Your data was leaked. Now what?
Data breaches are no longer rare. They are expected. I want to cut through the noise and explain what
actually matters and what you should do about it.

FIRST: DON’T PANIC ABOUT LOGIN ACCESS:
If your name, phone number, or email was exposed, that alone isn’t enough for someone to log into your
accounts. Good authentication design uses multi-factor authentication (MFA) requires something you
know AND something you must have on your device, PIN, fingerprint, or Face ID. Without that
combination, a leaked email address is just an email address.

WHAT YOU SHOULD ACTUALLY WORRY ABOUT:
The real risk is social engineering. Criminals use leaked data to sound credible and manipulate you. Here’s
what that looks like in practice:

Fake authority calls:
Someone claims to be from your bank or the police and says your money is at risk. Hang up. Call your bank
directly using the number on their official website.

Friend-in-need scams:
A ‘known contact’ messages you asking for an urgent money transfer. Call them back on their real number before
doing anything.
Phishing links
An email or SMS leads you to a fake login page. Don’t click immediately. Check the sender address and hover over
the link before trusting it.
Identity fraud:
Criminals use your data to order products or take out loans in your name. Review your account transactions every
few days. Spotted something odd? Contact your bank immediately.

THREE RULES TO LIVE BY

  1. Verify through official channels Contact the breached company via their official website not through links in breach notification emails.
  2. Never share login No legitimate company, bank, or authority will ever ask for your password.
  3. Know what’s never No one is permitted to ask you to transfer money to unknown accounts or send someone to collect your ID, card, or devices.

Security isn’t just about technology, it’s about awareness. Stay skeptical, stay informed.

Download PDF