Reported, not repackaged

Breach Letter in the Mail During Filing Season? Why That Timing Is Worth Acting On

title:Breach Letter in the Mail During Filing Season? Why That Timing Is Worth Acting Onauthor:Lionel Karstenspublished:2026-04-23section:Innovationwords:1,159read:5 min
A folded notification letter on a desk beside a laptop, the paper creased in three from the envelope
A folded notification letter on a desk beside a laptop, the paper creased in three from the envelope

Notification letters cluster with tax season, and the combination of a stolen identifier and an open filing window is the one worth moving on quickly.

A letter arrives in April on unfamiliar stationery, explaining that a company you dealt with two years ago has experienced an incident, that your information may have been involved, and that they are offering monitoring at no cost for a period. The instinct is to file it with the other things that will be dealt with later, which is a reasonable response to a document that has been carefully written to be unalarming. The timing is the part that deserves attention, because April is also the window in which one specific kind of fraud is easiest to commit and hardest to unwind.

Sort the Letter First

The first task is to work out what was actually exposed, and the letter will say, usually in a paragraph well below the reassurance. The categories are not equivalent. An email address and a password are a nuisance and a reason to change credentials. A card number is largely the issuer's problem, since fraudulent charges are reversed and a new card is issued. A Social Security number, a date of birth and a full name together are a different category entirely, because those are the durable identifiers that cannot be reissued and that open new accounts rather than misusing existing ones.

The second task is to confirm the letter is genuine, since breach notifications are themselves impersonated. Do not use the phone number or the link in the letter. Go to the company's own site independently, or call a number you already had, and ask whether the notice is theirs. State attorneys general maintain public databases of breach notifications in many states, which is a fast independent check, and the company's own newsroom generally carries a statement if the incident was large enough to require mass mailing.

Why a Freeze Beats the Monitoring Offer

The monitoring service bundled with the letter tells you after something has happened. A credit freeze prevents most of it from happening in the first place, and it is free by federal law at each of the three nationwide consumer reporting agencies. A freeze blocks new credit accounts from being opened in your name until you lift it, which you can do temporarily and specifically when you are applying for something, and lifting it is now a matter of minutes online rather than a letter and a wait.

The reason freezes are underused is that people assume they are permanent, complicated or damaging to a credit score, and none of those is true. The Consumer Financial Protection Bureau publishes plain descriptions of the freeze right and of how to exercise it at each agency, which is worth reading once so that the process is familiar before it is needed. Freeze the children in the household as well if the exposed data included them, since a child's identity is attractive precisely because nobody checks it for eighteen years.

The Tax Season Overlap

Here is why April specifically matters. Tax-related identity theft works by filing a fraudulent return in somebody else's name early in the season and directing the refund elsewhere, and the fraud is usually discovered when the real return is rejected as a duplicate. That timing means a Social Security number stolen in the autumn is most valuable in the following spring, and a letter arriving during filing season is a letter about an identifier that is currently in its highest-value window.

The practical responses are short. File as early as you can, because the first return filed is the one accepted. Request an identity protection personal identification number, which is a code that must accompany any return filed under your number and which is now available to any taxpayer who wants one rather than only to confirmed victims. And if a return is rejected as already filed, treat that as the start of a documented process rather than as a software problem, because there is a specific affidavit form and a specialized unit that handles it.

Passwords, and the Advice That Changed

The guidance that most people learned has been substantially revised, and the revisions run in a friendlier direction than expected. Forced periodic changes are now discouraged, because they push people toward predictable variations of one password. Composition rules demanding a symbol and a digit are similarly deprecated in favor of length, since a long passphrase is both stronger and easier to remember. The current federal guidance on digital identity, which most large organizations follow, reflects all of that, and it is the reason your bank stopped making you change your password every ninety days.

What has not changed is that reuse is the actual vulnerability. A breach at one company matters mainly because the credentials it exposes are tried everywhere else, which is why a password manager and a unique credential per account converts a breach into a single-site problem. Two-factor authentication matters more than password strength on the accounts that gate everything else, which are email and the phone carrier account, since both can be used to reset almost anything.

Backups, Tested Rather Than Assumed

Breach letters are a good prompt for the adjacent question, which is whether the household could recover if data were lost rather than stolen. Most people have a backup arrangement of some kind and very few have ever restored from it, which means what they actually have is an assumption. The test is short: pick a file, delete it, and restore it from the backup. If that fails, the backup was decorative, and it is better to learn that on a Tuesday than after a drive failure.

What to Do With the Letter Itself

Keep it. It is dated evidence that a specific organization exposed specific data about you on a specific date, and that becomes relevant if fraud appears later and somebody asks how the information got out. It also matters for class action notices, which arrive years afterward and require you to identify yourself as an affected person. A single folder holding breach letters, with a note of what was exposed in each, is a five-minute habit that answers a question nobody can answer from memory.

Reports of identity theft go to the Federal Trade Commission, which operates the national reporting system and generates the recovery plan and the affidavit that banks and creditors ask for. Knowing that route exists before it is needed is most of the value, because the hours after discovering a fraudulent account are not the hours in which to work out who to call.

The letter that arrived in April was written to be reassuring and was probably accurate in everything it said. What it could not say is that its own timing mattered, that the free monitoring it offered was the weaker of the two available responses, or that the strongest move available to the recipient takes about twenty minutes and costs nothing. Those are the things worth knowing before the next one arrives, and there will be a next one.