The 2025 Breach Reality Check and What to Do When You Get a Breach Notice

by | Feb 16, 2026 | Cybersecurity

Home  ›  Blog  ›  Current Post

What to Do When You Get a Breach Notice — and Why Most People Get It Wrong

By Dayton Allied Business Solutions  ·  Published February 2026

You've probably gotten one. Maybe more than one this year. The envelope arrives, or the email lands, and the subject line reads something like: “Notice of Data Security Incident.” Your first instinct might be to glance at it and move on. That instinct is exactly what cybercriminals are counting on.

The 2025 Identity Theft Resource Center (ITRC) Annual Data Breach Report — the 20th edition of the most comprehensive breach tracking study in the U.S. — delivers a clear message: breaches are no longer rare disruptions. They are a constant feature of modern life. And the notices companies send you are becoming less useful, not more.

This article explains what the data actually says, what a breach notice really means for you and your business, and exactly what steps to take — in order — the moment one lands in your inbox.

The 2025 Numbers: A Record That Should Alarm You

The ITRC tracked 3,322 data compromises in the United States in 2025 — the highest annual total ever recorded, and the third straight year topping 3,000 incidents. That represents a 79% increase in data compromises in just five years.

To put it plainly: the environment you and your employees operate in today is nearly twice as dangerous as it was in 2020.

“The bad guys are getting better at targeting. At the end of the day, it’s all about money.” — James E. Lee, President, Identity Theft Resource Center

The most targeted sectors in 2025 were Financial Services (739 compromises), Healthcare (534), Professional Services (478), Manufacturing (299), and Education (188). If your business operates in any of those categories — or works with vendors who do — you are in the crosshairs.

The Professional Services sector — law firms, accountants, IT consultants — deserves special attention. Attacks on these firms increased 39% year over year and 162% over five years. Attackers use them as stepping stones: breach one service provider and you gain a path into dozens of their clients.

Supply chain attacks followed a similar pattern. The number of organizations affected by third-party supply chain breaches nearly doubled year over year, and supply chain incidents now account for roughly 30% of all breaches involving at least one third party.

Source: ITRC 2025 Annual Data Breach Report (HIPAA Journal coverage)

The Hidden Crisis: Your Breach Notice Tells You Almost Nothing

Here is the part of the story most coverage buries. The notices are getting worse.

In 2020, nearly 100% of breach notifications included information about how the breach occurred — the root cause, the attack vector, what data was taken and when. By the end of 2025, only 30% of notices included that information. The other 70% tell you that “a security incident occurred” and leave you to figure out your own level of risk.

70% of 2025 breach notices failed to explain how the breach happened — up from 65% in 2024 and a dramatic collapse from near-100% in 2020. (ITRC)

Why the regression? Largely to reduce legal exposure. Companies have learned that the more specific they are about what happened, the more liability they face. The result is vague legal language that may technically satisfy state notification requirements while telling victims almost nothing actionable.

The ITRC’s own consumer survey found the consequences of that vagueness are real: 48% of people who did nothing after receiving a breach notice said they were exhausted from receiving too many, 46% felt helpless, and 41% concluded the vague language meant the breach wasn’t serious. That last group is especially at risk. A legally careful notice is not the same as a minor breach.

The ITRC’s president James E. Lee said it plainly: “Businesses should prioritize transparency over liability mitigation.” Until they do, the burden of interpreting risk falls on you.

Source: GovTech — 2025 Data Breach Report: More Compromises, Less Transparency

What to Do the Moment You Receive a Breach Notice

Don’t set it aside. Here is a step-by-step response, prioritized in order of impact.

Step 1 — Read It Carefully, But Skeptically

Determine what type of data was involved: name, email, password, Social Security number, financial account numbers, medical records, driver’s license. The type of data determines your next steps. Note the date the breach occurred versus the date you are being notified — a gap of many months is a warning sign about how seriously the company takes transparency. Keep the notice.

Also: verify it is legitimate. Phishing emails disguised as breach notices are common, especially following high-profile incidents. Look up the company’s phone number independently and call to confirm before clicking any links in the notice.

Step 2 — Freeze Your Credit at All Three Bureaus

If any financial, identity, or Social Security data was involved, place a credit freeze immediately. A freeze prevents anyone from opening new credit in your name — even if they have your Social Security number. Unlike a fraud alert, which only asks lenders to verify identity (and is often ignored), a freeze is a hard block.

Freeze your file at all three bureaus:

  • Equifax: equifax.com/personal/credit-report-services
  • Experian: experian.com/freeze/center.html
  • TransUnion: transunion.com/credit-freeze

Freezes are free and can be temporarily lifted when you need to apply for credit. If children’s data was involved, freeze their credit too — child identity theft often goes undetected for years.

Note: Social Security numbers were involved in two-thirds of all 2025 breach reports, and SSN-related breaches have nearly doubled over five years. If yours was exposed, treat it as a long-term risk, not a one-time event.

Step 3 — Change the Affected Password — and Anywhere You Reused It

Password reuse is the biggest multiplier of breach damage. Attackers use automated “credential stuffing” tools to try exposed username/password combinations across hundreds of other sites immediately after a breach. If you use the same password for a breached service and your Microsoft 365 or business email login, that one breach can become many.

Change the exposed password immediately. Then audit and change it everywhere else you reused it or a variation of it. A password manager makes this practical — it generates and stores unique, complex passwords for every account.

Step 4 — Enable or Verify Multi-Factor Authentication

Multi-factor authentication (MFA) stops a large percentage of account takeover attempts even when credentials are compromised. If MFA is not enabled on the affected account — or on your email, Microsoft 365, banking, or healthcare portals — turn it on now. If it is already enabled, confirm it is functioning and that you recognize all registered devices.

The ITRC president specifically named MFA as one of the foundational requirements for digital safety in 2025 and beyond.

Step 5 — Accept Free Identity Protection — But Know Its Limits

Most breach notices offer one to two years of free credit monitoring or identity protection services. Accept it — it costs you nothing and provides early warning. But do not treat it as a substitute for a credit freeze. Monitoring tells you after something has gone wrong. A freeze helps prevent it.

Step 6 — Monitor Financial Accounts and Your Credit Reports

Review bank statements and credit card accounts for unauthorized transactions. U.S. residents are entitled to free annual credit reports from all three bureaus at AnnualCreditReport.com. Stagger your requests — pull one every four months — so you are reviewing your credit throughout the year. Look for accounts you didn’t open, hard inquiries you didn’t authorize, or unfamiliar addresses.

Step 7 — Expect Downstream Attacks

A breach notice is often not the end of your exposure. It can be the beginning. Attackers trade stolen data in bulk, and they use breach headlines to craft convincing follow-up attacks: phishing emails, text messages (smishing), and phone calls (vishing) impersonating the breached company, your bank, or government agencies.

In the ITRC consumer survey, 49% of breach victims reported an increase in spam emails and robocalls after a breach, 40% reported an increase in phishing attempts, and 40% experienced an attempted account takeover. Heightened skepticism for several months after a breach is warranted.

For Business Owners: Why This Isn’t Just a Personal Problem

Many business owners receive a breach notice and treat it as a personal matter. That is a costly assumption.

Your employees reuse passwords. Your vendors reuse passwords. Old accounts remain active. When credentials are exposed in a consumer breach — a retail site, a streaming service, a healthcare portal — attackers test those credentials against business systems immediately. If a staff member used the same password for a breached service and their business email login, that is your door being opened.

The ITRC found that 81% of small businesses reported experiencing a cyberattack, breach, or both in the past year. Nearly 40% raised prices to cover breach-related costs. These are not abstract risks.

If your business experiences or suspects a breach of its own systems, you face a separate and more complex set of obligations: most state laws require notifying affected individuals, and 34 states require reporting to the state attorney general. Depending on your industry, federal requirements under HIPAA or the FTC Safeguards Rule may also apply.

The steps that reduce your exposure are practical and achievable:

  • Enforce MFA on all business accounts, especially email and remote access
  • Eliminate password reuse through a company password manager policy
  • Remove unused or former-employee accounts promptly
  • Limit admin privileges to those who genuinely require them
  • Train staff to recognize phishing — it remains a leading attack vector
  • Monitor login activity for anomalies

These steps do not guarantee you will never be breached. Nothing does. But they dramatically reduce damage when exposure occurs — and in 2025, the question is when, not if.

Source: ITRC 2025 Annual Data Breach Report press release

Quick Reference: Breach Response Checklist

  • Read the notice — identify what data was exposed and note the breach date
  • Verify the notice is legitimate before clicking any links
  • Freeze your credit at Equifax, Experian, and TransUnion
  • Change the affected password everywhere you reused it
  • Enable or verify multi-factor authentication on critical accounts
  • Accept any free identity monitoring offered in the notice
  • Pull credit reports and review for unfamiliar accounts or inquiries
  • Watch bank and card statements for unauthorized activity
  • Stay alert for phishing, smishing, and vishing for months afterward
  • If a business credential was involved, escalate: review login history, audit admin accounts, check for forwarding rules

Data breaches are a permanent feature of the threat landscape. The 2025 ITRC report makes clear that even well-protected organizations get hit, and that the notices you receive will continue to tell you less than you need to know. The difference between those who limit their exposure and those who don’t is preparation — having the right accounts hardened, the right responses planned, and the right steps ready to execute before a notice ever arrives.

If a key employee received a breach notice today involving reused credentials, would you know immediately whether your business systems were at risk? If the answer is uncertain, that’s the gap to close.

The DaytonABS Care Plan is built around exactly this kind of proactive hardening — account security reviews, MFA enforcement, admin role cleanup, and practical response guidance so your team is never guessing what to do next. Reach out any time.

Dayton Allied Business Solutions  ·  daytonabs.com

Filed under: All Posts

About the Author

David Pfiffner is the owner of Dayton Allied Business Solutions, a managed IT and web solutions company serving businesses in the Huber Heights and Dayton, Ohio area. Nearly two decades of hands-on technology experience.

Need IT Help?

Proactive IT management, cybersecurity, backup, and web solutions for Dayton businesses. Flat monthly pricing. Local support.

Explore the Blog

Browse all posts for practical technology tips, IT advice, and web strategy for small businesses in the Dayton area.

Ready to Put This Into Practice?

If something in this post resonated, let’s talk. We work with small businesses in the Dayton area on exactly these kinds of problems.

Special Offer!

Get a free 30-minute review of your IT setup. We look at what you have, tell you what is at risk, and give you one thing you can do today at no cost and no obligation.

Grab the Offer!