Receiving a data breach notification letter is alarming enough. Discovering that someone has actually used your stolen information to commit fraud is a different level of crisis entirely. Identity theft following a data breach is unfortunately common — and the steps you take in the hours and days after you discover it make a significant difference both in limiting the damage and in the strength of any legal claim you may have. This guide walks through what to do immediately, how to document everything, and how to start rebuilding.
Identity theft doesn't always announce itself with an obvious fraudulent charge. Some signs are subtle and easy to miss if you're not actively watching. Common indicators include:
A credit freeze — also called a security freeze — is the single most effective step you can take to stop ongoing identity theft. It prevents new credit from being opened in your name at all three major bureaus:
A freeze is free and remains in place until you lift it. You can temporarily "thaw" it when you need to apply for credit yourself. This does not affect your existing accounts or credit score.
Visit IdentityTheft.gov (the FTC's official identity theft resource) and file a formal complaint. The site will generate a personalized recovery plan and create an official Identity Theft Report — a legally recognized document that you can use with creditors, debt collectors, and law enforcement to dispute fraudulent accounts.
Visit your local police department with your FTC Identity Theft Report and any evidence of the fraud. Request a copy of the police report — you'll need the report number for many dispute and remediation processes. Some creditors require a police report number before they will close a fraudulent account.
For each fraudulent account you identify, contact the creditor's fraud department directly. Provide your FTC Identity Theft Report and police report number. Request in writing that the account be closed and the fraudulent activity be removed from your credit file. Federal law requires creditors to investigate these disputes within 30 days.
File disputes with each bureau where the fraudulent account appears. Under the Fair Credit Reporting Act, you have the right to have fraudulent information blocked from your credit report. Provide your identity theft documentation. The bureau must block the information within four business days of receiving your dispute if you provide a valid Identity Theft Report.
If your identity theft is traceable to a data breach, the documentation you create now is directly relevant to your legal claim. Companies are legally responsible for losses caused by their failure to protect your data — and a well-documented claim commands higher compensation in any settlement negotiation.
Start and maintain a dedicated folder (physical or digital) containing:
After placing the freeze and disputing fraudulent items, continue monitoring your credit reports for at least one year. Pull free reports from each bureau via AnnualCreditReport.com. Consider enrolling in a credit monitoring service that provides real-time alerts for new inquiries or accounts.
Update passwords on all accounts — especially email, banking, and any account linked to the same email address exposed in the breach. Use unique passwords for each account. Enable two-factor or multi-factor authentication on every account that offers it.
If medical information was exposed, contact your health insurer and review your Explanation of Benefits statements for services you didn't receive. Fraudulent medical claims can be more damaging and harder to clean up than financial fraud. The same FTC dispute process applies.
When your identity theft is traceable to a specific data breach, you are among the strongest-positioned class members in any related litigation. Unlike a class member who simply received a notification letter but has not (yet) experienced fraud, you have documented actual damages — which typically entitles you to significantly higher compensation.
In some cases, particularly where losses are substantial, your situation may be better handled through individual litigation rather than participation in a class settlement. An attorney specializing in data breach cases can evaluate which path maximizes your recovery based on the specific breach and your documented losses.
There is no upfront cost to consult with a data breach attorney, and they are only compensated if they achieve a recovery for you.
You may not be able to pinpoint the exact source with certainty — your information may have been exposed in multiple incidents. However, if you received a breach notification letter and subsequently discovered fraudulent activity involving the same type of information that was exposed, the connection is legally viable. Document the timing and the overlap of data types, and let an attorney assess causation.
Yes. The time, stress, and effort involved in detecting and resolving the fraud are recoverable losses in most data breach claims, even if no money was ultimately taken. Courts and settlement administrators recognize that the harm extends beyond direct financial loss.
Yes — accepting free monitoring and identity restoration services offered by the breached company does not waive your legal rights in any data breach lawsuit. These services have real value and you should use them while simultaneously preserving your legal options.
Related: How to Join a Class Action · What Damages Can I Recover? · Get a Free Case Review
The Law Office of David S. Harris offers free consultations — no fee unless we win.
No fee unless we win your case. Licensed in Florida — nationwide cases.
(786) 306-7278Get a Free Case ReviewData Breach Class Action: A Comprehensive Guide to Your Rights and Recovery
July 19, 2026 · 14 min read
Data Breach Notification Letter Guide: What Your Notice Means and How to Respond in 2026
July 19, 2026 · 12 min read
Class Action Lawsuit Settlement Guide: How to Claim Your Recovery in 2026
July 19, 2026 · 13 min read