# What to Do If Your Personal Data Appears in a Breach

Source: https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection/personal-data-breach-response

**Answer:** Verify the breach notice through the organisation’s official channel, identify exactly which data was exposed and match your response to that data. Replace reused passwords, secure the associated email and mobile accounts, watch affected payments and be alert for targeted scams. A breach does not automatically mean that every account has been hacked, but exposed information can make later attacks more convincing.

Part of [Digital Safety, Privacy & Account Protection](https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection) · 13 min read · by UrbanX Knowledge Hub

**Last reviewed: 26 August 2026 · 13 min read**

### Breach, takeover and phishing are different events

An **organisational data breach** or security compromise involves personal information held by an organisation being accessed, lost, altered or disclosed without authorisation.

An **account takeover** means someone has gained control of an individual account.

A **phishing attempt** is a message or page designed to make a person disclose information or approve an action.

They can be connected, but they are not interchangeable. A breach may expose an email address without exposing its password. A phishing message may falsely claim there was a breach. An account can be taken over through password reuse even when the platform itself was not breached.

### Step 1: Verify the notice independently

Attackers use real and invented incidents as bait. If an email or SMS says your data was exposed:

- do not use its sign-in or payment link;
- visit the organisation’s known website or app;
- look for its official security notice;
- contact a verified number if clarification is needed; and
- check whether the sender asks for a password, one-time PIN, remote access or urgent payment.

A legitimate notification should help describe the incident and protective steps. It should not require the recipient to “reverse” a transaction by disclosing a secret code.

### Step 2: Identify the exposed fields

Do not treat every breach as if it exposed the same information. Record what the organisation confirms, which dates are involved and whether passwords, payment details or identity records were included.

#### Email address or phone number

Expect more convincing phishing and impersonation. Be cautious of messages that reference the affected organisation, account type or incident.

#### Password or password hash

Change the affected password immediately. If it was reused or closely patterned elsewhere, change every related account—starting with email, password manager, banking, mobile and cloud accounts. Use unique generated passwords.

#### Payment-card or bank information

Contact the bank or payment provider through its official fraud channel. Follow its advice on blocking or replacing the affected instrument and monitor statements. A card number, account credential and transaction history do not all create the same risk, so confirm what was exposed.

#### South African identity number or identity document

An identity number cannot simply be changed like a password. Preserve the notification, become more cautious about applications or account changes in your name, and contact affected financial or service providers if misuse appears. Never upload extra identity documents to an unverified “breach checking” service.

#### Address, employment or family details

These can enable convincing social engineering or create physical-safety concerns when combined with threats. Alert relevant household members or institutions if the exposure is specific and consequential.

#### Security questions and recovery information

Replace answers where possible. Use generated responses stored in a password manager instead of facts that appear in public records or social profiles.

#### Authentication tokens or active sessions

A password change may not be sufficient. Use the service’s sign-out-all-sessions option, revoke connected applications and follow its incident-specific instructions.

### Step 3: Secure the accounts that matter most

Prioritise accounts that can reset or finance others:

1. Primary email
2. Password manager
3. Banking and payment services
4. Mobile-network account and device ecosystem
5. Cloud storage
6. Work or school identity
7. Social, shopping and gaming accounts

Enable strong MFA or passkeys where available and replace exposed backup codes.

### Step 4: Watch for secondary attacks

Breached data is often useful because it supplies context. A scammer may know a name, provider, old address, last four digits or service type and use that detail to sound legitimate.

Be especially cautious of:

- “breach compensation” or refund forms;
- calls claiming to secure a bank or mobile account;
- requests to move money to a safe account;
- unexpected SIM-swap or number-port messages;
- password-reset notifications you did not initiate;
- invoices or delivery messages using correct personal details; and
- people offering paid data removal or recovery.

Known information is not proof that the caller represents the organisation.

### Step 5: Monitor proportionately

Keep the organisation’s notice and case reference. Review relevant statements, sign-in history and security alerts. You do not need to change unrelated information that was not exposed merely to feel active; focus on the risk created by the confirmed fields.

Services such as Have I Been Pwned can indicate whether an email address appears in breaches known to that service. A result is a useful signal, not a complete record of every incident, and it does not by itself prove that the email account is currently controlled by someone else.

### South African privacy context

The Information Regulator’s security-compromise guidance explains duties that may apply to a responsible party under the Protection of Personal Information Act (POPIA), including notification considerations. The organisation holding the information—not the affected individual—has the primary statutory incident obligations described in that guidance.

An individual should still protect accounts, retain the notice and raise concerns through the organisation’s privacy or information-officer channel. If a person believes their POPIA rights were not handled appropriately, the Information Regulator publishes information and complaint routes.

This article provides general protective guidance, not a finding that a particular organisation has complied with or breached POPIA.

### What not to do

- Do not click a breach-notice link before verifying the incident.
- Do not reuse a replacement password.
- Do not publish the notice if it contains personal identifiers.
- Do not pay a stranger to remove data from a breach.
- Do not assume an old address or expired card creates zero risk; it can still support impersonation.
- Do not assume an email-address exposure means the email password was exposed.
- Do not ignore an organisation’s later update about additional affected fields.

### A compact response checklist

- Verify the incident independently.
- Record the affected organisation, dates and exposed fields.
- Secure primary email and mobile recovery routes.
- Replace exposed and reused passwords.
- Enable strong MFA or passkeys.
- Contact the bank if payment data is affected.
- End sessions or revoke tokens if advised.
- Watch for targeted phishing and identity misuse.
- Keep the notice and case references.
- Review official updates as the investigation develops.

### Sources

- [Information Regulator: Handling of Security Compromises](https://inforegulator.org.za/2025/08/19/fact-sheet-handling-of-security-compromises/)
- [Information Regulator: POPIA](https://inforegulator.org.za/popia/)
- [Have I Been Pwned](https://haveibeenpwned.com/)
- [CISA: Use Strong Passwords](https://www.cisa.gov/secure-our-world/use-strong-passwords)
- [SABRIC: How to Stay Safe](https://www.sabric.co.za/how-to-stay-safe/)
- [FTC: Protect Personal Information From Hackers and Scammers](https://consumer.ftc.gov/articles/protect-your-personal-information-hackers-and-scammers)

### Related guides

- [All Digital Safety, Privacy & Account Protection guides](/knowledge-hub/digital-safety-privacy-account-protection)
- [What to Do After an Online Account Is Hacked](/knowledge-hub/digital-safety-privacy-account-protection/what-to-do-account-hacked)
- [Password Managers: Why Reusing Passwords Is Risky](/knowledge-hub/digital-safety-privacy-account-protection/password-managers-password-reuse-risk)
- [How Multi-Factor Authentication Protects Online Accounts](/knowledge-hub/digital-safety-privacy-account-protection/multi-factor-authentication-account-protection)

## Frequently Asked Questions

**Does a breach mean my account was hacked?**

Not necessarily. It means information was exposed or compromised; whether an individual account was accessed depends on the incident and later activity.

**Should I change every password?**

Change the affected password and every place where it was reused or patterned. Give priority to email, banking, mobile and other recovery-critical accounts.

**Can I change a South African identity number after a breach?**

It is not a routine replaceable secret like a password. Preserve the breach record, monitor for misuse and follow official guidance if identity fraud occurs.

**Does Have I Been Pwned show every breach?**

No. It reports breaches in its data set. An absent result is not proof that no exposure has ever occurred.

**Must I personally report the organisation’s breach to the Information Regulator?**

POPIA places security-compromise duties on the responsible party. Individuals can still use the Regulator’s published channels for complaints or concerns about their personal information.
