What a data breach notification actually means
The email opened with an apology and closed with twelve months of free credit monitoring. Between those two things sat one bulleted list of five words, about halfway down.
That list was the only content in the message. Everything else was written by lawyers.
The letter is a legal filing wearing an apology
Nobody on the security team wrote the words you are reading. A breach notice gets drafted by counsel, passed through communications, and sent against a deadline. Under the European regime the regulator has to hear about it within seventy two hours of discovery, with affected individuals told without undue delay after that. Other jurisdictions differ on the numbers and agree on the shape.
So the letter goes out while the investigation is still running. Almost everything odd about the document follows from that one fact.
It also has to do two incompatible jobs. Satisfy a regulator who will check that you disclosed, and survive being read back to you line by line in a courtroom two years later. Keeping you as a customer comes a distant third, and the tone is the only place that third job appears.
Which makes the reassurance the part written for you. It is also the part carrying no facts.
Four phrases and what they are covering
“We have no evidence that your information has been misused.”
Almost always true. It says they looked and found nothing. It says nothing about how far back they were able to look, and plenty of companies keep detailed access logs for ninety days. If the intrusion began ten months before anyone noticed, seven of those months cannot be examined by anybody. An absence of evidence and an absence of logging produce the identical sentence.
“A limited number of accounts were affected.”
Limited is a word standing in for a number that exists. Somebody in that building knows it to the individual row. It stayed out of the email for a reason, and the reason is seldom that the count is small. Regulatory filings sometimes print the figure when the customer email will not, and in several jurisdictions those filings are public.
“Your information may have been affected.”
This one is usually honest and gets read as weasel wording. In a lot of intrusions the company can prove an attacker had access to a database and cannot prove which rows actually left the building. So they notify everyone in the table. May means may.
“Out of an abundance of caution.”
A phrase that turns up when a company wants credit for a disclosure it was legally obliged to make. Harmless in itself, useful as a marker, because a letter containing it has been through several drafts.
The date they buried
Every notice gives you a discovery date. Fewer than half put a start date anywhere near it.
Search for some variation of “believed to have occurred between”, and expect to find it on the linked FAQ page instead of in the email. The distance between those two dates is dwell time, and it is the closest thing to an honest severity score in the whole document.
Two days means somebody caught it. Eleven months means the data was sold on twice and folded into a product before you ever heard the word breach.
Severity is the field list and nothing else
Here is the position I will defend. How worried you should be has no relationship to how the company sounds. A calm, carefully drafted letter can carry a full customer database. An alarmed one can carry a misconfigured storage bucket that a researcher found and reported before anyone else went near it.
Tone tracks who reviewed the draft. Severity tracks the fields, so find the list and sort what you see.
Name and email address. The common case and the mild one. What it costs you is that you are now a confirmed customer of that company, which is the part a convincing phishing email was previously missing. There is a version of this that is severe: where membership itself is the sensitive fact, a clinic or a dating service or a support group with a roster, an email list is the entire disclosure.
Passwords, hashed or otherwise. Hashed is a range. A current algorithm at a sensible cost setting means real money spent per password guessed. An unsalted scheme from a system built in 2011 means a single consumer graphics card gets through the easy half of that table over a weekend. If the notice names the algorithm, go and look it up. If it stays vague, assume the worse answer, because the companies that got this part right are usually keen to say so.
Payment card numbers. Awkwardly, the least damaging item on the list. Cards cancel, replacements arrive inside a week, and in most places the bank carries the liability for fraudulent charges.
Date of birth, passport and national identity numbers, address history. This group changes the shape of the problem, because none of it rotates. A password takes forty seconds to change. A date of birth takes forever.
Security questions with the answers attached. Consistently underrated. Your mother’s maiden name is a permanent credential you have handed to every bank you have ever held an account with, and it is now a permanent credential somebody else holds too.
The order to work in
Read the field list. Two minutes, and it decides the rest.
Change the password on that account, then sweep everywhere you reused it. This is the step people abandon and it is worth more than the rest combined. I have written separately about why reuse is the mechanism behind most account takeovers, so I am not going to relitigate it here. Just run the sweep, starting with the mailbox your password resets land in.
Turn on two factor for the breached account while you are already in the settings.
Expect phishing for the next two months and treat any message about the breach as hostile. The people buying these lists read the same coverage you do. A company has just told several hundred thousand people to expect contact about their account, and a fake notice riding in behind a real one is a standard move. Navigate by typing the address yourself.
Take the credit monitoring if it costs nothing, and be clear about what it is. It is the cheapest item that could have gone in that envelope, it runs the company a fraction of a dollar per head at that volume, and it reports damage once the damage exists. What prevents the damage is a freeze on your credit file, where the bureau will not release your report to a new lender until you lift it. Usually free, roughly ten minutes per bureau, different names in different countries. It goes unmentioned in the letter because it is not the company’s to hand out.
Assume there is a second letter
The follow up notice revising the numbers upward is common enough to plan around.
The shape is consistent. First letter says a limited number of accounts and lists two fields. Eight weeks later, a second notice says the review is complete, the affected population is larger than initially estimated, and a third field has appeared on the list.
Nobody lied. That first letter was written eleven days into an investigation that ran four months, against a clock which started the day somebody noticed something odd in a log.
So read the first email as an opening estimate. Where the listed fields sit near a decision boundary, act as though the list is one item worse than what got printed, because that is the direction these corrections travel. I have yet to see one go the other way.
Old dumps keep coming back
Something the letters never mention. Breached data does not decay on a schedule.
Old dumps get merged into compilations, deduplicated against each other, and put back into circulation years later as though they were new. A password taken in 2019 surfaces in a combination list in 2026 and gets replayed against accounts that did not exist when it leaked.
Which is the practical case for running the reuse sweep on the day the letter arrives. Promising yourself a quiet weekend for it never works, and the window on this data does not close.
The part I got wrong
I triaged these by severity for years, had my effort in precisely the wrong place, and told other people to do it the same way.
Letters mentioning identity documents went in the urgent pile. Letters saying only your name and email address were involved got deleted unread.
Then a phishing attempt landed about six weeks after one of the ones I had deleted. It named the right service and it arrived inside the window where I would plausibly have been hearing from them. I did not fall for it, and the reason was that I happened to be sitting at a desk instead of holding a phone in a queue.
The error is easy to state once you see it. The serious breach gave me almost nothing to do. Freeze the file, stay alert, accept that a date of birth is permanent. One afternoon of work and then it is out of my hands for good.
The mild breach was the one where my own behaviour was the only control left in the system. That was the letter needing the attention, and that was the letter I had trained myself to bin.
I also let the free monitoring from one of those notices lapse after twelve months and failed to notice for most of a year, which is a fair measure of what I quietly thought it was worth.
More privacy tools tested honestly, failure modes included, are here.