Local Tech Fix (626) 655-0020
All articles

A Letter Says Your Data Was Breached. Here Is How to Check It Is Real and What to Do in What Order.

September 14, 2026

The letter is not the emergency. The emergency is the wave of calls and emails that arrives afterwards, from people who know you are expecting to hear about this.

closeup of mail app icon on phone
Photo by Brett Jordan on Unsplash

It comes in an ordinary envelope, and it is almost always late. A company writes to tell you that some of your personal information was taken, usually several months ago, and that they take your privacy very seriously. Half the time it is a business you had forgotten you ever dealt with — a lab your doctor sent a sample to, a payroll provider two employers back, a city department that holds a permit with your name on it.

Two questions follow, in this order, and both of them are reasonable. Is this real, or is it the scam? And do I actually have to do anything, or is this paperwork?

The answers are better than most people expect, because California is unusually specific about these letters. The law says what the letter must be titled, what headings it must use, what facts it must contain and how quickly it must be sent. It also requires the sender to file a copy with the Attorney General for anything touching more than 500 residents — and the Attorney General publishes them. That means you can verify the letter in a couple of minutes without touching a phone number or a link printed on it, which is the single most useful habit in this whole subject.

What follows is that verification, then the triage, then the two or three things that are genuinely worth doing. This is not legal advice and we are not lawyers; it is what a technician tells a customer who has walked in holding the envelope.

Before anything else: California publishes these letters

Section 1798.82 of the California Civil Code requires a business that has to notify "more than 500 California residents as a result of a single breach" to "electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General." Those samples are posted publicly, and you can search them at the Attorney General's site under Privacy, Data Security Breach.

The Attorney General's own description of the list is the part worth knowing: "You can search by the name of the organization that sent the notice, or simply scroll through the list. To read a notice, click on the name of the organization in the list. Then click on the link titled 'Sample Notification.'"

So the check is: take the name at the top of your letter, search the register for it, and compare the sample notice the state holds against the one in your hand. Same event, same dates, same categories of data, same instructions. If it matches, the letter is real, and you now have a second copy of it from a source no scammer can edit.

One caveat comes straight from the register itself, and it explains the most common piece of confusion: "in some cases the organization that sent the notice is not the one that experienced the breach. For example, a bank may notify of a credit card number breach that occurred not at the bank, but at a merchant." A letter from a company you have never heard of is not automatically fake. It may be the company that was actually holding your data on somebody else's behalf.

Two limits on the register, stated plainly so you do not over-trust it. It only covers breaches affecting more than 500 California residents, so a genuinely small incident will not appear. And the sample is filed within fifteen calendar days of the notices going out, so a letter that arrived this morning may briefly be ahead of the copy on the website. Absence is a reason to be careful, not a proof of fraud.

What the letter has to contain, and how to read it as a checklist

California does not leave the format to the company's marketing department. The notice "shall be written in plain language, shall be titled 'Notice of Data Breach,'" and must present its information "under the following headings: 'What Happened?' 'What Information Was Involved?' 'What We Are Doing,' 'What You Can Do,' and 'For More Information.'" The statute even sets a floor on the typography: the text "shall be no smaller than 10-point type," and the format "shall be designed to call attention to the nature and significance of the information it contains."

The required contents are a useful checklist because they tell you what you are entitled to know. The letter must give the name and contact details of the business sending it. It must give "a list of the types of personal information that were or are reasonably believed to have been the subject of a breach." It must give, where the company can determine it, the date of the breach, an estimated date, or the range of dates it happened within — and, separately, "the notification shall also include the date of the notice." It must say whether notification was delayed because of a law enforcement investigation. And it must give a general description of the incident.

There is one more requirement that matters enormously and gets skimmed: if the breach exposed a Social Security number, a driver's licence number or a California identification card number, the notice must include "the toll-free telephone numbers and addresses of the major credit reporting agencies." If your letter carries that block, the sender has effectively told you which branch of this article you are on before you have finished reading it.

Use all of that as a tell. A one-paragraph email with no headings, no data list and no dates is not a California breach notice. It may be a legitimate courtesy message from a company that was not legally required to notify you — or it may be somebody testing whether you will click. Either way it is not the document, and the document is what you should be reading.

The thirty-day clock is new this year, and it will still feel slow

This changed on 1 January 2026 and almost nobody outside compliance departments noticed. Until then, California required notice "in the most expedient time possible and without unreasonable delay" — a standard with no number in it. Senate Bill 446, chaptered as Stats. 2025, Ch. 319, replaced that with a deadline: "the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach." The same bill put the fifteen-calendar-day clock on the filing with the Attorney General.

Before you start counting backwards from the date on your envelope, read the next subparagraph, because it is doing a great deal of work. A business may still delay "to accommodate the legitimate needs of law enforcement... or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system." Working out exactly whose records were in a stolen database is genuinely slow, and it is an explicitly permitted reason to take longer.

So the honest expectation is this. The thirty days runs from discovery, not from the break-in, and the exception is wide. It is entirely normal for the breach date printed on your letter to be six months, a year or more before the date of the letter itself. That gap is not evidence that anyone broke the law, and chasing it is not a good use of your afternoon.

What the gap does tell you is something practical: the information has been out of the company's control for that entire period. Any advice framed as "watch carefully over the next few weeks" is answering the wrong question. Whatever was going to be sold, was sold, months ago. That is an argument for a measure that does not expire — which brings us to the sort.

The only sort that matters: what can be re-issued and what cannot

Go to the "What Information Was Involved?" heading and split the list into two piles. This one decision drives everything else, and it is the step most people skip because the letter itself rarely draws the line.

The first pile is credentials and account numbers — the things that can be replaced. The statute's own definition includes "a username or email address, in combination with a password or security question and answer that would permit access to an online account," and "account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account." If that is what was taken, the answer is rotation. Change the password, change it anywhere you reused it, turn on two-factor authentication, and ask the bank to reissue the card. It is work, but it has an end.

The second pile is identity material, and it is a different problem because you cannot reissue yourself. California's list runs to Social Security numbers, "driver's license number, California identification card number, tax identification number, passport number, military identification number," medical information, "health insurance information," and "unique biometric data generated from measurements or technical analysis of human body characteristics, such as a fingerprint, retina, or iris image, used to authenticate a specific individual."

Nothing in that second list can be rotated. Your date of birth is not going to change, and the Social Security Administration does not issue new numbers on request as a matter of routine. Changing your password does nothing about it. The thing that actually helps is to make the number useless to a stranger, and that is what a credit freeze does.

One small, strange, genuinely useful detail sits in the same statute, for anyone whose letter mentions fingerprints or face data. A notice involving biometric data may include "instructions on how to notify other entities that used the same type of biometric data as an authenticator to no longer rely on data for authentication purposes." Read that slowly: the remedy the legislature could think of for a stolen fingerprint is to tell everyone to stop accepting fingerprints. That is the whole reason the second pile is treated differently from the first.

A freeze and a fraud alert are different tools, and people mix them up

These two get used interchangeably in conversation and they do different jobs. The Federal Trade Commission publishes both in plain terms, and the differences are mechanical rather than a matter of judgement.

A credit freeze is the strong one. "When a credit freeze is in place, nobody can open a new credit account in your name," and the FTC is careful to add the catch in the same breath: "nobody can open a new credit account in your name, including you." It costs nothing — "There's no cost to place or lift a credit freeze, and it doesn't affect your credit score" — and it does not run out: "A credit freeze lasts until you lift it." You do not have to be a victim of anything to place one. In the FTC's words, "Anyone can freeze their credit report, for any reason, even if their identity hasn't been stolen."

The part that decides your afternoon: to place a freeze you have to "contact all three nationwide credit bureaus — Equifax, Experian, and TransUnion." Three separate processes, three separate times. Nobody does it on your behalf.

A fraud alert is the lighter one and works the opposite way round administratively. It "tells businesses to check with you before opening a new credit account in your name," but, "unlike a credit freeze, a fraud alert doesn't prevent businesses from seeing your credit report." The convenience is in the plumbing: "You don't have to contact all three. The credit bureau you contact must tell the other two." An initial fraud alert lasts one year and can be renewed, and placing one also entitles you to a free credit report from each of the three bureaus. An extended alert lasts seven years but requires you to have completed an FTC identity theft report first. There is a separate version for active duty servicemembers.

Our practical read for a household that has just received one of these letters and has the second pile of data in it: place the freeze, because it is free, permanent until you say otherwise, and does not depend on anybody remembering to act on a flag. If you want the belt-and-braces version, the FTC notes you can place a fraud alert as well even with a freeze already in place.

Two more things worth knowing. Freezing does not cancel your existing cards or stop you using credit you already have — it blocks new accounts being opened. And when you do need to borrow, the FTC's advice avoids the usual mistake of unfreezing everything: "identify which bureau a lender will use to check your credit and just lift the freeze at that one bureau, and then put the freeze back in place once the need for a credit check passes."

If the breach involved a child's records — a school district, a paediatric practice, a benefits administrator — the FTC says a child under 16 can have a free freeze too, that it "stays in place until you tell the credit bureaus to remove it," and that "the process for getting a freeze for a minor is different than getting one for an adult." Start at the bureaus' own pages for minors rather than the ordinary adult flow.

The bit we actually get called about: a freeze is three accounts now, not three PINs

Here is the advice that has quietly gone stale everywhere else, and it is the part of this job that is genuinely ours rather than a lawyer's or a bank's.

The old version of a credit freeze involved a PIN. Each bureau mailed you a number, you put the letter in a drawer, and years later you needed it to lift the freeze and could not find it. A great deal of published advice still tells you to write those three PINs down.

That is not how it works now. Experian's own page states it flatly: "You no longer need a PIN to manage your credit freeze with Experian. All you need is a free Experian account to manage your freeze." Equifax likewise documents managing the freeze online with a username and password after creating an account, adding that "placing, temporarily lifting, or removing a security freeze is free," with a phone route as the alternative.

So what you are really creating, when you follow the standard advice, is three new online accounts at three companies whose entire business is holding data about you. Each one has a password, a recovery email address and probably a second factor. And the moment you will next need all three is predictable and awful: you are at a dealership, or in the middle of a mortgage application, or signing up for a phone line, and something has to be lifted in the next ten minutes.

That is the failure we get called about, and it is a plain technology problem rather than a financial one. So do the setup properly on the day you place the freeze, while you are already sitting there. Put all three sets of credentials in a password manager rather than in a drawer or a phone note. Use an email address you will still control in five years, not a work address. Point the second factor at an authenticator app rather than a phone number you might change, and save the recovery codes in the same password manager. Write one line in the notes field of each entry saying which bureau it is and when you placed the freeze.

And treat those three logins as high-value in their own right. An account that can lift a freeze on your credit file is worth attacking, and it is protected by exactly the same password you used everywhere else if you let it be.

Your credit reports are free every week, from exactly one place

The other thing to do with the letter is look at what is actually on your credit file, and the sensible cadence for that is not "obsessively" — it is once now, and then at intervals.

The FTC's position is unambiguous and saves you a subscription: "All three nationwide credit bureaus have permanently extended a program that lets you check your credit report from each once a week for free at annualcreditreport.com. In addition, federal law requires each nationwide credit bureau to give you a free copy of your credit report once every 12 months if you ask for it."

It also tells you where to go, and where not to: "Don't contact the three credit bureaus individually. These are the only ways to order your free annual credit reports" — the annualcreditreport.com site, the toll-free line 1-877-322-8228, where a request "will be processed and mailed to you within 15 days," or by post. Search engines are full of lookalike sites with similar names that want a card number for a trial. Type the address rather than clicking an advertisement for it.

One more entitlement most people never use: if you are turned down for credit, employment, insurance or housing because of something in your report, that adverse action notice comes with a free report from the bureau involved — but "you must ask for your report within 60 days of getting the notice." If a breach did lead to something, that is often how you find out.

What you are looking for on the report is simple: accounts you do not recognise, and enquiries from lenders you never approached. Not your score. The score is not the point here and watching it drift is a distraction.

The free monitoring in the envelope: take it, but know what it is

Most of these letters offer a year of credit monitoring or identity protection, and that is not corporate generosity — it is in the statute. Where the company sending the notice was itself the source of the breach, and the exposed data included the identity-material category, California requires "an offer to provide appropriate identity theft prevention and mitigation services... at no cost to the affected individual for not less than 12 months."

Take it if it is free. But be clear about what it is. Monitoring is detection: it tells you after somebody has used your details. A freeze is prevention: it stops the account being opened in the first place. Signing up for the monitoring instead of placing the freeze is the common and expensive mistake, because the monitoring is the thing being pushed at you and the freeze is the thing nobody is paid to sell.

Three practical notes. First, the enrolment period runs from a date the company chose, so put a calendar reminder a month before it lapses; the usual pattern is that it rolls into a paid subscription unless you cancel. Second, the enrolment page is an obvious target — reach it through the address printed in the letter you have verified against the state register, not through a link in an email that arrived separately. Third, if the offer requires you to hand over the full Social Security number on a web form, stop and confirm you are on the right site, because this is precisely the moment people are most willing to type it.

The second wave is the one that costs people money

This is the real risk in the whole sequence, and it is a timing problem rather than a technical one. Everybody affected has just been told, officially, to expect contact about a security incident. That is an extraordinarily good pretext, and it does not require the caller to know anything about you except that you got a letter — which, since the register is public, is not a secret.

So the rule for the next few months is the boring one: do not act on anything inbound. Not the email that says your monitoring enrolment failed. Not the text about confirming your claim. Not the call from someone who already knows your address and the name of the breached company, because both of those are in the letter and often in the press.

The specific things a legitimate sender will not do: ask you to confirm your Social Security number, your date of birth or your card details on an inbound call; ask for a freeze PIN or the login to your bureau account; ask you to download remote access software so they can "secure your device"; ask for payment of any kind; or press you to do it now. Urgency is the product.

There is a second-order version that turns up a few months later and catches people who have already been stung once: a caller offering to recover your losses, or to sue the company on your behalf for a fee. If money has actually gone, the free routes are the right ones, and we have written separately about why the recovery offer is itself the follow-up scam.

And if you are simply not sure whether a call is real, the answer is the same as the first section of this article. Hang up. Search the register. Go to the company by a route you chose. Nothing legitimate is lost by a twenty-minute delay.

If something has already happened, the order matters

If there are accounts on your credit report you did not open, or a tax refund that was already claimed, or a card you never applied for, the situation is different and the sequence changes.

Report it at IdentityTheft.gov, which is the FTC's own reporting and recovery site. It produces a personalised recovery plan and, importantly, the FTC identity theft report — the document required for the seven-year extended fraud alert and asked for by banks and creditors when you dispute accounts you never opened. Doing that first means everything afterwards has paperwork behind it.

Then the freeze, if it is not already in place. Then the disputes with the individual lenders, with the report number to hand. Then a police report if a creditor or your bank asks for one specifically.

What not to do: pay a credit repair company. Everything in the paragraph above is free, and the fee-charging version of it is a business built on people not knowing that.

If the letter arrived at a business

Small businesses get these letters too, and the shape of the problem is different. The breach is usually at a supplier — the payroll bureau, the benefits administrator, the practice management system, the online store platform — which means two separate exposures arrive in one envelope.

The first is your staff's personal data, held by someone you chose on their behalf. That is an employment conversation as much as a technical one: tell people plainly what the supplier said, point them at the freeze and the free weekly reports, and do not let the notice sit in an inbox for a fortnight because nobody wanted to raise it.

The second is your own account at that supplier, and this is the part that gets forgotten. If the platform was compromised, the credentials your business used on it are suspect. Rotate that password, rotate it anywhere it was reused, turn on two-factor authentication on the supplier portal, and check the account for changes made while you were not looking — new users, changed notification addresses, altered bank details for payments. A changed direct deposit or remittance address is the classic follow-through, and it usually happens quietly, weeks later.

One more thing for sole traders and single-member companies: a tax identification number is on California's list of protected identifiers, and for a sole proprietor that number is very often the Social Security number. A letter that looks like it is only about your business may be about you personally.

What we do with this, and what is not ours to do

The boundary first, because it is a crowded field full of people selling things. We are not lawyers and this is not legal advice. We do not sell credit monitoring, identity protection or credit repair, and we take nothing from anyone who does. Whether to join a class action, and whether your particular letter creates any claim, is a question for a solicitor and not for us.

What we do is the technology half, which is where these letters actually become work. Setting up the password manager and the authenticator so the three bureau logins, the recovery email and the codes still exist in five years when you need to lift a freeze in a hurry. Rotating the credentials that were in the first pile, properly, including the places the same password was reused. Checking the email account behind everything else for forwarding rules and app passwords somebody may have left there. Turning two-factor on for the bank and the email before anything else. Looking at the actual machine if the letter arrived alongside something odd on the computer. And, plainly, telling you when the answer is that there is nothing to do.

We work with households and small businesses across Southern California — the San Gabriel Valley, Orange County, the Inland Empire, the Coachella Valley, Ventura County and the coast. If you are holding one of these letters and are not sure whether it is real, bring it in or read us the name at the top of it. Checking it against the state register takes about two minutes, and it is a better first move than anything the letter asks you to do.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →