By J. Mesa
On May 31, Live Nation told regulators that someone had accessed a database holding Ticketmaster customer data. A criminal group claims to hold records on 560 million customers. The data sat in a cloud environment hosted by Snowflake, and on June 10 the security firm Mandiant reported that about 165 Snowflake customers may have been exposed in the same campaign. The attackers used stolen logins on accounts that lacked multi-factor authentication. If you bought a concert ticket in the last few years, expect a letter. This guide tells you what to do with it.
What is a data breach notification letter?
A data breach notification letter is a notice a company must send when someone gains unauthorized access to your personal information. Every US state has a law that requires it. The letter usually states what happened, when, what types of information were involved, what the company is doing, and what it offers you.
How do I know the letter is real?
Scammers send fake breach notices to collect the very details a real breach exposes. Check before you act.
- Search for news of the breach and for a notice on the company’s official website.
- Many state attorneys general publish the breach notices filed with them.
- Do not call the phone number, scan the QR code, or tap the link in a notice you have doubts about. Find the company’s contact details yourself.
- A real notice does not ask you to confirm your Social Security number or pay a fee.
- To accept free credit monitoring, type the monitoring company’s web address yourself and enter the enrollment code from the letter.
What should I do first?
Read the letter for one fact: which types of your information were exposed. The right response depends on that list. Then work through the matching section below.
What if my password or login was exposed?
- Change the password on that account now.
- Change it on every other account where you used the same or a similar password. Criminals test stolen logins on other sites, an attack called credential stuffing.
- Turn on multi-factor authentication.
- Start using a password manager, so each account gets its own password.
What if my Social Security number was exposed?
- Freeze your credit at Equifax, Experian, and TransUnion. It is free and blocks new accounts in your name.
- Get an IRS Identity Protection PIN at IRS.gov to stop a false tax return.
- Create your own account at ssa.gov before someone else does.
- Accept the free credit monitoring the company offers.
- Check your credit reports at annualcreditreport.com.
You can’t change a Social Security number in any practical sense, so treat this exposure as permanent and keep the freeze in place.
What if my credit or debit card number was exposed?
- Review recent transactions and report anything you do not recognize.
- Ask the issuer for a new card number.
- Turn on alerts for every transaction.
- For a debit card, act faster. Fraud on a debit card takes money straight from your bank account, and your legal protection shrinks the longer you wait to report it.
- Update the new number with the services that bill you automatically.
What if my bank account number was exposed?
Call the bank. Ask about fraud monitoring on the account, and whether it recommends a new account number. Turn on alerts. Watch for small test withdrawals, which criminals use to check that an account works.
What if my driver’s license or passport number was exposed?
- Ask your state motor vehicle agency whether it will flag or reissue the license. Policies differ by state.
- Freeze your credit, since a license number helps a thief pass identity checks.
- For a passport, the State Department generally does not require a replacement when only the number is exposed. Watch for misuse and report it.
What if my medical or insurance information was exposed?
- Read every explanation of benefits statement from your insurer. Look for visits, prescriptions, or equipment you never received.
- Ask your insurer and your providers for copies of your records, and dispute entries that are not yours. Another person’s information in your chart can affect your care.
- Ask the insurer whether it will issue a new member number.
What if only my name, email, phone, or address was exposed?
This sounds minor, and it carries a real risk: targeted phishing. A criminal who knows you bought tickets, which hospital you used, or which bank you hold an account with can write a convincing message. For months after a breach, treat any email, text, or call about that company with suspicion. See our guides to phishing emails and scam texts.
Should I accept the free credit monitoring?
Yes. It costs you nothing and alerts you to new activity on your credit file. Enrolling does not usually waive your legal rights, though you should read the terms. Monitoring reports a problem after it happens. A credit freeze prevents the most damaging kind. Do both.
What should I not do?
- Do not ignore the letter.
- Do not pay anyone who offers to remove your data from the dark web. Nobody can.
- Do not respond to follow-up calls or texts that ask you to “verify” your information.
- Do not assume one breach is the end of it. The same data gets resold for years.
How do I check what has been exposed about me?
Search your email addresses at haveibeenpwned.com. The free service lists known breaches that included each address and can notify you of new ones. Many password managers and browsers also flag saved passwords that appear in breach data.
Can I sue, or join a class action?
Large breaches often lead to class action lawsuits and settlements. You will normally receive a separate notice by mail or email with a claim form and a deadline. Verify that notice the same way you verified the breach letter. Keep your breach letter and records of any time and money you spent responding, since settlements sometimes reimburse those losses.
What does this mean if I own a business?
Three things.
Your customers will get letters from you one day if you are unprepared. Every state requires notification, and the deadlines are short. Know what personal data you hold, where it lives, and which laws apply. Write an incident response plan before you need one.
The Snowflake cases carry a plain lesson. According to Mandiant, the attackers did not break Snowflake’s own systems. They signed in to customer accounts with usernames and passwords that information-stealing malware had captured from infected computers, some of them years earlier. The affected accounts had no multi-factor authentication. A stolen password should never be enough to reach your customer data.
- Require multi-factor authentication on every cloud service that holds business data.
- Change passwords after any malware infection, including infections on a contractor’s or an employee’s personal computer.
- Keep work logins off personal and shared home computers.
- Limit cloud access to known networks or managed devices where the service allows it.
- Ask your vendors the same questions.
Your employees are breach victims too. A staff member dealing with identity theft loses time and focus. Share this guide, and consider it part of your security awareness training.
Your next step
If you have a breach letter on the counter, read it tonight and list what was exposed. Then freeze your credit. If you own a business, list every cloud service that holds customer data and confirm each one requires multi-factor authentication. Cerberus Cybersecurity helps small businesses assess their data protection and write breach response plans. See our services or contact us.