6.3 Personal Data Incidents

Identity Theft

Signs of identity theft:

Step 1: Contain the Damage (IMMEDIATELY)

Step 2: Close Fraudulent Accounts (Within 24-48 Hours)

Step 3: Secure Your Legitimate Accounts (Within 48 Hours)

Step 4: Additional Actions

Lost or Stolen Wallet or Purse

What's at risk:

Step 1: Immediate Containment (IMMEDIATELY)

Step 2: Replace Documents (Within 24-48 Hours)

Step 3: Monitoring

Sent Money to a Scammer

Common scenarios:

Step 1: Try to Stop the Payment (IMMEDIATELY)

Document everything:

For wire transfers:

For credit/debit card charges:

For payment apps (Venmo, PayPal, Zelle):

For gift cards:

For cryptocurrency:

Step 2: Report the Fraud (Within 24 Hours)

Step 3: Protect Against Further Loss (Within 24 Hours)

Gave Out Personal Information

Follow this playbook if you gave out high risk, personal information via email or to a caller in a conversation you did not initiate.

High Risk Personal Information:

Step 1: Immediate Actions (Based on What You Shared)

Step 2: Monitor accounts daily for 2 weeks

If you see anything unusual, follow the appropriate playbook

Clicked a Phishing Link or Opened Suspicious Attachment

Your next steps are based on what you did, based on risk.

Low Risk

High Risk

Received Notice of Data Breach

This is when a company notifies you your data was exposed.

Common notification sources:

Step 1: Verify Notification is Legitimate (IMMEDIATELY)

Beware of phishing! Don't click links in breach notification emails, instead, verify using one of the following:

Step 2: Understand What Was Exposed (Within 24 Hours)

Read the notification carefully:

Step 3: Take Action Based on Data Exposed (Within 48 Hours)

If passwords were exposed: Follow the playbook for the type of compromised account above

If email address only: Not much you can do here, just understand you will likely start receiving a lot of spam and potentially phishing attempts, so be extra vigilant in the coming weeks and months.

If Social Security number or financial data:

If medical information:

Step 4: Accept Company's Offer (If Valuable)

Many companies offer:

Evaluate the offer:

Step 5: Additional Actions

Document the breach:

Monitor relevant accounts based on exposure and consider legal action if negligence was involved.

Ongoing monitoring:

SIM Swap Attack

Signs of SIM swap:

Step 1: Regain Control of Phone Number (IMMEDIATELY)

Contact your mobile carrier:

Step 2: Secure Accounts That Use Phone for 2FA (Within 1 Hour)

Attackers may have targeted accounts using SMS for two-factor authentication. Verify recent logins to new devices in the following priority:

If there was an unauthorized login, for each account:


Revision #1
Created 2026-07-12 22:23:24 UTC by Chris Landis
Updated 2026-07-12 22:28:22 UTC by Chris Landis