asks you to approve a login you did not start. What should you do?
    Correct answer: Unexpected prompts can mean someone already has the password. Never approve or share the second factor.
    Module 06 — of seven

    Money, identity, evidence and reporting

    Reporting a breach, a suspicious message and an actual fraud are three different tasks. Choose the route that matches the event.

    IMMEDIATE DANGERCall 999.
    MONEY OR BANK ACCESSContact the bank or payment provider immediately.
    FRAUD OR HACKINGReport Fraud; Police Scotland on 101 in Scotland.

    Protect money and credit

    Preserve evidence

    Keep the original breach notice, email or text; dates and times; sender addresses and phone numbers; screenshots; relevant statements; website addresses; names of people spoken to; complaint copies; and every reference or crime number. Do not publish full identifiers or sensitive screenshots.

    Choose the right route

    The breached organisation

    Ask what happened, exactly which data was involved, what it has done, what it recommends and how it will help. Make clear when you are making a data-protection complaint.

    ICO complaint template →
    Information Commissioner’s Office

    If the organisation has not kept your information safe or you remain dissatisfied, you can complain to the ICO. The ICO recommends giving the organisation an opportunity to investigate first.

    Make an ICO complaint →
    Report Fraud

    Use for cyber crime or fraud in England, Wales and Northern Ireland. Call 0300 123 2040 or report online. In Scotland, contact Police Scotland on 101.

    Report fraud or cyber crime →
    Issuer, lender or provider

    Tell the bank about suspicious money, the lender about credit in your name, and the issuing body about a document that is actually lost or stolen. Ask for a case reference.

    Identity recovery guidance →
    The ICO cannot award compensation. If you suffered damage because an organisation broke data protection law, the ICO says you can ask the organisation directly; a disputed claim may need the courts. Get independent legal advice before paying a claims firm or beginning proceedings.
    Current UK complaint process Under ICO guidance published in June 2026, an organisation has 30 days to acknowledge a data-protection complaint. It must take appropriate steps to investigate, keep you updated and provide an outcome without unjustified delay. ICO: complain to an organisation.
    Knowledge check · 06
    You notice an unfamiliar bank transfer after a breach. What comes first?
    Correct answer: The bank may be able to stop a payment, secure access or help recover funds. Reporting to the police route follows, but does not replace contacting the bank.
    What can the ICO do about a data-protection concern?
    Correct answer: The ICO handles data-protection complaints but does not award compensation or replace documents.
    Module 07 — of seven

    Stay vigilant without living on alert

    Vigilance is a routine, not a permanent state of panic. Use alerts and scheduled checks so you do not have to react to every message.

    A practical monitoring rhythm

    This is a practical routine, not a legal deadline. Increase or reduce it to match the data exposed, the organisation’s advice and any signs of misuse.

    TodaySecure priority accounts, bank access and recovery methods. Save the notice and references.
    This weekReview sessions, forwarding rules, statements, credit information and provider updates.
    Each monthCheck financial and credit activity; review alerts and follow up unresolved complaints.
    When contactedStop, break contact and verify independently—however much the caller appears to know.

    Watch for delayed and repeat targeting

    Help children and people who need support

    If the data belongs to a child, a person at risk or someone who finds digital processes difficult, agree a simple rule: no money, code, password or account change is made during unexpected contact. Nominate a trusted person to check first. Tell the organisation about age, accessibility or communication needs when complaining.

    Sensitive data can create a safety risk, not just a fraud risk. If exposed health, care, location, sexuality, domestic-abuse, safeguarding or children’s information may put someone in immediate danger, call 999. For a non-emergency police matter, use 101 and seek relevant specialist support.

    Look after the impact

    People can feel embarrassed, angry or anxious after a breach or scam. Criminals design pressure tactics to work on ordinary human reactions. Record what happened, ask a trusted person for help and use free support rather than hiding the incident.

    Official support Ofcom lists free, confidential scam support through Citizens Advice in England and Wales on 0808 223 1133 and Advice Direct Scotland on 0808 164 6000. The ICO also maintains an additional-support directory for harms linked to personal-data incidents.
    Knowledge check · 07
    Why can a monitoring routine be safer than reacting to every message?
    Correct answer: A routine supports calm, repeatable decisions. It cannot erase exposed data or replace reporting.
    A “recovery specialist” calls weeks later and knows the amount you lost. What should you remember?
    Correct answer: Information from the first incident can be reused in a follow-up recovery scam.
    Course complete

    Your after-breach action card

    Stop · Verify · Secure · Watch · Report

    1. Stop: do not act inside unexpected contact.
    2. Verify: use an app, statement, card or official website you trust.
    3. Secure: protect email, affected accounts, reused credentials and active financial access.
    4. Watch: use alerts and planned checks for account, payment and identity activity.
    5. Report: tell the organisation, bank or provider, reporting centre, police or ICO according to what happened.

    Five truths to keep

    1. A data breach is not automatic proof of fraud, but it can make future scams far more convincing.
    2. Caller ID, logos and knowledge about you do not prove who is contacting you.
    3. Your main email, recovery settings and active sessions matter as much as the password.
    4. Contact the bank or provider immediately when money or account access is at risk.
    5. Keep evidence and complain through the correct route; do not publish sensitive details while seeking help.

    Primary sources used

    Course content checked against the linked sources on 27 August 2026. Reporting routes and guidance can change; use the live official links for a current incident. This course does not ask for, transmit or store personal information.