The breach tower · the atrium

Data breach: the tower, floor by floor

This is the entrance to the data breach tower. Almost everybody arrives here on the same day: a company has written to say something happened, or a browser has put a warning next to a password, and the question is how worried to be.

The honest headline is that this is survivable and mostly free to fix, and that the order you do things in matters far more than which product you buy. The floors above are arranged in that order. Check what is actually out, understand what that particular kind of data is worth to somebody, close the doors that are open, and only then decide whether any monitoring service is worth a subscription.

The second thing worth knowing is that a breach is rarely about you. Your details were sitting in a company’s database alongside several million other people’s, and that company was the target. Nothing you did caused it and no password of yours was guessed. What you control is entirely on the other side of the event: whether the password that leaked was used anywhere else, and how fast you close that off.

Three levels, and you are on the first. The atrium lists the floors; a floor covers one subject completely and holds the shorter guides underneath it. Nothing here is more than three clicks from the front door.

One more thing before you climb, because it changes how the whole building reads. There is a difference between your data being in a breach and your accounts being at risk, and the two are constantly presented as the same thing by companies with something to sell. Being in a breach is nearly universal: if you have used the internet for a decade, you are in several, and finding out is useful rather than alarming. Being at risk is a narrower and more answerable question — it depends on what leaked, whether that password protects anything else, and whether a second factor stands behind it. The floors above are built to move you from the first question to the second as quickly as possible, because the second is the one you can actually do something about.

Where to start

Five ways in. If you only have five minutes, take the first and then the third.

“Am I in a breach at all?”
Start with checking
“A company emailed me to say I was.”
Read what that means in what leaked
“What do I do right now?”
Go straight to the first hour
“Should I pay for monitoring?”
The honest answer is in monitoring and after
“My card details were in it.”
That is a specific floor in what leaked
“It was my child’s school that was breached.”
There is a floor for that in what leaked

Checking

Finding out what is actually out there, using services that do not charge for it and do not need anything from you beyond an address.

Have I Been PwnedWhat the service says it does with the address you type, quoted from its own FAQ with the date.Being built
Your browser’s own checkThe warning built into the browser you already use, and what it is comparing against.Being built
Checking a password, not an addressHow a password can be checked against known leaks without ever being sent anywhere.Being built
What the results meanReading a list of breaches without concluding either too much or too little from it.Being built

What leaked

Not all breaches are the same event. What was taken decides what can be done with it, how long it stays dangerous, and whether you need to act at all.

Email and passwordThe most common kind, the most dangerous, and the one entirely fixed by not reusing passwords.Being built
Card detailsWhat a stolen credit card number is worth, why this is often the least alarming kind, and who carries the loss.Being built
Identity documentsPassport and licence numbers, which cannot be changed, and what follows from that.Being built
Health and employment recordsThe categories with the longest tail, and the specific harms they enable.Being built
Children’s dataWhy a child’s details are worth more to a criminal than an adult’s, and what to do.Being built

The first hour

What to do, in order, on the day you find out. Every step here is free, and the first three cover most of the risk.

Change the right password firstWhich account before which, and why the mailbox always comes before the bank.Being built
Everywhere you reused itThe step people skip, and the one the whole attack depends on them skipping.Being built
Turn on the second factorMaking the next leak of that password an inconvenience rather than an incident.Being built
Check what else movedForwarding rules, connected apps, recovery addresses — the things attackers change quietly.Being built
Tell the bank, or do notWhen contacting them helps, when it achieves nothing, and what to ask for.Being built

Monitoring and after

The subscriptions sold on the strength of this fear, what they can genuinely see, and the free alternatives that do most of the same work.

Credit monitoringWhat it watches, what it cannot prevent, and where it is free by law.Being built
Breach notification servicesBeing told next time, without paying somebody to tell you.Being built
When the leak keeps hurtingDetails that cannot be changed, and how to live with them sensibly.Being built
Your rightsWhat a company owes you when it loses your data, and how that differs by country.Being built

What this tower will not do

It will not frighten you into a subscription. Fear is the entire marketing engine of this category, and most of what those services do — telling you that you appear in a leak — is available free and takes thirty seconds. The floors say clearly which parts are genuinely worth money and for whom.

It will not tell you to change every password you own every few months. That advice makes passwords weaker rather than stronger, the standards bodies dropped it deliberately, and the floors above explain what replaced it.

And it will not pretend a breach can be undone. Once data is out it is out, copies exist, and no service can retrieve them. What can be changed is what that data still unlocks, which is almost always more than people assume and entirely within their control.

A note on how these floors are sourced, because this subject is unusually full of confident numbers with no origin. Where a floor says what a checking service does with your address, that is quoted from the service’s own documentation with the date we read it. Where it describes what a company owes you after losing your data, it points at the regulation rather than paraphrasing it. And where the honest answer is that nobody knows — how many copies of a given dump exist, for instance — the floor says that instead of inventing a figure. What holds instead is simple: nearly every step in this tower costs nothing at all, and no floor carries an affiliate link.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.