Reported, not repackaged

A breach letter arrived in April, which is the worst month for it

title:A breach letter arrived in April, which is the worst month for itauthor:Lionel Karstenspublished:2026-04-23section:Innovationwords:958read:4 min
A folded notification letter on a desk beside a laptop, the paper creased in three from the envelope
A folded notification letter on a desk beside a laptop, the paper creased in three from the envelope

Notification letters cluster with tax season, and the combination of a stolen identifier and a filing window is the one worth acting on quickly.

A breach notification tells you three things: that an organization holding your data was compromised, roughly what categories of data were involved, and what they are offering.

It does not tell you whether your particular record was among those taken, whether it has been used, or whether it will be. That ambiguity is why the letters are easy to file away and forget.

The response depends almost entirely on the second item. A breach of email addresses is a nuisance. A breach involving a Social Security number, a driver's license number or a date of birth is a different matter, and in the spring it overlaps with the one window where a stolen identifier is most valuable to somebody else.

Sort the letter first

What was takenRealistic exposureDo this
Email address, nameMore targeted phishingBe skeptical of related messages; nothing else
Password, or a password hashReuse across other accountsChange it, and anywhere else it was used
Payment card numberFraudulent charges, limited liabilityWatch statements; replace the card if it was full detail
Social Security number, date of birthNew accounts opened in your nameFreeze credit at all three bureaus
Health or medical recordsHarder to remediate; longer tailFreeze, and review any explanation of benefits carefully

Why a freeze beats the monitoring offer

The free credit monitoring bundled into most notification letters is worth accepting, as long as nobody mistakes it for protection. Monitoring watches and reports.

A freeze refuses in advance: it shuts off access to your credit report, and an application nobody can underwrite does not turn into an account. That holds whoever is filling in the form and whichever of your identifiers they are holding.

Since federal law made them free nationwide, putting a freeze on and taking it off again at all three of the major bureaus costs nothing, and thawing one for an afternoon when you are actually buying something takes minutes online.

The plain-language account of how a freeze differs from a fraud alert, which is the distinction people get wrong, is kept by the Consumer Financial Protection Bureau.

The practical objection people raise is inconvenience, and it is mostly a memory of how this worked years ago. The current process is fast.

The one thing worth doing at the same time is recording where the PIN or account credentials for each bureau are stored, because the moment you need to lift a freeze is usually a moment when you are in a hurry.

The tax season overlap

A stolen Social Security number has an obvious use in the filing window: a fraudulent return filed early, claiming a refund, before the real filer gets there. The signal is usually a rejected electronic filing, on the grounds that a return has already been filed under that number.

Two things help. The first is filing early, which sounds glib and is genuinely the most effective single defense, because the fraud depends on getting there first.

The second is an identity protection PIN, a number issued by the tax authority that must appear on the return for it to be accepted. It is available to filers who want it rather than only to victims, and it closes the attack almost entirely.

If a return is rejected for this reason, the reporting route runs through the tax agency itself and through the identity theft recovery process the Federal Trade Commission maintains for exactly this situation. The recovery plan it generates is the document other institutions will ask for.

Passwords, and the advice that changed

The guidance that dominated for two decades, meaning frequent forced changes and mandatory symbol requirements, has been substantially revised. The current thinking is that length matters more than complexity, that forced rotation on a schedule makes passwords worse rather than better because people iterate predictably, and that the single largest risk is reuse across sites.

Which produces a short, unglamorous set of instructions. Use a password manager, because nobody can remember unique long passwords for a hundred accounts and the alternative is reuse.

Turn on two-factor authentication on email first, since email is the recovery route for everything else. Prefer an authenticator application or a hardware key over text messages where the option exists, because phone numbers can be moved by someone determined enough.

Backups, tested rather than assumed

The other half of a security posture has nothing to do with credit. It is whether you could reconstruct your own records after a device is lost, stolen or encrypted by ransomware.

The habit that separates a real backup from a hopeful one is restoring from it. Once a year, pick a file and restore it. People discover in that ten minutes that the backup stopped running fourteen months ago, that it covers one folder rather than the drive, or that the external disk it writes to has failed silently.

Keep a copy somewhere physically separate from the originals, which is the part that survives a fire or a theft as well as a hardware failure. Cloud storage counts, provided you know what it actually covers, which is frequently less than people assume.

What to do with the letter itself

Keep it. It is dated evidence that a specific organization held your data and that it was exposed, which is useful if a fraudulent account appears later and you are asked how it could have happened. Note the date on the calendar as well, because the offered monitoring usually runs for a fixed term and expires without a reminder.

Then take the twenty minutes for the freeze. It is the one action on the list that prevents rather than detects, it costs nothing, and it does not need to be repeated for the next letter.