Skip to content
Security

How to check a breach email

The National Cyber Security Centre says an email offering to help after a data breach can be independently verified by matching the message directly to the company’s…

Security2 min read

card uv — illustration for “How to check a breach email”
Photo: Debit card exposed to ultraviolet light- 2013-09-28 20-21 — User:Harrihealey02, CC BY-SA 3.0 (Wikimedia Commons)
On this page
  1. How to Tell the Message is Real
  2. What a Real Notice Should and Should Not Do
  3. First-Hour Actions if the Breach is Real

The National Cyber Security Centre says an email offering to help after a data breach can be independently verified by matching the message directly to the company’s official breach notification or account security channels—never by touching the email’s links or attachments.

How to Tell the Message is Real

Before opening the email, go to the company's official website or a verified social media account to see if they have acknowledged the breach. Any legitimate breach notice will be available there, and should match the company name, breach date, and information exposed as described in the email.

Scam messages often arrive days or weeks after a breach becomes public, when the story has faded but the anxiety has not. That means you cannot take the email’s subject line or claims about its own timing at face value. Public guidance from national cyber security agencies is consistent: do not open attachments or follow links unless you have verified independently that the message is genuine.

If you are unsure the sender is genuine, contact the company yourself, through a number or address you already had.

What a Real Notice Should and Should Not Do

If you do receive a legitimate breach notification, it should tell you what information was exposed, what action the company is taking to protect the data, and what you should do next. You will never be asked to enter personal identifying details, which is a tell-tale sign. Requests for a Social Security number, credit card information, or password to click on an included link should raise immediate suspicion.

The breach notice may include useful steps, such as recommending new password creation or account verification, but all of this should be done through the organization's official channels or devices, not through push notifications in the email. Open the site or the app yourself rather than following anything the message provides.

First-Hour Actions if the Breach is Real

If the notification is confirmed to be real, begin by changing the account's password, then following that up with changes to related email and payment account passes. Take a minute to review recent account activity for suspicious logins, connected device changes, or transaction records you do not recognize.

If you see anything suspicious, treat it as a security alert. That means contacting the company through official email or other secure channels, and reporting any suspicious login or financial activities you spot.

Suspicious messages can be reported. In the United Kingdom the National Cyber Security Centre takes forwarded emails at [email protected] through its Suspicious Email Reporting Service.

In the United States the Cybersecurity and Infrastructure Security Agency collects phishing reports, and most countries run an equivalent. Tell the company that was supposedly breached as well: it can warn other customers that its name is being used.

None of this is urgent in the way the email wants it to be. A real breach notice will still be on the company site tomorrow; a fake one is counting on you not looking.

More from Security

All stories
card uv — illustration for “How to spot unsafe sites”
Security

How to spot unsafe sites

It is possible to enjoy online casino games while remaining safe. This guide lays out easy, straightforward steps anyone can take to keep themselves safe.