Data breaches exposed 4.2 billion records in 2025. The Medibank breach, the Optus breach, the Latitude Financial breach — millions of Australians have had their personal information stolen. If you've received a breach notification, or if you've found your email in Have I Been Pwned, here's exactly what to do.

Step 1: Verify the Breach (First 30 Minutes)

Before taking action, confirm the breach is real. Check the company's official website and social media for breach notifications. Search for news coverage from reputable outlets. Visit haveibeenpwned.com and enter your email address to see if it appears in known breach databases. Be cautious of phishing emails that impersonate breach notifications — always navigate directly to the company's website rather than clicking links in emails.

Step 2: Change Your Passwords (First Hour)

Change the password for the breached account immediately. If you've reused that password on any other account — especially email, banking, or social media — change those passwords too. Use a password manager to generate unique, complex passwords for each account. Enable two-factor authentication on every account that supports it, prioritising email, banking, and social media.

Step 3: Assess What Was Exposed (First 2 Hours)

Read the breach notification carefully to understand what data was exposed. Different data types require different responses:

Email and password: Change password, enable 2FA, monitor for phishing.

Phone number: Be alert for SIM swapping attacks — contact your carrier to add a PIN to your account.

Credit card numbers: Contact your bank to cancel and reissue the card. Monitor statements for unauthorised transactions.

Tax File Number (TFN) or passport: Contact the ATO and the Australian Cyber Security Centre (cyber.gov.au). Consider placing a credit freeze with Equifax, Experian, and illion.

Medicare number: Contact Services Australia to request a new Medicare card number.

Step 4: Monitor for Identity Theft (Ongoing)

Set up credit monitoring through your bank or a service like CreditSavvy (free in Australia). Check your credit report for unfamiliar accounts or enquiries. Monitor your bank statements weekly for unauthorised transactions. Be alert for unexpected bills, calls from debt collectors, or government correspondence about accounts you didn't open.

Step 5: Report and Seek Help

Report identity theft to the Australian Cyber Security Centre at cyber.gov.au/report. If you've suffered financial loss, report to the Australian Federal Police and your state police. Contact IDCARE (idcare.org, 1800 595 160) — Australia's national identity and cyber support service — for free, specialist support.

Understanding What Attackers Do With Stolen Data

Understanding how stolen data is used helps you prioritise your response. Stolen email and password combinations are typically sold in bulk on dark web marketplaces and used in credential stuffing attacks — automated attempts to log into other services using the same credentials. This is why password reuse is so dangerous: one breach can cascade into dozens of compromised accounts.

Stolen financial data (credit card numbers, bank account details) is typically used within 24–48 hours of a breach, before the victim or their bank notices. This is why immediate action on financial data is critical. Stolen identity documents (passport, driver's licence, TFN) are used for identity fraud — opening credit accounts, taking out loans, or filing fraudulent tax returns — which can take months or years to discover and resolve.

Preventing Future Breaches: Long-Term Habits

The best defence against data breaches is reducing your exposure. Use unique email addresses for different services — services like SimpleLogin and Apple's Hide My Email generate disposable email addresses that forward to your real inbox, so a breach at one service doesn't expose your primary email. Use a password manager to ensure every account has a unique password. Enable two-factor authentication on every account that supports it. Regularly audit your accounts and delete services you no longer use — every account is a potential breach vector.

Consider using a credit monitoring service that alerts you to new credit enquiries or accounts opened in your name. In Australia, CreditSavvy (free) and Equifax's paid monitoring service both provide this. A credit freeze — which prevents new credit from being opened in your name without your explicit approval — is the most effective protection against identity theft, though it requires unfreezing when you legitimately need new credit.

Sources & Further Reading