What to do when your data appears in a breach
Breach notices arrive regularly and most of them require a proportionate response rather than an alarmed one.
The first thing to establish is what was exposed, which the notice has to describe. An email address and a password is a different problem from a government identifier, and the response differs accordingly.
For credentials, change the password at that service and anywhere it was reused, and turn on a second factor. For identity information, a credit freeze is the proportionate step — free to place and lift, and it blocks the main use of the data.
Offered monitoring is worth accepting since it is free, while understanding what it does: it tells you after something has happened. A freeze prevents it. The two are not substitutes and monitoring is the weaker of them.
Expect targeted messages afterwards. Attackers use breach data to make contact convincing, referencing a real account or a real transaction, so scrutiny should go up for a while rather than down.
Still have a question?
Describe what you are trying to work out and a member of the team will answer, or direct you to the office that makes the decision.