White Rock Advisory

· Cyber Resilience · 5 min read

I think I’ve been involved in a Data Breach. What should I do?

Received a data breach notification, or discovered your details online? Here's what to do next, how to protect yourself, and where to report suspicious activity.

Received a data breach notification, or discovered your details online? Here's what to do next, how to protect yourself, and where to report suspicious activity.

If you’ve been told your personal information may have been involved in a data breach, don’t panic.

You might wonder:

  • Has someone stolen my identity?
  • Should I change my password?
  • Is my bank account at risk?
  • What happens next?

The good news is that being involved in a data breach does not automatically mean you’ve become a victim of fraud. However, it does mean your information may now be available to criminals, making it important to take a few sensible precautions.

The sooner you act, the better.


How do you know you’ve been involved in a Data Breach?

Many people first discover a breach because they receive a notification from:

  • The organisation that experienced the breach.
  • Their password manager.
  • A monitoring service such as Have I Been Pwned.

Sometimes the first sign is more subtle. You may notice unusual login attempts, unexpected password reset emails, or an increase in phishing messages.


What information could be involved?

Every breach is different. Some contain very little information, while others may expose significant amounts of personal data. This could include:

  • Your name.
  • Email address.
  • Mobile or home telephone number.
  • Home address.
  • Date of birth.
  • Passwords or password hints.
  • Financial information.
  • IP addresses.
  • Location data.

The more information exposed, the greater the opportunity for criminals to attempt identity fraud or convincing scams.


Secure Your Accounts

If the breached account used a password, change it immediately.

  • Even if the organisation says passwords were encrypted or hashed, it’s safest to assume the password should no longer be trusted.
  • If you’ve used the same password elsewhere, change it on those accounts as well.
  • Never use that password again, hackers always try password recycling.
  • This is also a good opportunity to begin using a password manager if you don’t already have one.
  • Or where available, consider enabling passkeys. They remove the need for traditional passwords on many services and provide strong protection against phishing attacks.

When changing passwords, refer to creating strong passwords. A simple rule is use 3 random words.

If you suspect an account of yours has been accessed, follow the recover a hacked account guidance.


Turn On Two-Step Verification

Passwords alone are no longer enough. Wherever possible, enable Two Step Verification, also known as 2FA or MFA.

Even if someone discovers your password, they should still be unable to access your account without the second verification method.

This is one of the most effective protections available.


Check whether your details have appeared elsewhere

Services such as Have I Been Pwned allow you to check whether your email address has appeared in known public data breaches.

Don’t forget to register for notifications, which means you’ll be alerted if your details appear in future breaches.

Remember, not every breach becomes public, so continue practising good cyber hygiene regardless of the results.


Watch for Fraud and Scams

Once criminals know your information is available, they may attempt to exploit it. Be particularly cautious of:

  • Emails asking you to reset passwords.
  • Text messages claiming there’s a problem with your account.
  • Phone calls pretending to be your bank.
  • Requests to confirm personal information.
  • Unexpected invoices or payment requests.

Because criminals often know some genuine information about you, these scams can appear convincing.

Always verify requests independently.

Help staff recognise phishing, suspicious messages and social engineering through practical cyber awareness and staff engagement training.


Protect Your Identity

Depending on the type of information exposed, you may wish to consider additional protection. This may include:

  • Registering for protective monitoring through Cifas.
  • Monitoring your credit record.
  • Setting up account alerts with your bank.
  • Watching for unexpected financial activity.

Many banks and credit reference agencies provide free notification services that alert you to unusual activity.

If the nature of your work means you have access to certain sensitive information, you may be a high risk individual, consider this cyber security guidance, and get in touch with us.


Where should you report suspicious activity?

If someone attempts to exploit the breach:

Suspicious emails Forward to report@phishing.gov.uk

Suspicious text messages Forward (free of charge) to 7726

Suspicious phone calls Text: CALL followed by the number to 7726

Bank fraud or payment scams If someone is trying to persuade you to transfer money or reveal banking information, stop the conversation, and call 159 to speak directly with your bank.

If you believe you’ve become the victim of fraud or cyber crime, report it using the appropriate UK Government reporting service.


Practical steps you can take today

You don’t need to do everything at once. Start with these simple actions:

✅ Change any affected passwords.

✅ Stop reusing passwords across accounts.

✅ Enable Two-Step Verification.

✅ Register for breach notifications.

✅ Monitor your financial accounts.

✅ Stay alert for phishing emails and scam phone calls.

✅ Report suspicious activity.

Small actions taken quickly can significantly reduce your risk.


Data breaches are becoming increasingly common.

Being included in one doesn’t necessarily mean criminals will target you, but it does mean you should assume your information may now be circulating more widely than intended. Good cyber security isn’t about panicking. It’s about responding calmly, taking sensible precautions and making it harder for criminals to exploit your information.

If you are managing a data breach, or want to improve a response to a breach, start with this decision makers​ guidance.

You can also test how your organisation would respond to a realistic breach through a cyber incident exercise.

The sooner you act, the more opportunities you remove from those looking to take advantage.


Need Support?

If your organisation is responding to a cyber incident or suspected breach, strengthen the arrangements you rely on with practical incident preparation and response guidance.

Whether your organisation has experienced a cyber incident, needs help responding to a data breach, wants to improve by preparing for incidents before they happen. We provide practical, independent guidance, backed by real-world operational experience, get in touch

Back to Blog
Chat on WhatsApp