# Quick summary
# What to do first: read the notice
- Contact information (name, phone, email, address) increases your risk of phishing and targeted scams.
- Financial data (credit card or bank account numbers) creates an immediate risk of monetary loss.
- Permanent identifiers (birthdate, social insurance number, passport, driver's licence) can enable identity creation and long-term fraud.
# Immediate account hygiene
Enable multi-factor authentication (MFA) where available. Biometric MFA or app-based authenticators are preferable to SMS when you have the choice.
# Credit checks and fraud alerts
Notify the credit agencies that your information may have been compromised and ask them to place a fraud alert on your file. A fraud alert makes it harder for someone to open new credit in your name without extra verification.
# Consider monitoring and protection services If the breach exposed sensitive identifiers (passport, driver's licence, SIN), consider identity monitoring or dark-web monitoring to detect whether your information is being circulated or sold. The article mentions Equifax Complete Protection as an option that bundles credit and dark-web monitoring with other tools such as a password manager and device protections.
# Watch for specific scams that follow breaches When contact information is leaked, expect an uptick in phishing attempts and fraud that reference the breached organization. Treat unsolicited calls, emails, and messages asking for more personal information or login credentials as suspicious.
# Real-world examples cited Recent breaches referenced include Loblaw (customer names, phone numbers, emails), Telus Digital (customer support records and financial data exposed by the hacker group ShinyHunters), and an exposed storage server at Duales that contained passport and driver's licence numbers for clients of a money-transfer app.
# Practical next steps checklist
- Read the breach notice and note exactly what was exposed.
- Change passwords on affected accounts and anywhere the same password was used.
- Turn on MFA for critical accounts.
- Pull your Equifax and TransUnion credit reports and review them regularly.
- Consider paid dark-web or identity-monitoring services if permanent identifiers were compromised.
- Be extra cautious of phishing and social-engineering attempts that reference the breached company.
# Bottom line You can't always stop data theft at the source, but timely, specific actions reduce the odds that stolen information will lead to financial loss or identity fraud. Start by understanding what was exposed, then focus on changing credentials, monitoring credit, and adding protective services when necessary.