What To Do If Your Personal Information Is Breached or Leaked: A Practical Step-by-Step Guide (Updated 2026)
Data breaches remain extremely common, with record numbers reported in recent years. Sensitive personal information — including Social Security numbers, financial details, tax records, and login credentials — continues to be exposed through ransomware, third-party vendor compromises, social engineering, and large-scale credential theft campaigns.
Major incidents have affected banks, government agencies (including IRS-related data), credit processors, data brokers, and large technology companies. Even when a breach doesn’t directly expose SSNs, compromised credentials from services like Google, Apple, Microsoft, or Meta can enable account takeovers, phishing, and access to emails or cloud storage containing tax documents, bank statements, and other highly sensitive information.
This is general information based on FTC, IRS, and other official sources. It is not legal or tax advice. Consult a qualified Enrolled Agent, CPA, or attorney for your specific situation.
Step-by-Step Guide: What to Do to Protect your Personal Information (Regardless of Any Known Breach)
1.) Obtain an IRS Identity Protection PIN (IP PIN) — free and strongly recommended by the IRS, especially after major SSN exposures. Obtaining a PIN for yourself, your spouse, and any dependent children with a Social Security number will help prevent someone from filing a fraudulent tax return using your information.
To obtain a PIN you will need to create an individual IRS account and follow the steps in the IP PIN section of your profile page. Creating an IRS account and obtaining a PIN takes about 20 min.
If you can’t register for the IRS account (or would like to obtain a PIN for the child) you might be able to obtain a PIN over the phone or in person.
2.) Place a credit freeze with Equifax, Experian, and TransUnion (free and highly effective).
A credit freeze locks your credit file so nobody—not even you—can open a new loan, mortgage, or credit card until you temporarily lift the freeze.You'll do this three separate times because each bureau has its own system. It takes about 5 minutes to put a credit freeze with each credit bureau. Create an account with each credit bureau and then add a credit freeze.
When you decide to get a mortgage or a loan - temporarily unfreeze your credit and apply for the loan.
3.) Monitor your records: IRS tax transcripts via your IRS account, credit reports (free weekly at AnnualCreditReport.com), financial and bank accounts.
4.) Protect Your Children
Many people don't realize that children can also be victims of identity theft.
If your child has a Social Security number, consider placing a credit freeze for them as well. Criminals sometimes use children's SSNs because the fraud can go undetected for years.
5.) Be vigilant against phishing and vishing (voice phishing). Many recent incidents started with compromised credentials obtained this way. The IRS will never call you or email you with a demand to confirm your identity or requesting a payment.
6.) Use unique passwords + a password manager and enable MFA (or passkeys) everywhere. Massive aggregated credential leaks make password reuse particularly dangerous.
7.) Watch for IRS Identity Verification Letters. In recent years, the IRS has significantly expanded its identity theft prevention efforts. If its fraud detection systems identify unusual activity or determine that additional verification is needed before processing a tax return or issuing a refund, the IRS may mail an identity verification letter, such as 4883C, 5071C, or 5747C. Receiving one of these letters does not necessarily mean you are a victim of identity theft—it often means the IRS is taking extra steps to ensure that the return was actually filed by you before releasing your refund. If you receive an unexpected IRS letter requesting identity verification, contact your tax professional before responding so they can help confirm the letter is legitimate and guide you through the process
Notable Recent Data Breaches & Credential Exposures (2024–2026)
Here are significant incidents from the past few years that exposed or risked personal, financial, tax, or account access information. I’ve grouped them for clarity.
High-Impact Breaches Involving SSNs, Financial, or Tax Data
National Public Data (NPD) – 2024: One of the largest ever. ~2.9 billion records on ~1.3 billion people, including SSNs, names, addresses, and DOB. A data broker/background check company compromise with widespread identity theft risk.
Change Healthcare (UnitedHealth) – February 2024: Ransomware attack impacting up to ~193 million individuals. Exposed SSNs, payment/financial information, and medical data. Caused major nationwide disruption to healthcare claims processing.
AT&T – 2024 (with additional datasets in 2025): Exposed SSNs and account details for tens of millions of current and former customers.
Ticketmaster – 2024: ~560 million customer records (names, addresses, emails, order history, and some payment-related data) leaked and offered for sale.
Citizens Financial Group & Frost Bank (via third-party vendor) – April 2026: Citizens (~3.4 million records including account numbers); Frost (>250,000 SSNs/TINs plus W-2s, 1099s, mortgage interest, and HSA data). Highlights third-party risk in banking/financial services.
Pathstone Family Office – 2026: ~641,000 wealth management client records including SSNs, DOB, addresses, and detailed financial profiles.
IRS Contractor Data Theft (Charles Littlejohn) – Data 2018–2020; notifications 2024–2025: Insider theft of tax return information affecting ~406,000 taxpayers (primarily high-wealth individuals/entities). Sensitive financial and tax data was leaked.
Heritage Bank – 2026: Nearly 183,000 individuals’ personal information exposed.
Additional Notable Incidents Involving Major Tech Companies & Credential Risks
16 Billion Credential Mega-Leak (June 2025): Researchers discovered one of the largest credential exposures ever — approximately 16 billion username/password combinations compiled from infostealer malware. Included logins for Google, Apple, Microsoft, Meta/Facebook, Instagram, GitHub, banking portals, government services, and many others. Not a single centralized breach of these companies, but stolen credentials for accounts on their platforms. Extremely dangerous for credential-stuffing attacks and account takeovers that can lead to access to personal emails and cloud-stored documents.
Microsoft Midnight Blizzard Breach (disclosed January 2024): Russian state-backed actors compromised Microsoft’s corporate network (access began November 2023) via password spraying on a legacy test tenant. They accessed emails and documents belonging to senior executives and security/legal teams. While primarily corporate/internal data, such incidents demonstrate risks to cloud and identity infrastructure used by millions.
Charter Communications (Spectrum) – April 2026: ~4.9 million customer records exposed after a vishing attack compromised an employee’s Microsoft Entra ID account, which was then used to access Salesforce data. Another example of social engineering targeting Microsoft identity systems.
Vercel via Context.ai (Google Workspace) – 2026: A Vercel employee’s Google Workspace account was compromised through a third-party AI tool (Context.ai) that had been granted broad OAuth permissions. Data was later listed for sale. Illustrates risks of third-party app permissions in Google/Microsoft ecosystems.
Other notable supply-chain or related incidents (2026) include attacks on Foxconn (8 TB stolen, impacting data tied to clients including Apple, Google, Dell, and Nvidia) and destructive attacks leveraging Microsoft Intune (e.g., Stryker).
These examples show recurring themes: third-party/vendor compromises, social engineering (vishing/phishing), ransomware, and the growing danger of aggregated credential dumps. Even when SSNs aren’t directly stolen, access to email or cloud accounts (Google, Microsoft 365, iCloud) can expose tax returns, financial statements, and other sensitive documents.
What to Do If Prevention did not work and You Became a Victim of Identity Theft
The preventive steps above significantly reduce your risk, but if you believe someone has actually used your personal information, it's important to act quickly. The sooner you report the issue, the easier it is to limit potential damage.
If your Social Security number or tax information was misused:
Report the identity theft to the Federal Trade Commission (FTC) at IdentityTheft.gov. The FTC will generate a personalized recovery plan based on your situation.
Contact your tax professional immediately. If you receive an IRS notice about a suspicious tax return, an e-file rejection because a return has already been filed using your Social Security number, or any other unexpected IRS correspondence, don't ignore it. Your tax professional can help determine the appropriate next steps and, if necessary, assist with IRS identity theft procedures.
Continue monitoring your IRS account, tax transcripts, financial accounts, and credit reports for any suspicious activity.
If your bank account or credit card information was exposed:
Contact your bank or credit card company immediately.
Request replacement account numbers or cards if recommended.
Review recent transactions and report any unauthorized charges as soon as possible.
If your online account credentials were exposed:
Change your password immediately.
If you reused that password on other websites, change those passwords as well.
Enable Multi-Factor Authentication (MFA) on every account where it is available.
If you discover fraudulent credit accounts:
Contact the lender immediately.
File an identity theft report with the FTC.
Dispute the fraudulent accounts with all three credit bureaus (Equifax, Experian, and TransUnion).
If you work with a tax professional
Notify them as soon as possible if you receive any unexpected IRS notices, identity verification letters, or believe your personal information has been misused. Early communication often allows issues to be resolved much more quickly.
Helpful Resources
FTC Identity Theft Recovery: https://www.identitytheft.gov
Report Fraud to the FTC: https://reportfraud.ftc.gov
IRS Identity Theft Central: https://www.irs.gov/identity-theft-central
