How To Help a Relative After a Data Breach
What to do in the days and weeks after a relative's personal data has been exposed in a breach.
Last reviewed: 1 June 2026
When a company suffers a data breach, the personal information of customers — email addresses, passwords, sometimes payment details or ID numbers — can end up in criminal hands. Receiving a breach notification is alarming, but acting quickly and calmly with your relative can significantly reduce the risk of harm.
Assess what was exposed
Not all breaches carry the same risk, so the first step is reading the breach notification email or letter together, slowly, rather than skimming it in a panic. Look specifically for which categories of data were involved — a leaked email address alone is far less serious than a leak that includes passwords, card numbers, or a national insurance number, because each one opens a different door for a fraudster. If the notification is vague, check the company's official website or press statement rather than trusting a follow-up email, since scammers sometimes send fake 'your data was breached, click here' messages riding on real breach news. Knowing exactly what was taken determines whether the next step is changing a password or freezing a credit file.
- Passwords: change them on the breached service and any other account using the same password
- Email address: expect an increase in phishing emails to that address
- Payment card details: contact the card issuer immediately
- National ID or passport numbers: consider a fraud alert or credit freeze
Secure affected accounts immediately
Once you know what was exposed, work through accounts in order of sensitivity rather than trying to fix everything at once, which usually leads to nothing getting finished. Start with online banking and the main email account, since email is often the recovery route into everything else — change the password, turn on two-factor authentication, and check for any 'forwarding' rules or recovery email changes a fraudster may have quietly added. Move next to shopping accounts with saved card details, then streaming and social accounts. If your relative reused the breached password anywhere else, that password needs changing everywhere it appears, not just on the site that was breached, since credential-stuffing attacks specifically target reused passwords.
- Change the password on the breached account first
- Enable two-factor authentication if it was not already on
- Check for any unfamiliar sign-ins or recent activity
- Report any suspicious transactions to the bank straight away
Stay alert over the following months
A breach does not end when the headlines do — stolen data is frequently sold on and reused weeks or months later, once the initial rush of password changes has died down and people have relaxed. Keep an eye on bank and card statements for a few months rather than just the first week, and be extra cautious of any call, text, or email that references personal details accurately, since scammers often use breached information to sound convincing — for example, quoting a correct account number to claim they are calling from the bank's fraud team. Remind your relative that a real bank will never ask them to move money to a 'safe account' over the phone, no matter how much personal detail the caller seems to know.
- Watch for phishing emails that reference the breached company
- Monitor bank statements and credit reports for unusual activity
- Be sceptical of any contact claiming to be from the breached company asking for more information
- Consider placing a credit freeze if sensitive ID data was exposed
Conversation script
“I saw that [the company] had a data breach — I wanted to help you work through the steps so we can make sure everything stays safe.”
“The most important thing first is to change the password on that account, and then check if you used the same password anywhere else.”
“We should also keep an eye on your bank statements over the next few months, just in case.”
Frequently asked questions
How do we know if a relative's data is being sold on the dark web?
Free tools such as Have I Been Pwned let you enter an email address and see whether it has appeared in known breaches. This will not cover all exposures, but it is a useful starting check.
Should we contact the company that was breached?
You can, though companies rarely offer more than their public statement. Focus energy on protecting accounts rather than waiting for the company to act.