Skip to main content

Involved in a data breach? Here’s what you need to know

 A bowl of multicolored cereal hoops spilled on a white floor

Posted: September 21, 2023 by

If you've received a message from a company saying your data has been caught up in a breach, you might be unsure what to do next. We've put together some tips which should help you when the (more or less) inevitable happens.

1. Check the company’s advice

Every breach is different, so check the company's official channels to find out what's happened and what data has been breached. Organizations often put out a rolling statement on their website, blog, or X (Twitter). Follow any specific advice they offer first, and keep an eye out for any further communications.

2. Change your password

If your password has been caught up in a breach, you should immediately change it. If you've used the same password on another site or service then you also need to change that. Cybercriminals will often try one password on multiple sites because they know people reuse them, so make sure you use a different password for every single site you have an account on. If you don't already use one, it's worth considering a password manager, which will generate and store passwords for you so you don't have to remember them all in your head.

3. Enable multi-factor authentication

Multi-factor authentication (MFA) adds an extra layer of security when logging in to your online accounts, and stops anyone from logging in with just your password. One of the most common ways of adding MFA to your online accounts is with an app—such as Google Authenticator, Authy, or Microsoft Authenticator—which generates a code that you enter into the site you're logging into. You can also use SMS MFA, where you are sent a code via text that you then enter into the website, or a hardware key such as a YubiKey which you plug into your computer. 

It's worth bearing in mind that a code can be phished as easily as a password so code-based MFA can't protect you from phishing, but it's still much better to have it turned on than not use it at all. Remember to never give an MFA code to anyone else, even if they pressure you into revealing it.

4. Freeze your credit report

If you're in the US, a credit freeze stops new creditors and potential thieves from accessing your credit report. Credit freezes must be set (and removed) at each of the three bureaus.

5. Set up credit monitoring

Credit monitoring tracks your credit report and borrowing behavior and alerts you if anything changes. A breached company may offer this as a service to you, but you can also get different levels of monitoring solutions, depending on your individual need.

6. Watch out for scammers

Scammers often try to take advantage of data breaches. They know that the breached company is likely to be contacting victims, and that the victims will be looking out for emails from the company. It's easy to spoof an email to make it look like it comes from somewhere else, and then send someone malware or a link to a phishing site.

We suggest you monitor the company's website for information about the breach and be very sceptical of messages that appear to come from that company. All the usual advice applies: Look for inconsistencies, odd email addresses, and strange links, and watch out for the two major red flags: urgency and a request for money or personal information.

Comments

Popular posts from this blog

New Year’s Resolution: Getting Your Estate in Order

        Helping families and their businesses plan for the future     Your Most Important New Year’s Resolution: Getting Your Estate in Order   Happy New Year to all. Every January, millions of Americans resolve to lose weight, exercise more, or learn a new skill. These are admirable goals. But there’s one resolution that matters more than all of them combined—one that most people avoid because it forces them to confront their own mortality. Get your estate in order. Not next year. Not when you retire. Now. The Problem With Tomorrow Here’s what I see constantly...

Leasing Set To Surge In 2026?—Credit Unions May Miss Out If They Don’t Move

  CINCINNATI—As credit unions look to revive auto lending in 2026 after a sluggish year, one lending tool may become indispensable: vehicle leasing. With new-car prices still historically high, negative equity rising, and manufacturers fighting for market share, leasing is poised for a major rebound this year—and credit unions that remain on the sidelines risk losing out on strong, recurring loan volume. That’s the message from Scot Hall, executive vice president at  Swapalease.com , who says the economic and market dynamics heading into 2026 are aligning in ways that make leasing not only attractive, but essential. “Prices are up and they’re not coming down anytime soon,” Hall said, noting that inflation, tariffs, supply volatility, and chip-related uncertainty continue to push vehicle pricing higher. “Leasing is a great way to combat that. It’s also a great way to get somebody out of negative equity in a relatively short period of time.” Market Conditions Are Setting the Sta...

NCUA Issues 2026 Supervisory Priorities Letter to Credit Unions

Alexandria, VA (January 14, 2026)  ― The National Credit Union Administration (NCUA) today announced its 2026 Supervisory Priorities, which continue the agency’s policy of “No Regulation by Enforcement,” while prioritizing safety and soundness. This policy underscores NCUA’s commitment to providing clarity and transparency in its oversight. The letter outlines NCUA’s priorities for the year and provides information to help credit unions prepare for examinations. This year, the agency will continue to focus on risk-based supervision, tailoring the examination scope to the credit union’s unique risk profile. Key Highlights of the 2026 Supervisory Priorities: Risk-Focused Examinations:  Examiners will concentrate on areas posing the greatest risk to credit union members, the credit union system, and the Share Insurance Fund. Balance Sheet Management and Lending:  With loan performance at its weakest point in over a decade, examiners will review credit risk management practic...

A 10% Cap, A Busy Congress, And Big Stakes For Credit Unions This Week

WASHINGTON—Credit union trade groups entered the week in Washington closely monitoring developments after President Trump’s proposal for a nationwide 10% cap on credit card interest rates, even as Congress returns to work on funding, financial services reform, and digital asset legislation. Both the Defense Credit Union Council and America’s Credit Unions say the rate-cap proposal poses an immediate threat to consumers credit unions disproportionately serve, while a fast-moving legislative agenda could shape the industry’s operating landscape for years. DCUC President and CEO Anthony Hernandez said the defense-focused trade group mobilized within hours of the President’s announcement, warning the cap could sharply limit access to credit for junior enlisted servicemembers, young officers with student loan debt, and federal workers already strained by a potential shutdown. Anthony Hernandez Hernandez said DCUC began responding within hours, providing comments to the press Friday night an...

Syracuse Fire Department Credit Union

 Congrats, Tonia, on your promotion! ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

What Could Tokenized Deposits Mean for CUs?

WASHINGTON—Noting that the FDIC has expressed support for tokenized deposits as insured bank liabilities, not experimental digital assets, a new analysis offers some insights into what that could mean for financial institutions, credit unions and the market in 2026 and beyond.  As PYMNTS Intelligence pointed out in its report, regulatory clarity reduces risk for banks moving from pilots to live deployments, and large banks and infrastructure providers are already testing real-world tokenized deposit use cases.  “At its simplest, tokenization converts an existing claim into a digital representation on a distributed ledger,” the report explained. “The underlying asset does not change, but the infrastructure that tracks ownership and settlement does. In banking, that distinction is critical. Tokenized deposits do not create new money. They represent traditional bank deposits, issued and redeemed by regulated institutions but designed to operate on modern, programma...

The 10-Year Fixed-Rate Mortgage Worth Bragging About

Sound like anyone we know? “Approximately half of its membership is 50 years old or older, says Star One marketing manager Susanna Fong. The 10-year mortgage is meant to entice those members close to retirement to bring their loans — including the remainder of a 30-year-mortgage — to the credit union.” How Star One’s 14-month-old mortgage product attracts both young professionals and soon-to-be retirees. By Erik Payne creditunions.com For borrowers nearing retirement, desirable mortgage options are limited. Long-term loans can extend into retirement years and cut into savings earmarked for food, travel, and other expenses. Short-term loans can make budgeting difficult for the remaining working years. Star One Credit Union ($7.2B, Sunnyvale, CA) understands that borrowers want to be free of loan obligations before they leave the workforce without breaking the bank to do so. So in January of 2014, the credit union introduced a promotional 10-year fixed-rate mortgage that charges no...

IRS Issues Ruling on Federal Credit Unions and COVID Credit

WASHINGTON–The Internal Revenue Service has issued a ruling that credit unions can receive a 2021 COVID Credit, but not 2020. In other words, federally chartered CUs can’t claim the employee retention credit for periods in 2020 but can do so for periods in 2021, because later amendments to the terms of the credit made them eligible, according to the IRS. Specifically, FCUs can’t claim the credit for wages paid after March 12, 2020, and before Jan. 1, 2021. The ruling was issued by the IRS Office of Chief Counsel in a newly released legal  memorandum . According to the IRS, FCUs are able to claim the credit for wages paid after Dec. 31, 2020, and before Oct. 1, 2021, the IRS said. The Employee Retention Credit (ERC) – sometimes called the Empl...

NCUA Board to Deal With Interest Rate Risk, Loan Workouts, Derivatives

First meeting of 2012 set for next week, includes issues of considerable importance to credit unions. The agency said in its proposed rule that federally insured credit unions with assets of more than $50 million and smaller ones with potentially risky loan portfolios are required to have policies to evaluate the institution’s interest rate risk exposure, set risk limits and test for interest rate shocks. Federally insured credit unions with assets of $10 million to $50 million would have to comply if they hold first mortgages and investments with maturities greater than five years that are equal to or greater than 100% of their net worth.   Read More; NCUA Board to Deal With Interest Rate Risk, Loan Workouts, Derivatives :

Beware of CD Alternatives Being Pushed By Banks

One of my readers told me in an email that an investment guy at his bank was trying to sell him on bonds while he was redeeming a matured CD. In the last month I also have seen this. While I was at PNC and Chase, the bankers referred me to one of their investment advisors. It should be noted that you may also see this at credit unions. Some examples at large credit unions include Golden 1 Investment Services and BECU Investment Services . So I thought it was worth repeating the following advice from Clark Howard :  ***** Read More; Beware of CD Alternatives Being Pushed By Banks : Deposit Accounts