Personal data stolen: how to tell, and what to do
Was your data stolen in a hack? The warning signs, how to check in 30 seconds, and the first things to do.
Every year, hundreds of websites have their customer databases stolen. If you have had online accounts for a few years, some of your data is very likely already circulating: more than 17 billion hacked accounts are publicly on record. The good news: you can find out which data, and sharply limit the damage.
What data gets stolen in a hack?
Most often: your email address, name, password (sometimes in plain text, often encrypted but crackable if it is simple), phone number and postal address. Depending on the site, also your date of birth, order history, part of your card number or your bank details.
Warning signs
- Password reset emails you did not request;
- sign-in alerts from an unknown device or country;
- texts or calls that mention your name, a recent purchase or a site you use;
- a sudden rise in spam or very convincing phishing emails;
- a payment or purchase you do not recognise;
- letters about a contract, loan or subscription you never signed up for.
None of these signs is guaranteed: most of the time, a breach goes unnoticed until the data is used. That is why checking matters.
How to check whether your data was stolen
Public breaches are listed by Have I Been Pwned, the global reference. SimplComIA relies on it: you enter your email address, confirm it is yours, and see how many known breaches it appears in. We never display or store the data itself. More in Has my email been leaked?
Your data was stolen: the first three steps
- Change the password on the affected site and anywhere you reused it, then turn on two-factor authentication for your email account.
- Tell your bank if a card or bank details are involved, and watch your statements.
- Be wary of messages that look legitimate: that is the main use of stolen data.
The rest, step by step, in Data breach: what to do, and in what order.
Can stolen data be recovered?
No: a stolen copy cannot be "recovered". You can, however, make the data useless (new password, replaced card) and require the affected site to erase what it still holds about you. See Removing hacked data: what is possible.