The first thirty minutes
- Change the password on that service, and on any other site where you used the same one.
- Turn on two-factor authentication there.
- Read what was taken. Passwords and card numbers need action now; names and emails mean more phishing, so be suspicious of related messages for months.
The next day
- If financial details were taken, watch statements weekly and consider a card replacement.
- If government id numbers were taken, ask your country's credit bureaus about a fraud alert or freeze.
- Keep the notification. If the company was negligent, regulators and class actions rely on it.
Keep this evidence
- The breach notification and its date.
- A note of what categories of data the company says were exposed.
Do not
- Do not click links in a "breach notification" email you did not expect; go to the company's site directly.
- Do not pay for "dark web monitoring" upsells; a password manager and two-factor do more.
Who to report to
Usually nothing to report yourself; the company must notify the data-protection regulator. Report if you are then defrauded. Find the numbers and portals for your country in the reporting directory.
General guidance, not legal advice. If someone is in immediate danger, call your police emergency number.