Blog/Account security

Phishing That Follows a Data Breach

After a breach is announced, criminals send fake breach notices and targeted phishing that uses your real details. How to recognise it and how to respond to genuine breach emails safely.

CyberWatch AI30 September 2026 · 2 min read
A blue email envelope icon on a bright blue background

A big breach makes the news. Within days, inboxes fill with messages that look like follow-ups from the company: "Reset your password now", "Verify your identity to protect your account", "Claim your compensation". Some are genuine. Many are phishing, and they are more convincing than usual because criminals may hold your real details.

What breach phishing looks like

  • Urgent password resets leading to a fake login page.
  • "Verify your identity" requests asking for ID photos or card details.
  • Compensation or refund offers asking for bank details. See breach compensation offers.
  • Fake identity protection sign-ups that take payment.
  • Calls from "the fraud team" quoting your leaked details.
Illustrative example · Email after a breach
Subject: Action required: your account was affected Dear Alex Morgan, as part of our response to the recent incident, all affected customers must reset their password within 24 hours. Your account (ending 4471) will be suspended otherwise. Reset now: hxxps://account-security-reset[.]net
Red flags:
  • A deadline and a suspension threat.
  • A link to a domain that is not the company's.
  • Real details (your name, account ending) used to build trust.

How to respond safely

  1. Do not use links or numbers in breach-related messages.
  2. Open the company's app or type its website address and follow its official notice.
  3. Change passwords yourself through the normal settings page.
  4. Report phishing using your email's report option. In the UK, forward to report@phishing.gov.uk.

Judge the request, not the details. A message that knows your name, address or order history can still be a scam.

Reduce the impact

  • Unique passwords everywhere, so one leak cannot open other accounts.
  • Two-step verification on email and financial accounts.
  • Passkeys where available, which cannot be phished. See what is a passkey.

Received a breach-related email? Paste it into CyberWatch AI Scan for a free check.

For more, see what to do after a data breach in our identity and account security guide.

Frequently asked questions

Why does phishing increase after a breach?

Because people expect to hear from the company, and criminals may have real details from the leak to make messages convincing.

The email knows my order number. Is it real?

Not necessarily. Leaked data can include order and account details. Check through the company's app or website instead of the email.

What is the safest way to respond to any breach email?

Do not click. Go to the company's official website or app yourself and follow the steps it publishes there.

Sources

  1. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  2. Data breach guidance for individuals, UK National Cyber Security Centre
  3. Report a scam email, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.