What to Do in the First 24 Hours After a Data Breach Notification

If you've received a data breach notification, act quickly: change affected passwords, check for suspicious activity, enable fraud alerts, and keep the notification itself as evidence. Depending on your circumstances, you may also be entitled to compensation.
What does a data breach notification actually mean?
It’s a message that nobody wants to get: we are writing to notify you that your data may have been affected by a recent data incident. Whatever way it is worded, these notifications are a sign that something has gone wrong and your rights as a consumer could be significantly affected. In fact, according to the Information Commissioner’s Office (ICO), companies are only required to notify individuals for whom the exposure of their data is “likely to result in a high risk of adversely affecting [their] rights and freedoms.” In practice, this can mean the disclosure of your financial information, address, and protected characteristics such as sexuality and religion.
So, if you receive a data breach notification, it’s important that you take action. This article is a complete guide to the first steps you should take in the immediate aftermath of receiving such a notification – the organisation might be responsible for exposing your data, but you can play a significant role in minimising the damaging aftershocks of the breach.
Step 1 – Read the notification carefully and save it

These days, data breach notifications are often delivered by email. That means you should read it carefully and, first of all, check the validity of the sender. If the email uses urgent language or insists you take immediate action, it could be a phishing attempt.
What information was exposed?
Organisations are obligated by the ICO to present the circumstances of the data breach in “clear and plain language,” and include the following details:
- The name and contact details of the organisation’s data protection officer
- The likely consequences of the breach (such as potential access to your bank account or loss of privacy)
- A description of what the organisation has done in light of the breach
The ICO also recommends that organisations give “specific and clear advice” on what affected individuals should do to protect themselves from the consequences of the data breach. We’ll cover that shortly.
Keep a copy – you may need it later
The notification letter is a powerful piece of evidence for your potential claim. Due to the regulations imposed by the ICO, they must include details that are key to securing compensation if you’ve suffered material or non-material damage. A notification admits that you, personally, were affected; that protecting your data was the organisation’s responsibility, and confirms that you are at a high risk of your rights or freedoms being impacted.
So, it’s very important that you keep a copy of any and all such notifications you receive. It’s easy to dismiss these notifications as dull or inconsequential – and the dry, legalistic language can sometimes reinforce that notion – but, when it comes to making a claim, they can be very consequential indeed.
Step 2 – Change your passwords immediately

It’s something we hear often but, when it comes to keeping your accounts secure, there really is no substitute for changing your passwords.
Start with the affected account
This should be obvious: if you’ve been notified that a particular account has been compromised, the password you use should be changed as soon as possible. Even if you haven’t noticed anything strange yet, it’s worth noting that black hat hacker groups can sit on stolen information for many years – until the noise has died down – before exploiting their ill-gotten data. Remember, if you’ve been notified it’s because the organisation has identified a high risk of your rights being infringed – and malicious actors could draw the same conclusion.
Change reused passwords elsewhere too
It can be a pain to keep track of all the different passwords you use, so it’s understandable why you might want to reuse a ‘secure’ password for multiple accounts. In fact, according to Forbes, people reuse their passwords for four accounts on average. Worryingly – and not coincidentally – that same study reported that 46% of those surveyed admitted their passwords had been stolen in the past year.
Once a malicious actor gains access to your details, they’re incentivised to find out where that information can fit, like trying a key in multiple locks. So, if you’re reusing your passwords, that can give them many more opportunities to gain access to more information about you and inflict serious material or non-material damage.
Step 3 – Check for suspicious activity

Have you been receiving strange emails recently? Have you noticed an uptick in the number of spam calls? Perhaps you’ve been notified by retailers like Amazon or PayPal that they’ve detected suspicious login information from overseas or at unusual hours of the day. These are all examples of suspicious activity that could indicate your data has been exposed and one or more of your accounts have been compromised.
If you change your passwords early enough after receiving notification of a data breach, you may be able to avoid such situations – but it’s always worth a check.
Step 4 – Set up fraud monitoring

If you’re worried about serious consequences as a result of the data breach, particularly if the compromised account was valuable or powerful, there are additional steps you can take.
For example, you can set up credit monitoring or bank fraud alerts. These are services provided by many mainstream banks, designed to flag unusual activity in your accounts. Often, there is no additional cost for these services.
You could also consider Cifas Protective Registration. Cifas, formerly known as the Credit Industry Fraud Avoidance System, is a not-for-profit organisation that aims to tackle fraud whose members include the likes of Barclays, JCB and governmental organisations such as Lambeth Council. For a two-year Protective Registration costing £30, you can have a flag placed against your name in Cifas’ National Fraud Database that increases oversight of suspicious financial activity.
Step 5 – Watch out for scam follow-up contact

Due to the regulations surrounding data breaches, their existence can quickly become public knowledge: the ICO publishes quarterly reports of which organisations have suffered data breaches, and the website haveibeenpwned.com also carries a regularly updated list.
From a consumer perspective, this is broadly a good thing. Even if you aren’t notified, it’s possible you could be affected by a data breach – you simply haven’t met the organisation’s reasonable threshold for being at “high risk.” However, this also means that malicious actors can masquerade as the breached organisations and could target its customers with phishing attempts and other scams. It’s worth watching out for suspicious communications even if they appear to come from a trusted source.
Can I claim compensation for a data breach?
In short: yes! If an organisation failed to comply with data protection obligations and you suffered damage as a result, you could be eligible to seek compensation.
At Pocket Claim, we’ve helped to connect hundreds of people affected by data breaches with expert law firms willing to fight their corner. You can find out more about data breach compensation here.
Ready to explore a data breach claim? Check out our live claims below.
Frequently Asked Questions
Is a data breach notification serious?
Yes. Organisations are only required to notify you if the ICO's threshold for a "high risk" to your rights and freedoms has been met — so if you've received one, it means the company itself has assessed the breach as serious enough to warrant a direct warning. It's not routine correspondence, and it shouldn't be treated as junk mail.
How long after a data breach should I change my password?
As soon as possible — ideally within hours of receiving the notification, not days. Hackers sometimes sit on stolen data for months or years before using it, so acting early, even if nothing suspicious has happened yet, is the best way to stay ahead of them. Start with the affected account, then update any other accounts where you've reused the same password.
Can I ignore a data breach notification?
You can, but it's not advisable. Ignoring it won't undo the exposure of your data, and it means missing the window to protect yourself — changing passwords, monitoring for fraud, and watching for follow-up scams. It could also mean losing track of a notification that may later support a compensation claim.
Will I be told if my data was misused?
Not necessarily. The notification tells you your data was exposed and assessed as high risk — it doesn't mean the organisation will proactively update you if that data is later used fraudulently. That's why it's important to monitor your accounts and credit activity yourself rather than waiting to be told.
How do I know if a data breach email is genuine or a scam?
Genuine notifications explain clearly what happened, name the organisation's data protection officer, and avoid pressuring you into urgent action like clicking a link or entering login details. If an email uses urgent language, asks you to "verify" your details immediately, or contains suspicious links, treat it as a possible phishing attempt — even if it claims to come from a company you trust — and check directly with the organisation through its official website or app rather than replying to the email.


