Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Respond to the information that was actually exposed

Separate a breach notice from phishing and protect accounts in an order that matches the risk.

Online and financial-service usersAbout 6 minutes of reading + 3 questions
Go to response steps Received a data-breach notice?

What you will learn

  • Verify a notice without using its link.
  • Decide which passwords, accounts or documents need protection.
  • Recognise follow-up phishing that uses breached information.

A breach is not the same as an account takeover

A data breach means an organisation’s information became available to an unauthorised party. It does not automatically prove that every account was accessed. The risk depends on whether email, password, phone number, card details, documents or other information was exposed.

News of a genuine breach can trigger scams offering a fake password reset, compensation or device scan.

Confirm the scope

Open the organisation’s official site or app independently. Find out what happened, which information was affected and what the organisation recommends. Do not use the contact details in the message you are checking.

Protect accounts in order

  1. If a password you still use was exposed, replace it in official settings. Replace it on every other account where it was reused.
  2. Start with email, banking and work accounts because they may provide access to money, information or recovery of other services.
  3. Enable 2FA or a passkey where available, review active sessions and check recovery details.
  4. If card or banking information was exposed, contact the bank immediately. For identity documents, seek advice from the issuing authority and police according to the circumstances.
  5. Preserve the official notice and record the actions you take.

Expect targeted follow-up scams

Information from the incident can make a later message more convincing. Knowing your name, phone number or old password does not prove the sender is genuine support. Do not pay a person promising to remove the data or guarantee recovery.

Practice example

A message claims a service suffered a breach

Security notice
Today, 09:41

Your password was leaked. Click within 30 minutes and enter your old and new passwords to save the account.

Fictional situation for practice.
Show the example explanation
The breach may be real while the message is fake
Open the service independently and find its official notice.
The old password is requested
Change passwords in official settings, not through an unexpected form.
A short deadline adds pressure
Act promptly through a channel you opened yourself.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A breach message links to an urgent password change. What do you do first?

Why does this matter? Scammers can exploit news of a genuine incident in a new phishing message.

  1. Open the service independently and check its official notice.Correct answer

    This verifies the incident without relying on the suspicious message.

  2. Enter the old password to prove my identity.

    The old password may be the information the attacker is collecting.

  3. Forward the link to every contact.

    Forwarding may spread a fraudulent message.

A leaked password was reused on three accounts. What do you change?

Why does this matter? Attackers may test the same credential on other services.

  1. Only the service that announced the breach.

    Reuse leaves the other accounts exposed.

  2. Every account using it, with a unique password for each.Correct answer

    Unique replacements break the link between services.

  3. Nothing unless an unknown login is visible.

    No current login does not mean the credential will not be tried later.

Card information may have been exposed. Who should you contact first?

Why does this matter? The bank can assess protection for the specific payment instrument.

  1. An unknown person offering identity monitoring.

    An unsolicited offer may be a follow-up scam.

  2. The bank through an official number or app.Correct answer

    A verified bank channel leads to action for the affected account and card.

  3. The original sender through the same link.

    The same channel is not independent verification.

No registration. Your answers are not sent; the result is just for you.

First establish what was exposed

Replace an exposed password everywhere it was reused, starting with email and financial accounts.

Recover a compromised account

References

Sources and further reading

The verification and response order follows NCSC guidance for individuals after a data breach and the Serbian National CERT publication on compromised email and account protection.

Content last reviewed