Article

Your Data Was Breached. What To Do Next

·By Mathew Chewing

A breach notice is not spam and it is not the end of the world. Here are the steps that actually reduce your exposure, in the order they matter, for Australian businesses.

Protect Yourself: 8 Steps to Take When You Get a Notice Your Data Was Breached

The email arrives on a Tuesday. A service you signed up for years ago has been breached, and your details were "potentially affected." Most people feel a flicker of alarm, decide there is nothing to be done, and archive it.

That is the wrong instinct, but so is panic. A breach notice is information, and information you act on within a day or two is worth far more than information you act on in a month. Here is the order that actually matters.

1. Check the notice is genuine

Breach notifications are a gift to scammers, because they arrive at exactly the moment you are primed to click something urgent about your account. Fake ones follow real incidents within hours.

Do not use the links in the email. Go to the company website directly, or search for their official breach statement. Legitimate notifications never ask for your password, card number or MFA code — there is no scenario where a breached company needs you to confirm your password by email.

2. Work out what was actually taken

The response depends entirely on the data type, and the notice usually says if you read carefully.

  • Email address only. Expect more targeted phishing. Low direct risk.
  • Password (hashed or plain). Change it immediately, and everywhere you reused it.
  • Payment card. Watch the statement; consider a replacement card.
  • Identity documents — licence, passport, Medicare number. This is the serious one, and it has its own process below.

3. Change the password, then find every place you reused it

Change it on the breached service first. Then be honest about where else that password lives. Attackers run credential stuffing at scale: they take the username and password pairs from one breach and try them automatically against hundreds of other services. The breach of a hobby forum becomes a compromise of your business email because the password was the same.

If the honest answer is "I do not know where else I used it," that is the argument for a password manager. Every credential unique, all of them long, none of them remembered by you.

4. Turn on MFA everywhere that offers it

A stolen password is worth far less against an account with multi-factor authentication. Prioritise the accounts that can reset other accounts: your primary email first, then banking, then anything holding payment details.

Prefer an authenticator app or a passkey over SMS where you have the choice, for the reasons covered in our guide to authentication that staff will actually use.

5. If identity documents were exposed, act like it matters

Passwords can be changed in seconds. A driver licence number cannot, which is why document exposure deserves a different level of effort.

In Australia you can place a ban on your credit report with the three main bureaus — Equifax, Experian and illion. A ban stops new credit being opened in your name, is free, and can be extended. Doing this with all three, not just one, is the step people skip.

If a licence, passport or Medicare card was exposed, contact the issuing agency about replacement — Service NSW for a licence, and so on. IDCARE is Australia and New Zealand national identity and cyber support service; it is free, government-funded, and will walk an individual or a business through a tailored response plan. It is genuinely the best call to make if identity documents are involved.

6. Watch for the follow-up scam

The breach is often the beginning rather than the end. Criminals who hold real details about you can be far more convincing than a generic scammer, because they can quote your account number, your recent order or your address.

Be sceptical of any contact referencing the breach — especially calls claiming to be from your bank fraud team, or offers of compensation and monitoring services that need your card details. If someone rings about a breach, hang up and call the organisation back on a number you looked up yourself.

7. If it was a business account, widen the scope

When the exposed credential belonged to a work account, the personal steps are not enough. Someone needs to check whether the account was actually used, and that means looking at the sign-in logs for unfamiliar locations, at mailbox rules for anything forwarding externally, and at connected applications for consents nobody remembers granting.

Revoke active sessions as well as changing the password — a session token stays valid after a password change until it is explicitly killed.

8. If you are the one who was breached, know your obligations

This is where Australian businesses need to be precise. Under the Notifiable Data Breaches scheme, if a breach is likely to result in serious harm to any individual whose information is involved, and you cannot remediate it in time to prevent that harm, you must notify both the affected individuals and the Office of the Australian Information Commissioner.

The assessment timeframe is the part people miss: once you become aware of grounds to suspect an eligible breach, you have 30 days to carry out a reasonable and expeditious assessment. Thirty days is the outer limit, not the target.

The practical implication is that you cannot assess what you cannot see. A business with no logging, no alerting and no idea which systems hold personal information will spend most of that window simply working out what happened. Getting detection and response in place beforehand is what makes the deadline achievable.

The short version

  1. Verify the notice independently.
  2. Identify what data was exposed.
  3. Change that password and every reuse of it.
  4. Enable MFA on the accounts that matter most.
  5. Credit bans and IDCARE if identity documents were involved.
  6. Treat follow-up contact as hostile until proven otherwise.
  7. For work accounts, check sign-ins, rules and connected apps.
  8. If it is your breach, start the 30-day assessment clock deliberately.

None of this is difficult. It is just time-sensitive, and the people who come out of a breach well are the ones who did the boring steps in the first week.

If you would rather know where your business stands before the email arrives, a cyber security assessment is the place to start.

Local IT and cyber security support across NSW

Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.

Had a breach notice that mentions a work account? Talk to us today — the first 48 hours are where the exposure is decided.

Want this handled for you?

Chewing IT looks after IT, cloud and cyber security for businesses across the Central Coast, Newcastle and Sydney. Free, no-pressure consultation — no contracts, no jargon.