Don’t panic. If your personal data was exposed, report it to the right authority for your situation: IdentityTheft.gov for identity theft risk, the IC3 for internet-enabled crime, the U.S. Postal Inspection Service for stolen mail, or your State Attorney General for consumer complaints. Then lock down your finances immediately. The FTC emphasizes that your most important role right now is personal remediation, not waiting for law enforcement to act.
Your immediate checklist:
- Freeze your credit at Equifax, Experian, and TransUnion — free and the single most effective fraud block.
- Place a fraud alert — an initial alert lasts one year and flags your file to lenders.
- Change your email password first — it’s the master key to every other account you own.
- Call your bank and card issuers — report the breach and request new account numbers if financial data was exposed.
- Document everything — save breach notification emails, screenshots, and dates before you file any report.
Table of Contents
- Which authority should you contact for your type of breach?
- How to file reports with each authority, step by step
- What information and evidence should you gather before filing?
- Priority actions to protect your identity and finances right now
- What should you expect after filing, and when should you follow up?
- When should you consider hiring an identity-recovery service?
- Key Takeaways
- A note on why this guide exists
- Techstacktoday’s privacy reviews can help you choose what’s next
- Authoritative sources and official reporting links
Which authority should you contact for your type of breach?
Match your situation to the right agency before you file. Reporting to the wrong office wastes time and can delay any investigation, as explained in the detailed post-mortem analysis of breaches that illuminates attack vectors and organizational failures.

| Breach Scenario | Primary Authority | When to Escalate |
|---|---|---|
| Company breach exposing your SSN, DOB, or financial data | FTC / IdentityTheft.gov | State Attorney General if the company is local |
| Suspected identity theft (fraudulent accounts, tax fraud) | IdentityTheft.gov | FBI field office if losses are significant |
| Phishing, ransomware, or online fraud | IC3 (ic3.gov) | FBI / U.S. Secret Service for large financial losses |
| Stolen mail or mailed documents intercepted | U.S. Postal Inspection Service | Local FBI field office if USPS is unfamiliar with the case |
| Medical records exposed | HHS Office for Civil Rights + FTC | State AG if a state health-privacy law applies |
| Consumer complaint against a company | State Attorney General | FTC if the company operates across multiple states |
| General local crime or in-person fraud | Local police department | FBI / U.S. Secret Service for organized criminal activity |
The FTC confirms that mail theft and stolen mailed documents go to the U.S. Postal Inspection Service first. If local police are unfamiliar with information-compromise investigations, contact your local FBI field office or the U.S. Secret Service. Health data breaches may also trigger the HHS Health Breach Notification Rule on top of state-level requirements, since all 50 U.S. states have breach-notification laws.
How to file reports with each authority, step by step
Work through these in order. Most take under 15 minutes each.
IdentityTheft.gov (FTC)
- Go to IdentityTheft.gov and click “Get started.”
- Select the type of identity theft that matches your situation.
- Complete the guided questionnaire — the site generates a personalized recovery plan and pre-filled letters for banks and credit bureaus.
- Save or print your Identity Theft Report. This document carries legal weight with creditors.
- Your report feeds the Consumer Sentinel Network, a database law enforcement agencies access directly.
IC3 (Internet Crime Complaint Center)
- Visit ic3.gov and click “File a Complaint.”
- Complete all required fields — name, address, financial loss amount, and a full incident description.
- Type the words “data breach” in the incident description field. IC3 routes complaints by keyword, so this helps investigators assign your case correctly.
- Submit and save your complaint reference number immediately.
Local police department
- Call your non-emergency line or visit in person.
- Bring printed copies of the breach notification, any fraudulent account statements, and your IdentityTheft.gov report.
- Request a written case number. Banks and credit bureaus often require a police report before reversing fraudulent charges.
State Attorney General
- Find your state’s AG office at naag.org or search “[your state] attorney general data breach complaint.”
- Most states have an online consumer complaint form. Look for fields labeled “data breach” or “identity theft.”
- Include the company name, breach date, and what data was exposed.
U.S. Postal Inspection Service
- Go to postalinspectors.uspis.gov or call 1-877-876-2455.
- Report mail theft, intercepted statements, or stolen pre-approved credit offers.
- Provide dates, your address, and a description of what was taken.
FBI / U.S. Secret Service
Contact your local FBI field office (tips.fbi.gov) or the nearest U.S. Secret Service field office when financial losses are large, when organized criminal activity is suspected, or when local law enforcement has confirmed a case but needs federal support. These agencies typically require a police report or documented evidence of misuse before opening a full investigation.
Pro Tip: Timestamp every action. Screenshot your submissions, note the exact time you filed each report, and store all case numbers in one document. Investigators use these timestamps to establish timelines, and you’ll need them if you escalate later.
What information and evidence should you gather before filing?
Strong reports get faster attention. Gather these items before you open any complaint form.

| Evidence Item | Why It Matters to Investigators |
|---|---|
| Breach notification email or letter | Establishes the date you were notified and the company responsible |
| Screenshots of fraudulent accounts or charges | Proves active misuse, not just exposure |
| Email headers from phishing messages | Helps trace the origin of the attack |
| Bank or credit card statements with unauthorized charges | Quantifies financial loss for IC3 and police reports |
| Photos of stolen mail or mailed documents | Required for USPS Inspection Service complaints |
| Your SSN, DOB, and account numbers affected | Needed to complete FTC and IC3 complaint fields accurately |
| Prior correspondence with the breached company | Shows you attempted resolution and documents their response |
The FTC provides model breach letters that show exactly what detail investigators and creditors expect. Use IdentityTheft.gov/databreach for tailored templates you can fill in and send directly to banks or credit bureaus.
Priority actions to protect your identity and finances right now
Reporting is important. Protecting yourself is urgent. These steps limit the damage while authorities process your case.
- Freeze your credit at all three bureaus: Equifax (equifax.com/personal/credit-report-services), Experian (experian.com/freeze), and TransUnion (transunion.com/credit-freeze). Freezes are free and stay in place until you lift them. The FTC confirms initial fraud alerts last one year; a freeze is stronger and has no expiration.
- Place a fraud alert — call any one bureau and they notify the other two automatically.
- Change your email password immediately, then update passwords on financial accounts, social media, and anywhere you reused the same credentials. A password manager makes this faster and keeps new passwords unique.
- Call your bank and card issuers. Script: “My personal data was exposed in a breach. I’d like to flag my account for suspicious activity and request a new card number.” Ask for a fraud case number.
- Email your bank if you prefer a paper trail: “I’m writing to notify you that my personal information was exposed in a data breach on [date]. Please place a fraud alert on my account and confirm in writing.”
- ️ Monitor your credit reports at AnnualCreditReport.com. You’re entitled to free weekly reports from all three bureaus.
Pro Tip: Write down your freeze PINs and store them somewhere offline. You’ll need them to temporarily lift a freeze when applying for credit. Losing a PIN means a verification process that can delay a loan or apartment application.
For a full post-breach protection checklist, Techstacktoday has a step-by-step guide covering every account type.
What should you expect after filing, and when should you follow up?
Set realistic expectations. IC3 and FTC reports primarily feed law enforcement databases; they rarely generate a direct response to you. That’s not a failure — it’s how the system works.
Federal law enforcement often needs concrete evidence of misuse before committing resources to a case. A police report, fraudulent account statements, or documented financial loss significantly increases the chance of an active investigation. Filing early still matters: it creates a timestamped record that strengthens your case if fraud surfaces later. The FTC notes that early reporting improves investigative effectiveness by establishing timelines before evidence degrades.
Follow-up schedule:
- Week 1: Confirm you have case numbers from every agency you contacted. Call local police if you haven’t received a written report within 5 business days.
- Week 2–4: Check your credit reports for new accounts or inquiries you didn’t initiate.
- Month 2–3: If fraud has materialized, contact the FBI field office or U.S. Secret Service with your police report and documented losses.
- Ongoing: Review bank and credit card statements monthly. Watch for small test charges (under $1) that signal a card is being probed.
If your case involves cross-border data exposure, note that international frameworks like the EU’s GDPR require organizations to notify supervisory authorities within 72 hours of discovering a breach — a standard that can affect U.S. residents whose data is processed by European companies.
When should you consider hiring an identity-recovery service?
Handle it yourself if the breach was limited to one account and you’ve already frozen credit and changed passwords. Consider professional help when:
- Multiple account types were exposed (SSN, medical records, and financial data together).
- Fraudulent accounts have already been opened in your name.
- A child’s identity was compromised — child identity theft is especially hard to detect and resolve without specialist help.
- Banks or credit bureaus have denied your dispute and you’re stuck in a loop.
- You simply don’t have the time to manage 10+ hours of calls and paperwork.
A reputable identity-recovery service should give you a dedicated case manager, a written recovery plan with documented milestones, transparent pricing with no surprise fees, and clear records of what was resolved. Red flags: any service that guarantees complete removal of all negative items, demands sensitive data like your SSN before signing a contract, or refuses to provide a written agreement.
Techstacktoday has reviewed and ranked identity-protection services based on real-world testing, not paid placements. Check those reviews before you commit to any provider.
Key Takeaways
Reporting a data breach to authorities is only half the job — immediate personal remediation steps like credit freezes and fraud alerts are what actually limit identity theft harm.
| Point | Details |
|---|---|
| Match agency to scenario | Use IdentityTheft.gov for identity theft, IC3 for internet crime, USPS for mail theft, and local police for documented fraud. |
| Freeze credit immediately | Place free freezes at Equifax, Experian, and TransUnion before filing any report. |
| Document everything | Save case numbers, timestamps, and screenshots — federal agencies need evidence of misuse to open investigations. |
| Follow up on a schedule | Check credit reports weekly for the first month; escalate to FBI or Secret Service only after fraud is confirmed. |
| Techstacktoday reviews | Techstacktoday’s independently tested identity-protection and password manager reviews help you choose vetted services post-breach. |
A note on why this guide exists
Most data breach guides tell you to “contact the FTC” and leave it there. That’s not enough. The gap between filing a report and actually stopping the damage is where most people get hurt — they wait for a government agency to fix things while fraudulent accounts pile up. The TechStackTeam built this guide because Techstacktoday has reviewed over 50 privacy and identity-protection services, and the pattern we see repeatedly is that readers who act fast on remediation (freeze, alert, password change) suffer far less harm than those who focus only on reporting. Reporting matters for enforcement and statistics. Recovery is what protects your family. We test services so you can choose the right one without guessing.
Techstacktoday’s privacy reviews can help you choose what’s next
Filing reports is the right first move. But once the immediate crisis is contained, you’ll want tools that keep watch so you’re never caught off guard again.

Techstacktoday reviews identity-protection services, password managers, and data removal services based on hands-on testing, not sponsored rankings. Every review scores services on real-world performance: how fast they detect fraud, how easy the recovery process is, and what you actually get for the price. Free resources on the site cover the basics; paid service reviews go deeper into features, pricing tiers, and what each plan covers. If you’re weighing whether a paid identity-protection subscription is worth it after a breach, start with the privacy tools comparison checklist to see which category fits your situation. No pressure, no upsell — just the information you need to decide.
Authoritative sources and official reporting links
| Resource | What It’s For |
|---|---|
| IdentityTheft.gov | Generates a personalized recovery plan and pre-filled dispute letters; reports feed the Consumer Sentinel Network for law enforcement. |
| IC3 Data Breach Complaint Page | File internet-enabled crime complaints; include “data breach” in the description for correct routing. |
| FTC Data Breach Response Guide | Official FTC guidance on individual recovery steps, model letters, and credit bureau contacts. |
| USPS Postal Inspection Service | Report mail theft, stolen statements, or intercepted mailed documents. |
| NAAG State AG Directory | Find your state Attorney General’s consumer complaint portal for state-level breach reporting. |
| AnnualCreditReport.com | Access free weekly credit reports from Equifax, Experian, and TransUnion. |
Store these links now, before you need them. IdentityTheft.gov is the fastest starting point for most individuals — it creates a recovery plan, not just a complaint number. If you’ve already filed and want to understand how breached data can resurface via data brokers, Techstacktoday’s guide explains the risk and what removal steps actually work.
This article is general information, not legal or financial advice. Confirm current reporting requirements with the relevant agency or a qualified professional for your specific situation.