A breach is not the same as an account takeover
A data breach means an organisation’s information became available to an unauthorised party. It does not automatically prove that every account was accessed. The risk depends on whether email, password, phone number, card details, documents or other information was exposed.
News of a genuine breach can trigger scams offering a fake password reset, compensation or device scan.
Confirm the scope
Open the organisation’s official site or app independently. Find out what happened, which information was affected and what the organisation recommends. Do not use the contact details in the message you are checking.
Protect accounts in order
- If a password you still use was exposed, replace it in official settings. Replace it on every other account where it was reused.
- Start with email, banking and work accounts because they may provide access to money, information or recovery of other services.
- Enable 2FA or a passkey where available, review active sessions and check recovery details.
- If card or banking information was exposed, contact the bank immediately. For identity documents, seek advice from the issuing authority and police according to the circumstances.
- Preserve the official notice and record the actions you take.
Expect targeted follow-up scams
Information from the incident can make a later message more convincing. Knowing your name, phone number or old password does not prove the sender is genuine support. Do not pay a person promising to remove the data or guarantee recovery.