Phone Stolen? Do This in the First Hour to Protect Your Data

What to do when your phone is stolen: lock it, suspend the SIM, reset passwords, and file a report — all within the critical first hour.

My phone buzzed with a low-battery alert on a crowded platform, and thirty seconds later it was gone from my pocket. If your phone is stolen, the first hour determines whether this becomes an inconvenience or an identity-theft mess.

The single biggest mistake is treating a stolen phone as a hardware problem when it’s actually an account-access problem — every app still logged in is a door standing open.

Quick Answer

If your phone is stolen, act within the first hour: use Find My iPhone or Find My Device to lock and locate it, remotely erase if recovery looks unlikely, call your carrier to suspend the SIM, change passwords on your email and banking apps, and file a police report with the phone’s IMEI number.

What Should You Do in the First Five Minutes?

Use a second device — a laptop, a tablet, or a friend’s phone — to start the recovery chain immediately. Every minute a stolen phone stays unlocked is a minute someone can dig through your mail app or saved logins.

Log In to Find My iPhone or Find My Device

On an iPhone, go to icloud.com/find and sign in with your Apple ID. On Android, go to android.com/find. Both show the last known location and let you play a sound, lock it, or erase it. If this isn’t set up yet, see Set Up Find My iPhone Before You Actually Need It or Set Up Google Find My Device — it only works if enabled beforehand.

Put the Phone in Lost Mode First

Lost Mode locks the screen, shows a callback number, and suspends Apple Pay or Google Pay automatically. Don’t erase yet — Lost Mode still tracks the phone, while a remote wipe kills the GPS signal for good.

Triggering Lost Mode or lock right away closes off payment apps and the lock screen before anyone can dig further.

How Do You Lock Down Your Accounts Remotely?

A locked phone can still be a risk if a thief pulls the SIM or a notification preview leaks a one-time code on the lock screen. Treat this as an account lockdown, not just a device lockdown.

Sign Out of Active Sessions

From a browser, open your Google Account’s “Manage devices” page or Apple ID’s device list and remove the stolen phone from every signed-in session. This cuts off Gmail, Photos, or iMessage access even if someone bypasses the lock screen later.

Change Passwords That Matter Most

Start with email, since it’s the recovery path for everything else, then banking apps. If two-factor codes lived on that phone, set up backup codes on a new device — see Two-Factor Authentication Setup for Your Most Important Accounts.

Removing the device from active sessions and rotating key passwords closes the gap a lock screen alone can’t cover.

How Do You Stop the Thief From Using Your SIM or Card Details?

A phone number is a recovery key for half the internet, and a stored payment card is cash in someone else’s pocket. Both need a phone call, not an app tap.

Call Your Carrier to Suspend the SIM

Every major US carrier can suspend service within minutes by phone, blocking calls, texts, and data even if the thief swaps SIM trays. Ask them to also block the device by IMEI number, which carriers share in a blocklist so the phone can’t be reactivated elsewhere.

Carrier Stolen-Phone Line Blocks IMEI?
AT&T Suspend via My AT&T app or call support Yes
T-Mobile Call customer care to suspend line Yes
Verizon Suspend from My Verizon or by phone Yes

Remove Saved Cards From Wallet Apps

Lost Mode suspends Apple Pay and Google Pay cards on that device, but log into your bank’s app separately and freeze or reissue any card stored for tap-to-pay. My bank’s fraud line answered faster than the carrier’s, so call both at once.

A carrier suspension and a wallet-app freeze cover the two ways a stolen phone can quietly spend your money.

Should You File a Police Report and Insurance Claim?

A police report won’t get your phone back, but it creates a paper trail your insurer will ask for and registers the IMEI as stolen.

File the Report With Your IMEI Number

Find the IMEI in your phone’s original box, carrier account, or Find My device details before it goes offline. Include the report number on any insurance claim.

Freeze Your Credit as a Backstop

If the phone had banking apps or autofilled details, a credit freeze with the major bureaus costs nothing and blocks new accounts from opening in your name.

Filing a report with the IMEI and freezing credit protects you even after the phone itself is unrecoverable.

Common Mistakes to Avoid

Waiting to See If the Phone “Turns Up”

Every hour of delay gives someone more time to try lock-screen bypasses. Fix: start the lock and lockdown steps immediately, even if you think it was just misplaced.

Erasing Before Trying to Locate It

A remote wipe is permanent and kills location tracking. Fix: use Lost Mode or lock first, and only erase once you’ve accepted the phone is gone.

Forgetting the SIM Card

Locking the software doesn’t stop someone from moving your SIM to another phone. Fix: call your carrier to suspend the line separately from any app-based lock.

Skipping the Password Reset

Email apps and autofill data are usually still logged in. Fix: reset your email password first, since it unlocks recovery for everything else.

Not Saving the IMEI in Advance

Digging for your IMEI after the phone is gone means checking old receipts under pressure. Fix: write it down or screenshot it now, before you need it.

Frequently Asked Questions

Can a stolen phone be tracked if it’s turned off?

No, Find My needs power and a network or Bluetooth connection. The last known location before it powered off still shows, which is what I’ve used to point police to a specific block.

Will locking my phone stop someone from factory resetting it?

On modern iPhones and Android phones, Activation Lock or Factory Reset Protection ties the device to your account, so a reset without your credentials leaves it unusable.

Should I change my Apple ID or Google account password too?

Yes, especially without a strong passcode. I rotate the account password even after a successful remote lock, since a saved password manager entry on the device could still be exposed.

Does phone insurance cover theft the same as damage?

Most carrier insurance plans cover theft but require the police report number and proof you filed within a set window, often 24 to 48 hours. Check your plan’s deadline right after filing.

What if my two-factor codes were only on that phone?

Use backup codes saved during setup, or your provider’s identity verification flow, then move authentication to a new device right away.

Conclusion

A stolen phone is recoverable in the way that matters most — your accounts and identity — if you lock, suspend, and reset passwords within the first hour. Start with identitytheft.gov if data was exposed, and run this data breach checkup once passwords are reset.

Social Media Privacy Checkup: Lock Down Every Account in 20 Minutes

Run a social media privacy checkup in 20 minutes: lock down post visibility, revoke old connected apps, kill location tags, and turn on two-factor login.

I assumed my social media accounts were locked down because I’d set them to private years ago and never touched the settings again. Then I ran a full social media privacy checkup on my own Facebook and Instagram accounts and found 47 forgotten apps still authorized since 2019, two old sessions logged in from cities I’ve never visited, and a public location tag on a photo from my kid’s school.

The real risk isn’t one leaked password — it’s the years of accumulated app permissions, forgotten sessions, and public tags that quietly pile up while you’re not looking.

Quick Answer

A social media privacy checkup means reviewing who can see your posts, revoking old connected apps, turning off precise location tagging, and enabling two-factor authentication on every account you use. Spend about 20 minutes total, start with Facebook and Instagram, and you close the biggest exposure gaps that scammers and stalkers actually exploit.

What Does a Social Media Privacy Checkup Actually Cover?

A privacy checkup isn’t one toggle. It touches four layers: post audience, third-party app access, location and tag exposure, and login protection. Skip one layer and the other three don’t matter much.

I run mine every six months alongside my Google Security Checkup, since both catch stale connected apps and old sessions.

Treat a privacy checkup as four separate layers, not one setting, or you’ll miss the gap that actually gets exploited.

How Do You Lock Down Facebook Privacy Settings?

Audience and Visibility Settings

Open Settings & Privacy > Settings > Audience and Visibility. Set “Who can see your future posts” to Friends, not Public, and run the “Limit Past Posts” tool to retroactively hide old public updates.

Timeline and Tagging Review

Under Profile and Tagging, turn on “Review posts you’re tagged in before they appear on your timeline.” This is the one setting most people skip, and it’s what let a stranger’s tagged photo of me sit in search results for months.

Pro tip: Facebook’s “Off-Facebook Activity” page, under Settings, lists every site and app that reported activity back to Facebook. Clear it and disconnect future tracking in one click.

Facebook’s audience and tagging settings decide whether a stranger can find you through someone else’s post, not just your own.

How Do You Lock Down Instagram and TikTok Privacy?

Instagram Privacy Basics

Switch your account to Private under Settings > Account Privacy, then check Settings > Story and turn off “Allow Sharing” so screenshots and replays don’t spread past your followers.

TikTok Privacy Basics

Go to Settings and Privacy > Privacy > Discoverability, set the account to Private, and turn off “Suggest your account to others.” TikTok defaults new accounts more openly than most people expect, so verify this even on an account you set up years ago.

Instagram and TikTok both bury the settings that stop your content from being screenshotted or recommended to strangers.

What Should You Check on X and LinkedIn?

Both default to public visibility, making them the easiest place to overshare. Here’s where each platform stands by default.

Platform Default Post Visibility Where to Change It Biggest Risk If Ignored
Facebook Public (new accounts) Settings & Privacy > Audience Old public posts stay searchable
Instagram Public Settings > Account Privacy Strangers can DM and screenshot stories
TikTok Public Privacy > Discoverability Videos get recommended to strangers
X (Twitter) Public Settings > Privacy and Safety Location and tagging exposed by default
LinkedIn Public Settings & Privacy > Visibility Connections list fully exposed

On X, go to Settings and Privacy > Privacy and Safety and turn off photo tagging and precise location. On LinkedIn, turn off “Profile viewing options” under Visibility so you browse anonymously, and hide your connections list.

X and LinkedIn both leak location and network data by default, so check them even if you post there rarely.

How Do You Stop Location Sharing and Tag Exposure?

Turn off precise location for each app in your phone’s system settings, not just inside the app: iPhone is Settings > Privacy & Security > Location Services; Android is Settings > Location > App Permissions.

Also disable “Nearby Friends” style features you enabled once and forgot, since they broadcast your live location.

Troubleshooting tip: if a photo still shows a location tag after disabling Location Services, the tag was likely added manually at posting time. Edit or delete that old post directly; the system setting only affects future uploads.

Turning off location in the app isn’t enough — check your phone’s system-level permission too, and clean up old tags manually.

How Do You Audit Connected Apps and Old Logins?

Every platform hides a list of third-party apps and active sessions.

Facebook and Instagram

Go to Settings > Apps and Websites (or Accounts Center > Connected Experiences) and revoke anything unused in the last year.

Active Sessions

Under Security and Login, review “Where You’re Logged In” and log out of any device or city you don’t recognize.

While you’re there, add a passkey or app-based two-factor authentication instead of SMS codes, the exact weakness SIM swapping attacks target. A free manager like the one in my Bitwarden setup guide removes the password risk entirely, and the Electronic Frontier Foundation keeps a solid account-security reference worth bookmarking.

Old connected apps and forgotten sessions are the quiet backdoor most people never think to close.

Common Mistakes to Avoid

  • Checking the app but not the phone’s location permission. Fix: review both; the app setting doesn’t override system-level access.
  • Assuming “Private” hides old public posts. Fix: run “Limit Past Posts” or delete old public updates manually.
  • Relying on SMS codes for two-factor authentication. Fix: switch to an authenticator app or passkey where supported.
  • Never revisiting connected third-party apps. Fix: set a six-month reminder to review and revoke unused access.
  • Ignoring tagging settings on other people’s posts. Fix: turn on tag review so nothing posts without your approval.

Frequently Asked Questions

How long does a full social media privacy checkup take?
About 20 minutes covering Facebook, Instagram, and one more platform you actually use. My own run took 24 minutes, including revoking nine old connected apps.

Do I need to do this on every platform I have an account on?
Focus first on platforms tied to your real name. I ignored an old MySpace-era account for years until a breach notice reminded me it still held my birthdate.

Will making my account private hurt my reach or followers?
Yes, it limits discovery, which matters if you’re building a public profile. For a personal account, that tradeoff is worth it.

Can someone find my old public posts after I go private?
Possibly, if they were indexed or screenshotted first. Run “Limit Past Posts” and search your own name to check.

What’s the single most important setting to fix first?
Two-factor authentication on your login. I’d rather a stranger see one old photo than lose the whole account to a password leak.

Conclusion

A social media privacy checkup takes less time than one scroll through your feed, and it closes the gaps that get exploited: stale app access, forgotten sessions, default public settings. Block 20 minutes this week, start with Facebook, and work down this list one platform at a time.

SIM Swapping Attacks: How Scammers Hijack Your Phone Number

SIM swapping lets scammers hijack your phone number and drain accounts. Learn the warning signs and how a carrier PIN stops it cold.

I got a call from my carrier’s fraud team at 11 p.m. asking why I’d just requested a new SIM in a city I’d never visited. I hadn’t. Someone had gathered enough of my details to convince a support rep to move my number onto their SIM, and for twenty minutes it belonged to a stranger.

That’s a sim swapping attack, and it can drain your bank account without a single click. The crux: your phone number is not a secure credential, it’s account metadata a call center employee can reassign in minutes — and every SMS login you rely on inherits that weakness.

Quick Answer

A SIM swap happens when a scammer tricks your carrier into porting your number to a SIM they control, using stolen personal data. Once they have it, they intercept SMS codes and reset your accounts. Stop it with a carrier PIN, a port-out lock, and app-based two-factor authentication instead of SMS.

What Is a SIM Swapping Attack?

A SIM swap is account takeover where an attacker impersonates you to your carrier. They call support with a name, billing address, and the last four of your social security number pulled from an old breach, and request a new SIM or a port to another carrier.

Once approved, your real SIM goes dead. Calls and texts meant for you route to the attacker instead. They use “forgot password” on your bank and email, intercept the SMS code, and lock you out while they clean you out.

A SIM swap is identity theft aimed at your phone number so an attacker can pass as you during account recovery.

How Do Attackers Steal Your Number?

Every swap I’ve read about or heard from readers follows the same rough sequence.

Collecting Your Details

Attackers buy or scrape data from breaches, phishing pages, or social media (birthday, mother’s maiden name). Sites like Have I Been Pwned show how often your email appears in a breach dump.

Contacting Your Carrier

Posing as you, they call or use chat, claim a “lost phone,” and request a SIM replacement or port. Weak carrier verification is why this works.

Losing Signal, Then Your Accounts

The tell to remember: your phone suddenly shows “No Service” with no explanation. That’s not a network hiccup — it’s evidence a swap is underway. Minutes later, attackers trigger resets on email and banking using your intercepted codes.

Watch for a sudden, unexplained loss of signal followed by unexpected account-lockout emails.

How Do I Stop a SIM Swap Before It Happens?

I treat this as a five-minute setup task, because the fix is cheap and the damage is not.

Set a Carrier Account PIN

Every major US carrier lets you add a separate PIN required for account changes, including SIM swaps and ports. This differs from your phone’s lock screen PIN — find it under “account security” in your carrier account.

Enable a Port-Out Freeze

Ask your carrier for a port freeze, which blocks any transfer to another carrier until you personally remove it — this stops the most damaging version of the attack.

Move Off SMS for Two-Factor Codes

Swap SMS-based two-factor authentication for an authenticator app or a passkey wherever supported. I moved my email and banking off SMS; if you haven’t set up 2FA yet, I cover the steps in my two-factor authentication setup guide.

Use a Password Manager

A SIM swap is less useful to an attacker if your accounts don’t share a password an old breach already exposed. I run everything through Bitwarden; here’s how I set it up for free, plus my notes on passwords you can remember.

Pro tip: Ask your carrier specifically for a “SIM swap PIN” or “number transfer PIN” — some reps default to describing your voicemail PIN, which does nothing to stop a swap.

Locking down carrier access and moving off SMS codes closes the two doors attackers rely on most.

What Should I Do if My SIM Was Already Swapped?

If your phone loses service unexpectedly and you didn’t request a change, treat it as an active incident.

Call Your Carrier From Another Phone

Use a friend’s phone or web chat to report the swap and request an immediate reversal, and ask them to lock the account.

Secure Your Email First

Email is the recovery key to everything else. Change its password from a trusted device and revoke active sessions. My post-breach identity checklist covers the same triage.

Check Bank and Crypto Accounts

Log in from a secure device, review recent transactions, and call your bank’s fraud line if anything looks off — banks reverse fraudulent transfers faster within the first 24 hours.

Troubleshooting tip: If your carrier app also needs SMS verification to log in, go to a physical store with photo ID — reps there restored my service and added a security PIN in about fifteen minutes.

Reclaiming your number and email within the first hour usually stops the damage before it spreads to financial accounts.

Which Two-Factor Method Is SIM-Swap Resistant?

Method SIM-Swap Resistant? Setup Effort Best For
SMS text codes No None (default) Accounts with no other option
Authenticator app Yes Low, 5 minutes Most personal accounts
Passkey Yes Low, 90 seconds Sites that support it
Hardware security key Yes Medium, one-time buy Email, banking, crypto

Anything that doesn’t touch your phone number is inherently safe from a SIM swap.

Common Mistakes to Avoid

Relying on SMS for Sensitive Accounts

Fix: switch email, banking, and crypto logins to an authenticator app or passkey first.

Skipping the Carrier PIN

Fix: set it anyway — your screen lock PIN protects the device, not your carrier support account.

Posting Personal Details Publicly

Fix: lock down birthday and family names on social profiles, since attackers use these to pass security questions.

Ignoring a Sudden “No Service” Message

Fix: treat it as urgent and call your carrier from another device.

Frequently Asked Questions

Can a SIM swap happen without me noticing?

No — the clearest sign is a sudden total loss of signal. My phone dropped to “SOS only” mid-evening with no reported outage, which tipped me off immediately.

Does a SIM swap require physical access to my phone?

No, the attacker never touches your device. They only need enough data to convince your carrier’s support team to reassign your number.

Will a new phone number stop future attempts?

Not by itself — the attacker’s real advantage is the data they’ve collected. A carrier PIN and app-based 2FA protect you regardless of your number.

Is eSIM safer than a physical SIM card?

Roughly the same risk — the vulnerability is the carrier’s verification process, not the SIM’s physical form. I still add a port-out lock on eSIM lines.

Can a password manager alone prevent a SIM swap?

No, it stops password reuse but not the carrier verification hole a SIM swap exploits. Pair it with a carrier PIN and app-based 2FA.

Conclusion

A SIM swap works because your phone number was never designed as a security credential, yet nearly every account treats it like one. Set a carrier PIN, add a port-out freeze, and move your two-factor codes to an authenticator app or passkey today.

How to Protect Your Identity Online After a Data Breach

Protect your identity online after a data breach with this step-by-step plan: freeze your credit, change reused passwords, enable 2FA, and monitor your accounts for 90 days.

Finding out your email address or Social Security Number appeared in a data breach is a stomach-dropping moment — I checked Have I Been Pwned one evening and found three breaches I had never heard of, two of them years old. The impulse is to panic and freeze, but the calmer move is to work through a short, ordered checklist. The single most important thing I have learned: the steps you take in the first 48 hours determine whether a breach becomes a minor inconvenience or a months-long identity-theft ordeal.

When you want to protect your identity online after a breach, speed matters more than perfection. You do not need to do everything at once — you need the right actions in the right order.

Quick Answer

Change your password on the breached site immediately, then update every other account that reused that same password. If your SSN was exposed, place a free credit freeze at all three bureaus — it takes about 15 minutes total. Turn on two-factor authentication on email and banking. Monitor your credit reports weekly at AnnualCreditReport.com for 90 days.

Acting within 48 hours of discovering a breach dramatically reduces the chance that a fraudulent account or charge ever appears in your name.

What Did the Breach Actually Expose?

Not all breaches carry the same risk. Read the notification email carefully for terms like “government ID,” “financial information,” or “hashed passwords.” Then search your email at Have I Been Pwned — a free, authoritative service that lists every known breach linked to your address and exactly what data types were included.

Set your urgency level based on what was exposed:

  • Email address only: low risk — expect more spam, little else
  • Email + password (hashed or plain): medium risk — change that password everywhere you reused it
  • SSN + date of birth + address: high risk — treat it as an emergency and freeze credit the same day

Knowing exactly what leaked lets you match your response to the actual threat instead of either over-reacting or dangerously under-reacting.

How Do I Change My Passwords After a Breach?

  1. Navigate directly to the breached site — do not click links in the notification email. Phishers send convincing fakes designed to capture credentials on a spoofed page. Type the URL yourself and log in there.
  2. Find every account sharing the same password and update each one. A password manager surfaces all reused credentials instantly and generates unique replacements for you.
  3. Build each new password as a passphrase — four random words like “trumpet-cloud-fence-marble” are long, memorable, and crack-resistant. My full guide on creating strong passwords you can actually remember walks through the method in detail.

Pro tip: Bitwarden is free, open-source, and syncs across all your devices. When I imported my logins it immediately flagged 14 reused passwords I had forgotten about — that visibility alone is worth the 20-minute setup.

Changing only the breached site’s password while leaving identical credentials elsewhere is the most common post-breach mistake — treat every reused login as a live threat right now.

Should I Freeze My Credit After a Data Breach?

Yes — if your SSN, date of birth, or name and address were exposed, freeze your credit immediately. A credit freeze locks your file at each bureau so no new lender can open an account in your name, even if they have your SSN. It has zero effect on your existing accounts or credit score.

You must contact all three bureaus separately. Each one is free and takes about 5 minutes online. Save the PIN each bureau provides — you need it to lift the freeze later.

Bureau Online Freeze Phone
Equifax equifax.com/personal/credit-report-services 1-800-349-9960
Experian experian.com/freeze 1-888-397-3742
TransUnion transunion.com/credit-freeze 1-888-909-8872

Troubleshooting tip: If the online portal throws an error — Equifax’s site did this to me during a high-traffic event right after a major breach — call the phone number instead. Have your SSN and two years of address history ready before you dial.

A credit freeze is the closest thing to a pause button on identity theft — place it even if nothing suspicious has appeared yet.

How Do I Turn On Two-Factor Authentication Fast?

Two-factor authentication (2FA) requires a thief to have both your password and a one-time code — usually generated on your phone — to log in. Even a leaked password cannot get them in alone.

Which Accounts Need 2FA First?

  1. Email — your inbox is the master key to every other account’s password-reset flow
  2. Banking and investment accounts
  3. Cloud storage such as Google Drive, iCloud, or OneDrive
  4. Social media — especially if you use “Sign in with Google” or “Sign in with Facebook” on other sites

Use an authenticator app like Google Authenticator or Microsoft Authenticator rather than SMS codes, which can be hijacked through SIM-swap attacks. For the strongest protection, switch to passkeys where supported — they replace the password entirely with a fingerprint or face scan. I moved several accounts to passkeys recently and login became noticeably faster. My guide on what passkeys are and how to set them up walks through the process on major platforms.

Enabling 2FA on email and banking takes about ten minutes and blocks the vast majority of account-takeover attempts that follow a credential breach.

What Should I Monitor for the Next 90 Days?

Even with a credit freeze active, existing open accounts can still be drained. Check these weekly until you are confident the window has closed:

  • Bank and card statements: dispute anything unfamiliar, even $1.99 — thieves run small test charges before larger ones
  • Credit reports at AnnualCreditReport.com: look for any new account you did not open
  • Email inbox: unexpected “welcome” or password-reset messages signal account-takeover attempts on services you never signed up for

I set transaction alerts on all my bank accounts — a text for every charge over $0.01. That caught a fraudulent $9 streaming subscription within two hours of it posting.

Catching fraud early keeps it a small dispute rather than a months-long credit repair problem.

How Do I Report Identity Theft If It Actually Happens?

  1. File at IdentityTheft.gov — the FTC’s portal generates a personalized recovery plan and creates legal documentation for disputing fraudulent accounts, loans, or tax returns filed with your SSN.
  2. Call your bank or card issuer’s 24/7 fraud line. They can freeze affected cards and initiate chargebacks within one business day.
  3. File a police report for significant fraud — creditors and collection agencies typically require a case number to close disputed accounts or loans.

Reporting promptly and in writing creates the paper trail that turns overwhelming fraud into a disputable, resolvable process.

Common Mistakes to Avoid

  1. Changing only the breached site’s password. Every account reusing that credential is equally exposed. Fix: update all shared passwords before anything else.
  2. Waiting for fraud to appear before freezing credit. By then, a loan may already be open. Fix: freeze all three bureaus the same day you confirm SSN exposure.
  3. Clicking links in breach notification emails. Phishers mimic these perfectly. Fix: go directly to the official site and log in yourself.
  4. Ignoring charges under $2. Small test charges precede large fraud. Fix: dispute any unrecognized charge, no matter the size.

These four mistakes give attackers extra time and opportunity — avoiding them closes most of the damage window before it opens.

Frequently Asked Questions

How long does identity theft recovery usually take?
Most cases resolve within a few weeks when you report early and document everything. Cases involving fraudulent loans or tax returns can stretch 6–12 months. Starting at IdentityTheft.gov from day one shortens the timeline considerably.

Can I lift a credit freeze when I need to apply for a loan?
Yes — thawing takes under an hour online. Log in to each bureau, verify with your PIN, and temporarily suspend or fully remove the freeze. You can even set an end date so it re-locks automatically.

Does a credit freeze hurt my credit score?
Not at all. A freeze only blocks new creditors from pulling your file. Your existing score and open accounts are completely unaffected.

What if I cannot confirm whether my SSN was included in the breach?
Assume it was if the breached organization held employment, financial, or healthcare records. The 15-minute freeze is free, and the only downside of placing it unnecessarily is a PIN to keep track of.

Is credit monitoring a substitute for a credit freeze?
No — monitoring alerts you after a fraudulent account appears, while a freeze stops it from being created. Think of the freeze as the lock and monitoring as the alarm: you want both running together.

Conclusion

You cannot undo a breach, but you can stop most of the damage before it starts. To protect your identity online after a breach, freeze your credit, change every reused password, and enable two-factor authentication on your most critical accounts — all within 48 hours. Start with the credit freeze right now: it is free, it takes 15 minutes, and it closes the most dangerous window an attacker has to exploit your exposed data.