Technology · January 6, 2026 · Amelia Hart · 6 min
A data breach is when personal information is exposed, lost or stolen. Here are the practical steps to take if you're affected, from changing passwords to monitoring accounts and reporting to the ICO and Action Fraud.
Few things are as unsettling as an email telling you that a company you trusted has lost your data. Data breaches have become a routine feature of online life, hitting retailers, banks, hospitals and social networks alike. The good news is that being caught up in one rarely means disaster, provided you act quickly and methodically. This guide sets out exactly what to do. This is general information, not legal or security advice.
A data breach is a security incident in which personal information is accessed, disclosed, lost or stolen without authorisation.
The data exposed varies enormously. At the milder end, it might be just your email address. At the more serious end, it can include passwords, dates of birth, home addresses, or payment and identity details. Breaches happen in several ways:
What matters for you is not usually how it happened, but what was exposed and what you do next.
Before you act, find out what the breach actually involved. The notification you received — or news coverage — should say. The right response depends heavily on the type of data:
| Data exposed | Main risk | Priority |
|---|---|---|
| Email address only | More spam and phishing | Stay alert to scam messages |
| Password (or reused password) | Account takeover | Change passwords urgently |
| Payment or card details | Fraudulent transactions | Contact your bank |
| Identity details (name, address, DOB) | Identity theft | Monitor closely, consider extra checks |
The single most dangerous situation is a leaked password you have used on more than one site. Criminals routinely try stolen passwords across many services, a tactic that turns one breach into many.
If you have been affected, work through these in order. Speed matters, but so does covering each base.
A password manager makes the first two steps far easier, because it can generate and store a unique password for every account, so a single breach can never cascade across your digital life.
A breach can have a long tail, so keep watch for weeks, not just days.
If you spot anything suspicious, act on it immediately rather than waiting to see whether it gets worse.
Reporting matters: it can help you, and it feeds the wider effort to hold organisations to account and to disrupt fraud.
Keep a simple record of what happened and what you did — dates, reference numbers and any correspondence — in case you need it later.
Under UK data protection law, you have rights over your personal data, and organisations have legal duties to keep it secure and to be transparent when things go wrong. If a breach caused you harm, you may in some cases be entitled to a remedy, but this depends on the specifics. The ICO explains your rights in plain language, and Citizens Advice can help you understand your options if you are unsure what to do. For anything with legal or financial stakes, consider professional advice rather than relying on a general guide. This is general information, not legal advice.
You cannot stop companies being breached, but you can limit what any single breach can do to you:
These habits turn a breach from a potential crisis into a minor inconvenience.
A data breach exposes personal information without permission, and being caught in one is increasingly common rather than catastrophic. The response that matters is fast and orderly: find out what was exposed, change the affected password and any reused copies, switch on two-factor authentication, contact your bank if money is involved, and stay alert to follow-up scams. Report concerns to the ICO and any fraud to Action Fraud, keep a record, and use unique passwords so the next breach cannot ripple across your accounts. Acting calmly and quickly is almost always enough to keep you safe.