Data breach – what should I do if my data has been breached?

image for what should I do if my data has been breached guidance

Hearing a company or website you interact with has suffered a data breach can be worrying. And we all have so many online accounts now that really, it’s only a matter of time before one of them gets breached and our details end up in the hands of cybercriminals… 

Read on to find out what you should do if (when) one of the websites you use has been breached, and your details along with it… 

How do I find out if my details have been revealed in the data breach?

If you haven’t been notified of a data breach, it’s very hard for you to know if your information has been accessed or not. However, the site haveibeenpwned.com provides free notifications if your email is involved in a data breach, and can also notify you if your password has previously been involved in a data breach. If it has, immediately stop using that password and change it for any other accounts where you’ve used it (though we’d hope you don’t use the same password across multiple accounts, because this is putting your data at risk. Read more here.).

Email and password breaches

If you find out your email has been breached – and by this we mean the email address has been leaked rather than access to your email account being compromised – you may feel panicked. However, in reality, if it’s just your email that’s been breached, this shouldn’t impact your life too negatively. Yes, you’ll receive more spam, but there’s likely no need for you to do any serious damage control – though you may wish to reconsider your relationship with the company that leaked your email.

A lot of people will receive a notification from a breached company, and immediately upon reading the words “breached passwords” fall into a panic and start changing all their account details and passwords. However, a lot of the time your password may not have been made visible to attackers.

This is because most sites probably don’t save your password as a readible text file – instead, they’ll turn it into a scrambled representation of itself before storing it (this is known as password hashing). This means that even if the site is breached, the cyber criminals won’t be able to see what your password is, because it has essentially been encrypted. 

However, our advice would be not to bank on this – it’s probably best to change your password if you suspect your account has been breached, just to be on the safe side. It’s always better to be safe than sorry. 

Steps you should take:

1) Confirm there’s been a data breach

Your first step should be to confirm there’s really been a breach and find out if your information or account has been put at risk by contacting the breached company directly and making sure that what they’re saying makes sense. This is so you can make sure you haven’t been contacted by scammers pretending to be the breached company, trying to get more of your information.

2) Change your passwords 

If you fear your passwords are at risk or have been accessed by cybercriminals, change them immediately. In situations like these, it may be useful to have a password manager, as apps like this allow you to change all of your passwords to new, complex character combinations without you needing to keep track of them in your head. It’s also imperative that you use different passwords for each account (some password managers can help you with this, by highlighting accounts where you’re using the same password), because this means that should one of your account passwords be leaked, the cybercriminals will not be able to use it to gain access to even more of your accounts.

3) Stay alert after the data breach

If you have been part of a data breach, the breached company may send you a notice or even set up a portal to provide breach-related information. You should save all the documents and accept any support and help that they offer. They may also provide suggestions for how to handle the breach and preventing similar things from happening again. Also, pay attention to any mail you receive that is unfamiliar to you, such as notices from HMRC regarding your taxes or any bills from unknown lenders.

4) Initiate a Fraud Alert

A fraud alert will warn lenders that you may have been a victim of fraud. There are three major credit reference agencies (TransUnion, Equifax or Experian) that you can ask to add a fraud alert to your credit report. When you request a fraud alert with any of them, the agency you’ve contacted will notify the other two. This means alerts will be added to your credit reports with those bureaus as well. This fraud alert will stay on your credit report for 90 days, and you can renew the fraud alert when it expires. 

5) Lock your credit file

You should also make sure to check up on your credit report, which you can do for free in the UK now by law. It may be smart to consider adding a security freeze, which is available to you for free. A security freeze prevents creditors from accessing your credit file, and they won’t offer you credit if they can’t access your credit reporting file. This will prevent accounts being opened in your name. Your credit report will only be accessible by unfreezing the account. Therefore, if you’re planning on applying for new credit soon you could consider postponing the security freeze. 

6) Monitor your accounts closely 

Unfortunately, when cybercriminals gain access to sensitive or private information, they may hold on to the information for months or even years after a breach. This means you may even forget about the whole incident before the criminals decide to use your information to carry out identity theft. On top of this, when private or confidential information has been exposed by a cybercriminal, they are likely to share or pool this with other criminals to gain access to even more of your accounts. They may also sell your data on the dark web for others to use. Because of this, it’s really important you monitor your accounts closely for a long time after experiencing a data breach. This can be made a lot easier through setting up extra security alerts and features.

7) Reevaluate your relationship with the company that suffered the data breach

Chances are, the company that’s responsible for your breached information will have some plan in place to support you and advise you on what to do, and you should accept the help that they offer. However, when a company that you’re trusting with your data is breached, it’s imperative that you work out whether you can still trust them with your information or not. You should investigate what they’re going to do to make things right, and whether they initially had the right precautions in place to make sure your data was safe.

Conclusion 

When your data has been breached, the most important thing is that you learn what caused it and how you can prevent it from happening again. Make sure you know what information has been compromised and that the company responsible for the breach is taking the right action to support you and correct its mistakes. 

If you feel as though the breached company mishandled your information or didn’t take the right action to keep your data safe, you should contact them and tell them. If you’re unhappy with their response or if you need any advice, contact the Information Commissioner’s Office (ICO). The ICO is responsible for enforcing a range of laws that regulate communications, networking and data protection -so essentially, they’re responsible for making sure your data isn’t mishandled.

If you are a business or organisation worried about the prospect of a data breach and you would like some advice from our experts, please call +44 (0)1392 247 110 or email us now.