Incident response

Data Breach Response Checklist: What to Do in the First 24 Hours

A practical first-day checklist for securing accounts, preserving evidence, monitoring identity risk, and avoiding follow-up scams after a data breach.

A breach notice creates two separate problems: the original exposure and the wave of follow-up abuse that can arrive afterward. The first day should focus on actions that reduce account takeover, preserve evidence, and keep the user from reacting to a convincing fake notice.

First: confirm the incident through an official channel

Do not start by clicking the link in an unexpected email or text. Open the organization’s known website, use its official app, call a published support number, or locate a notice through a trusted regulator or news source. Record what the organization says was exposed, when the incident occurred, and what it recommends.

Secure the recovery chain

  1. Secure the email account that receives password resets.
  2. Change the affected account password from a trusted device.
  3. Replace reused or closely related passwords on other accounts.
  4. Enable multi-factor authentication, preferring an authenticator app or security key where available.
  5. Review recovery email addresses, phone numbers, trusted devices, active sessions, and app passwords.
  6. Sign out sessions you do not recognize.

Match the response to the exposed data

Data typeImmediate riskPriority action
Email and passwordCredential stuffing and account takeoverChange reused passwords, secure email, enable MFA
Payment cardUnauthorized transactionsContact the issuer, replace the card if advised, monitor activity
Bank account informationTransfer or impersonation fraudContact the bank through a known channel and add monitoring
Government identifierNew-account and identity fraudUse official identity-theft recovery and credit-freeze processes
Health or benefits dataTargeted impersonation and privacy harmPreserve the notice, monitor claims, and verify support contacts
Address, phone, or date of birthMore convincing phishing and account recovery attemptsStrengthen recovery settings and expect targeted messages

Preserve evidence before it disappears

Checklist7 records

Evidence to retain

  • The official breach notice and its date.
  • The categories of information reported as exposed.
  • Support case numbers and names of representatives.
  • Suspicious emails, texts, calls, and login alerts.
  • Account changes, transactions, or claims you did not make.
  • Dates and times of password, MFA, freeze, or replacement actions.
  • Copies of reports submitted to banks, regulators, or law enforcement.

Monitor the right systems

Monitoring should follow the data involved. Payment-card exposure calls for transaction review. Government identifiers may justify credit freezes or fraud alerts. Health or benefits exposure calls for claim review and extra caution around calls that appear to know private details.

Do not install unverified “security” software

A breach notice may recommend a monitoring service, but use the official enrollment path. Do not install remote-access software, browser extensions, mobile profiles, or certificate files because a caller says they are required to secure the account.

First-24-hours checklist

Checklist10 actions

Complete in order

  • Verify the incident independently.
  • Record what data was affected.
  • Secure the recovery email account.
  • Change affected and reused passwords.
  • Enable or strengthen MFA.
  • Review sessions, devices, and recovery settings.
  • Contact financial providers when payment data is involved.
  • Use official identity-theft or credit-freeze channels when appropriate.
  • Preserve notices, logs, and case numbers.
  • Warn family or staff about likely follow-up phishing.

FAQ

Should I change every password after a breach?

Start with the affected account, the email account that controls recovery, and any account where the same or a similar password was reused. Use unique passwords and enable multi-factor authentication where available.

Use a website or phone number you already know is legitimate rather than trusting an unexpected message. Breach news often triggers impersonation and phishing attempts.

What evidence should I keep?

Keep the official notice, dates, affected account details, suspicious messages, transaction records, support case numbers, and a timeline of actions you took.

When should I freeze my credit?

Consider a credit freeze when identity data that could support new-account fraud may have been exposed. Follow the official process for the credit bureaus that apply in your country.

Sources and further reading