Phishing defense

Phishing After a Data Breach: How Follow-Up Scams Use Exposed Details

Learn how scammers use breach details to create convincing emails, texts, and calls—and how to verify notices without handing over more information.

A breach can make later phishing attempts feel unusually credible. A scammer may know the affected company, an email address, a phone number, a partial account identifier, or another personal detail. That information is context—not proof that the sender is legitimate.

Generic phishing asks the victim to believe a broad story. Breach-related phishing can name the organization that actually lost data, reference a real service, and imitate the language of credit monitoring, account recovery, compensation, or identity protection.

Message themeWhat the attacker wantsSafer verification
Enroll in monitoringIdentity data, payment, or account credentialsOpen the organization’s official notice independently
Reset your password nowCredentials or MFA codesOpen the known app or type the official domain yourself
Confirm a refundBank or card informationContact billing support through a known channel
Remote security checkRemote-access software or device controlDo not install software from an unsolicited call or message
Legal settlementPersonal information or an advance feeVerify the case and administrator independently

Use a known-channel rule

  1. Do not use the link, attachment, phone number, or QR code in the unexpected message.
  2. Open the organization’s official app or type the known domain.
  3. Find the incident notice or support page from that trusted starting point.
  4. Compare the sender domain, requested action, deadline, and contact method.
  5. Ask support to confirm the exact notice before providing information.

Protect the accounts attackers use for recovery

The most important account is often the email inbox that receives password resets. Secure it with a unique password and strong MFA. Review forwarding rules, recovery addresses, connected apps, app passwords, and active sessions. Then review the affected account and any account that reused the same password.

High-risk signs

Checklist9 signs

Treat these as reasons to stop

  • A demand for a password or one-time code.
  • A request to install remote-access software.
  • A shortened or misspelled domain.
  • An attachment described as a secure notice.
  • Payment required before a refund or monitoring service.
  • Pressure to act before contacting the company.
  • A threat to close an account immediately.
  • A caller who objects when you end the call and verify independently.
  • A request to move the conversation to another messaging app.

If you already interacted with the message

  • Clicked only: close the page, review downloads, and update the browser and operating system.
  • Entered credentials: change the password through the real site, sign out other sessions, and secure the recovery email.
  • Shared an MFA code: contact the account provider immediately and review active sessions and recovery settings.
  • Installed software: disconnect the device from sensitive accounts, remove the software, and obtain qualified technical help.
  • Sent money or card data: contact the financial provider through a known number and document the case.

Reporting and evidence

Keep the original message, full sender details, links without opening them, phone numbers, timestamps, and screenshots. Report the attempt to the affected organization, the relevant email or messaging provider, and the fraud-reporting authority that applies in your location.

FAQ

Does a message become trustworthy if it includes my real address or account number?

No. Exposed or commercially available details can make a fraudulent message more convincing. Verify the request through a channel you already know is legitimate.

Should I call the phone number in a breach email?

Use the number on the organization’s official website, app, card, or prior statement instead of relying on contact details supplied in an unexpected message.

Close the page, avoid entering information, review downloads, change credentials if they were entered, secure the recovery account, and use the organization’s official support path.

Why do phishing attempts increase after a breach?

Attackers can use the affected organization’s name and exposed personal context to imitate support, monitoring, refund, or account-recovery messages.

Sources and further reading