How to Check if Your Data Was Breached

When you give your data to organisations or corporations, there’s always a level of risk – even if they have strong data security practices, they can still be breached by malicious actors. In fact, according to the UK government’s annual survey of cyber security breaches and attacks, more than 650,000 businesses or charities experienced a breach or attack in 2025-26. The government even says that this “may underestimate the full extent of the prevalence” of such incidents.
Here’s what that means for people like you: it always pays to check if your data has been breached and act accordingly. In this article, we’ll run through the core steps for checking if your data has been breached and – if so – what you could do about it.
If you’re already aware that you’ve been affected by a data breach, we’d love to help. Find out if you could be eligible to seek compensation by checking out our live claims.
How do I know if my data has been breached?
In many cases, an organisation will contact you directly to make you aware that your data has been exposed – but there are several important things to remember about these notifications.
- It’s not a courtesy – it’s a requirement. As stated by the Information Commissioner’s Office (ICO), organisations must inform the people affected “without undue delay” if the breach is “likely to result in a high risk of adversely affecting individuals’ rights and freedoms.” So, for example, if your financial details have been exposed, you must be notified. This also applies for less obviously serious data: revealing protected characteristics such as your age, marital status or religion can constitute a breach of your right to privacy.
- Receiving a notification could be the beginning, not the end, of a potential claim. It’s not uncommon for organisations to offer some redress for exposing your data, such as making advisors available to discuss what you should do next. However, if you’ve suffered damage as a result of the breach, you could be owed significantly more than a phone call, and shouldn’t let an email notification, however politely worded, discourage you from getting what you deserve.
- The ICO also imposes a duty on organisations to report “certain personal data breaches to the relevant supervisory authority,” often the ICO itself. This bar is much lower than the one for notifying individuals affected, meaning the ICO may be aware that you’ve been affected by a breach long before you’re made aware – if you’re made aware at all.
An organisation may itself announce that it has been affected by a data breach, so it’s worth paying attention to news posted by companies that have access to your most important data, such as energy suppliers, banks, and more.
There’s also one telltale sign of a data breach that’s worse than the rest. If you start receiving requests to reset your password, or you notice suspicious activity – such as, in severe cases, the transferring of funds or unauthorised payments – then there’s a strong possibility your data has been exposed. Hackers don’t necessarily need your exact account logins to start wreaking havoc: if they have access to data that can be used to answer security questions, the knock-on effects of a breach can become much more serious.
Here are some key signs that your information has been misused:
- There are unknown financial transactions listed in your account statements
- New accounts with various organisations, including financial services, have been opened in your name
- There is a marked increase in the number of phishing emails or texts that you receive
- You are notified of login attempts from unfamiliar locations, often from other countries
What should I do if my data has been breached?
If you suspect that your data has been breached, there are several practical things that you can and should do as soon as possible.
- Change your passwords. It’s a pain, but changing your passwords is perhaps the strongest defence you can have against malicious actors looking to exploit your data. Once your data has been exposed, there’s no telling in whose hands it might end up, meaning a data breach from years ago could still cause serious damage… unless you invalidate that data with an updated password.
- Enable two-factor authentication. Two-factor authentication sounds highly technical, but is actually quite a simple concept: rather than relying on one means of logging into an account, you instead use two. In practice, this can mean using a password to log into a site, and then entering a code you receive by text. This means that malicious actors will need more than one piece of information – and, often, more than one device – in order to gain access to your accounts.
- Monitor bank accounts. It can hurt to check your bank balance, especially close to payday, but keeping a healthy eye on your transactions means you’ll hopefully spot suspicious activity before the damage is done.
- Report suspicious activity. Organisations such as banks and energy suppliers often have dedicated anti-fraud teams who can support you if you believe your data has been exposed. Make sure you know how to get in contact with them and the processes they follow.
- Keep any breach notifications! The notification that your data has been exposed is highly valuable when it comes to making a claim. While it may be couched in friendly or boring language, the existence of the notification proves two things: firstly, that you were affected in the breach – and, per the ICO, are at “high risk” of damage – and, secondly, that the organisation admits some level of liability. They were obligated to keep your data safe, and they failed. You may receive such notifications as physical letters, but they are often sent by email. Do not throw away or delete your notifications!
Could I be eligible to make a data breach claim?
Here’s a common misconception: you do not necessarily need to have suffered financial loss to make a claim. The exact eligibility criteria will vary from claim to claim, but you could be eligible to seek compensation if you have suffered material (e.g. financial) or non-material (e.g. emotional) damage.
Not sure if you can claim? We’ve got a handy guide that explains everything about data breach claims.
Pocket might already know about the data breach
Pocket Claim has partnered with expert law firms with decades of experience in pursuing data breach claims, and it’s possible that we’re already tracking a data breach that has affected you.
To check, and find out more about all of our live claims, click the button below.
Frequently Asked Questions
How can I check if my data has been breached?
The most common way is through a breach notification from the organisation involved. You can also check company announcements, follow news reports about cyberattacks, monitor the ICO's investigations, and watch for suspicious activity such as unexpected password resets or unauthorised account access.
Will a company always tell me if my data has been breached?
Not necessarily. Organisations are required to notify affected individuals when a breach is likely to result in a high risk to their rights and freedoms, but not every breach meets that threshold. In some cases, the ICO may be aware of a breach before affected individuals are informed.
What should I do if my data has been breached?
Act quickly by changing your passwords, enabling two-factor authentication, monitoring your bank accounts, reporting suspicious activity, and keeping any breach notifications you receive. These steps can help protect your information and may also support a future compensation claim.
Can I claim compensation if my data was breached?
You may be able to. If an organisation failed to protect your personal data and you suffered material damage, such as financial loss, or non-material damage, such as emotional distress, you could be eligible to make a data breach claim.
How do I know if I'm eligible to make a data breach claim?
Eligibility depends on the circumstances of the breach and the material or non-material damage you've suffered. Even if you haven't lost money, you may still have grounds for a claim if the breach caused distress or exposed sensitive personal information. Pocket can help you check whether you may be eligible.
Why should I keep my data breach notification?
A breach notification confirms that your personal information was involved in the incident and that the organisation recognised there was a significant risk to your rights and freedoms. It can also be valuable evidence if you decide to pursue a compensation claim.

