What a "Data Breach Notification" Email Actually Means and What to Do in the Next 48 Hours
TL;DR: A breach notification email means a company has confirmed your data was involved in a security incident — but the email itself often leaves out crucial detail. Here's what to actually do in the first 48 hours.
👉 See if your data's already leaked — free 30-second check →
Breach notification emails are written by legal and communications teams as much as security teams, which is part of why they can feel simultaneously alarming and vague. Understanding what they typically do and don't tell you makes the next steps clearer.
What the email is actually confirming
At minimum, it confirms your data was part of a dataset a company has identified as compromised. Depending on the jurisdiction's disclosure requirements — covered in more depth in what US law requires companies to tell you — the email should specify which categories of data were involved: email, password hash, payment details, or more sensitive fields like government ID numbers.
What it often doesn't tell you
- Exactly how the breach happened, beyond a general description
- Whether your specific data has already been used maliciously, as opposed to just exposed
- How long the data had been exposed before detection
What to do in the first 48 hours
- Change the password immediately — on that account, and anywhere else you reused the same one.
- Enable two-factor authentication if it wasn't already active, since a stolen password alone becomes far less useful with a second factor in place.
- Check for suspicious activity on the account and any linked payment methods.
- Be alert for follow-up phishing — scammers sometimes reference a real breach by name to make a fake follow-up email seem legitimate.
- Check whether the same email appears in other breaches you haven't been notified about yet, since companies vary widely in disclosure speed.
That last step matters more than people expect — official notification emails often lag well behind when data actually starts circulating. A Scan My Shadow report checks your email against 1,500+ breach and public sources directly, rather than waiting on a company's own notification timeline.
Frequently Asked Questions
Should I click links in a breach notification email?
Be cautious — legitimate notifications typically don't ask you to log in via an embedded link; go directly to the company's site instead of clicking through the email to avoid a potential phishing copycat.
Does a breach notification mean my identity has already been stolen?
Not necessarily — it means your data was exposed, which increases risk, but exposure and actual misuse are different things worth distinguishing when deciding how urgently to act.
How do I know if a breach notification email is real or a phishing attempt?
Check the sender's actual email domain carefully, and verify by going directly to the company's official site rather than clicking any link in the message.
Should I change passwords on unrelated accounts too?
Only if you reused the same password elsewhere — that's exactly the scenario that turns one breach into several compromised accounts, which is why password reuse is worth eliminating generally.
What if I never received a notification but suspect I was affected?
Checking your email directly against breach databases is the more reliable approach, since not every affected user receives timely or even any notification depending on the company and jurisdiction.
If the breach specifically involves your email, see What Should I Do If My Email Appears in a Data Breach? for the email-specific checklist.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated