Home › Knowledgebase › KB-447

How to recognise and respond to a data breach notification from your service provider

Summary

This guide helps you troubleshoot and resolve: How to recognise and respond to a data breach notification from your service provider. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

When a service provider experiences a data breach, they are legally required under Australia's Notifiable Data Breaches scheme to notify affected customers. Receiving one of these notifications can be unsettling, but knowing how to verify the message, assess your risk, and respond quickly will help protect your business and personal information. This guide walks you through what to look for, what to do next, and how to strengthen your accounts against follow-on attacks.

Recognising a Legitimate Data Breach Notification

Cybercriminals often exploit real breach news by sending fake "notifications" designed to steal your credentials. Before acting on any message, confirm it is genuine.

What a real notification looks like

Common signs of a phishing impersonation

When in doubt, do not click any links in the email. Open a new browser tab, type the provider's website address manually, and check for a security notice in your account dashboard.

Assessing Your Exposure

Once you have confirmed the notification is genuine, work out what information may have been affected and where that information is reused.

Identify the data types involved

  1. Read the provider's breach notice carefully and note which categories of data were exposed (for example, names, email addresses, passwords, payment details, dates of birth).
  2. Check whether the breach included hashed or plaintext credentials. Plaintext exposure is far more serious.
  3. Determine whether any government identifiers (TFN, Medicare, driver's licence) were involved, as these require additional steps.

Map your reuse across other accounts

  1. List every account that uses the same email address or the same password as the breached service.
  2. Prioritise accounts that hold financial data, customer records, or admin access to business systems.
  3. Note any shared or service accounts that may have used the same credentials.
A password manager is the easiest way to audit credential reuse. It will show every site where a particular password is stored, so you can update them one by one.

Securing Your Accounts

Take these steps in order to contain the impact and prevent attackers from using the leaked information against you.

Step 1: Change passwords immediately

  1. Log in to the breached service directly through your browser.
  2. Go to AccountSecurityPassword and create a new, unique password of at least 14 characters.
  3. Use a password manager to generate and store it.
  4. Repeat the process for every other account that shared the same password.

Step 2: Enable multi-factor authentication

  1. In the same Security menu, turn on Multi-Factor Authentication or Two-Step Verification.
  2. Prefer an authenticator app (such as Microsoft Authenticator, Google Authenticator, or Authy) over SMS where possible.
  3. Save the recovery codes in your password manager or print and store them securely offline.
If you use Microsoft 365 or Google Workspace for your business, review the sign-in activity for unusual locations or devices after enabling MFA.

Step 3: Revoke active sessions and API tokens

  1. Look for Sign out of all devices or Revoke all sessions in the security settings.
  2. Regenerate any API keys, OAuth tokens, or app-specific passwords that were issued to integrations.
  3. Confirm that no new mailbox rules, forwarding rules, or OAuth app consents have been added since the breach.

Protecting Your Business Data

If the breached account is connected to your business, the response needs to extend beyond the single login.

Audit connected systems

Notify the right people

  1. Inform your internal team or IT contact so they can monitor for suspicious activity.
  2. If customer data was exposed, seek legal advice on your obligations under the Privacy Act and the Notifiable Data Breaches scheme.
  3. Document the incident, including dates, actions taken, and communications sent, for compliance and insurance purposes.

Monitoring for Ongoing Risk

Breached data often circulates for months after the initial incident. Ongoing vigilance is essential.

  1. Subscribe to a credential-monitoring service (such as Have I Been Pwned or your password manager's built-in dark-web watcher) for alerts involving your email domains.
  2. Set up transaction alerts on bank accounts and credit cards linked to the breached service.
  3. Consider a credit ban through Equifax, Experian, or Illion if government identifiers were exposed.
  4. Review your accounts monthly for the next six months and watch for password reset emails you did not request.

Preventing Future Impact

Reducing the blast radius of the next breach is largely about good hygiene today.

If you suspect any of your business accounts have already been accessed without authorisation, change passwords, revoke sessions, and open a ticket with our security team straight away.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket