This month a mortgage lender and a finance company told tens of thousands of customers that their Social Security numbers were stolen. The breach emails landing right now are the serious kind. Here is exactly what to do, in the order that matters.
Most people do one of two things when a breach email arrives. They panic and freeze everything, or they delete it and hope for the best. Neither is right. The right move depends on what was actually taken - and most breach emails tell you, if you know where to look.
First: Is the Email Real?
Scammers love breach news. They send fake breach emails that look exactly like real ones, hoping you will click a “protect your account” link and hand over your password.
Here is the rule: do not click any link in a breach email. Not the “enroll in monitoring” link. Not the “log in to check” link. None of them.
Instead, open your web browser and type the company’s web address yourself. Or call the phone number on your actual bill or card - not the number in the email. If the breach is real, the company will have a notice on its site.
The sender domain is the fastest clue. A real notice from Lennar Mortgage comes from a Lennar domain. A fake one comes from something like lennar-security-alert.com or lennarsecure.net. Look closely.
Rung 1: PII Only
Some breaches expose names, addresses, phone numbers, and email addresses - but nothing that lets a thief open a credit card in your name. Framework, Ceva Logistics, and Trezor all sent notices like this in early August. Updoc, an Australian telehealth service, exposed names, emails, and addresses only.
If that is what the notice says, here is your action list:
- Change nothing. Your passwords are safe. Your bank accounts are safe. Your Social Security number was not taken.
- Raise your vigilance for two months. Scammers now have your real name, address, and phone number. They will use that to send convincing phishing texts and emails. If someone calls and knows your address, that does not mean they are legitimate. Hang up and call the company back on a number you trust.
- Watch for follow-up scams. The most common one: a fake “credit monitoring” offer that asks for your Social Security number to “enroll.” Do not give it.
That is the whole list. PII-only breaches are annoying, not dangerous - as long as you do not let the follow-up scams trick you into making them dangerous.
Rung 2: SSN or Financial Details
This is the rung that matters right now. Lennar Mortgage and Heights Finance both notified customers in mid-August that names, contact info, dates of birth, government IDs, Social Security numbers, and financial account details were taken. Chelan County, Washington sent similar notices on August 11.
If your notice says SSN or financial account details were exposed, you have work to do. It is not hard work, but it is specific work.
Place a credit freeze at all three bureaus. A credit freeze stops anyone from opening a new account in your name. It is free, it takes about ten minutes per bureau, and it is the single most effective step you can take.
The FTC has a step-by-step guide if you get stuck. You will need to unfreeze temporarily if you legitimately apply for credit later - that is normal, and it is free too.
Add a fraud alert. A fraud alert tells creditors to take extra steps to verify your identity before opening an account. It lasts one year and is also free. You only need to contact one bureau - they are required to notify the other two.
Enroll in the free monitoring if it is offered. Lennar is offering two years of Kroll monitoring, with an enrollment deadline of November 20. Do not pay for monitoring that a breach notice tries to sell you. The free offering is the real one.
Watch your statements. Check bank and credit card statements for transactions you do not recognize. Do this weekly for the next month, then monthly. The thief who has your SSN is not going to use it today - they will sell it to someone who uses it in six months.
Rung 3: Passwords or Payment Exposed
If the notice says passwords or payment card numbers were taken, act fast - but act on the right things first.
Change that account’s password immediately. Use a password you have never used anywhere else. If you reuse passwords across sites - most people do - change the password on any other account that shared it. The safest way to never have this problem again is to use a password manager. I covered why that is non-negotiable in the network security guide.
Call your card issuer. If a payment card number was exposed, the issuer will usually cancel it and send a new one. You do not need to close the account - just the card number. Ask them to watch for suspicious charges in the meantime.
Enable two-factor authentication on the breached account. If the company offers it - text codes, authenticator apps, or security keys - turn it on. A stolen password is useless without the second factor.
The Standing Checks
No matter which rung you are on, these three habits protect you after any breach:
Check your email at Have I Been Pwned. haveibeenpwned.com tracks breach data and will tell you if your email address appears in known leaks. It is free, safe, and run by a security researcher - not a data broker.
Put two-factor authentication on your email account. Your email is the master key to everything else. If someone gets into your email, they can reset passwords on your bank, your shopping accounts, and your social media. Protect it first.
Never click “follow-up” links. The real company already told you what happened. Any email that arrives later claiming to be an “update” or “urgent action required” is more likely to be a scam than real. Log into the company’s site directly if you want to check.
A Breach Email Is Not an Emergency
It is a to-do list - and the first item is usually “find out what was taken.”
Most breach notices are PII-only. Those mean vigilance, not panic. The SSN-level notices that landed this month are the exception, and they are exactly why the credit freeze exists: a free, ten-minute action that shuts down the main risk.
You do not need to monitor your credit for life. You do not need to buy identity theft insurance. You need to read the notice, match it to the right rung, do the steps, and move on.
What to Do Now
- Find the most recent breach notice in your email
- Confirm it is real by logging into the company’s site directly - do not click email links
- Find the “what was exposed” section and match it to the rung:
- PII only: raise vigilance, watch for follow-up scams
- SSN or financial details: freeze your credit at all three bureaus, add a fraud alert, enroll in free monitoring
- Passwords or payment: change the password, call your card issuer, enable two-factor authentication
- Check Have I Been Pwned for your email address
- Enable two-factor authentication on your email account if you have not already
The breach already happened. The only thing that matters now is what you do next.