How to recognise and respond to a data breach notification from your service provider
Summary
This guide helps you troubleshoot and resolve: How to recognise and respond to a data breach notification from your service provider. Follow the steps below to fix the issue.
Common Causes
When a service provider experiences a data breach, they are legally required under Australia's Notifiable Data Breaches scheme to notify affected customers. Receiving one of these notifications can be unsettling, but knowing how to verify the message, assess your risk, and respond quickly will help protect your business and personal information. This guide walks you through what to look for, what to do next, and how to strengthen your accounts against follow-on attacks.
Recognising a Legitimate Data Breach Notification
Cybercriminals often exploit real breach news by sending fake "notifications" designed to steal your credentials. Before acting on any message, confirm it is genuine.
What a real notification looks like
- It comes from an official domain you already have an account with (for example,
@companyname.com.au, not a lookalike such as@companyname-support.com). - It references a specific incident date, the type of data involved, and the regulator or statement page.
- It directs you to log in to your account through your normal browser, not by clicking an email link.
- It does not ask for your password, MFA code, or payment details.
Common signs of a phishing impersonation
- Urgent language such as "act within 24 hours or your account will be closed".
- Generic greetings like "Dear Customer" when the provider normally uses your name.
- Links that, when hovered, point to unfamiliar domains or shortened URLs.
- Attachments or QR codes that prompt you to "verify" your identity.
Assessing Your Exposure
Once you have confirmed the notification is genuine, work out what information may have been affected and where that information is reused.
Identify the data types involved
- Read the provider's breach notice carefully and note which categories of data were exposed (for example, names, email addresses, passwords, payment details, dates of birth).
- Check whether the breach included hashed or plaintext credentials. Plaintext exposure is far more serious.
- Determine whether any government identifiers (TFN, Medicare, driver's licence) were involved, as these require additional steps.
Map your reuse across other accounts
- List every account that uses the same email address or the same password as the breached service.
- Prioritise accounts that hold financial data, customer records, or admin access to business systems.
- Note any shared or service accounts that may have used the same credentials.
Securing Your Accounts
Take these steps in order to contain the impact and prevent attackers from using the leaked information against you.
Step 1: Change passwords immediately
- Log in to the breached service directly through your browser.
- Go to Account → Security → Password and create a new, unique password of at least 14 characters.
- Use a password manager to generate and store it.
- Repeat the process for every other account that shared the same password.
Step 2: Enable multi-factor authentication
- In the same Security menu, turn on Multi-Factor Authentication or Two-Step Verification.
- Prefer an authenticator app (such as Microsoft Authenticator, Google Authenticator, or Authy) over SMS where possible.
- Save the recovery codes in your password manager or print and store them securely offline.
Step 3: Revoke active sessions and API tokens
- Look for Sign out of all devices or Revoke all sessions in the security settings.
- Regenerate any API keys, OAuth tokens, or app-specific passwords that were issued to integrations.
- Confirm that no new mailbox rules, forwarding rules, or OAuth app consents have been added since the breach.
Protecting Your Business Data
If the breached account is connected to your business, the response needs to extend beyond the single login.
Audit connected systems
- Review any cloud storage, CRM, accounting, or ticketing systems that were linked to the compromised account.
- Check for unauthorised file changes, new admin users, or unfamiliar integrations.
- Export and review audit logs for the 30 days before the breach was disclosed.
Notify the right people
- Inform your internal team or IT contact so they can monitor for suspicious activity.
- If customer data was exposed, seek legal advice on your obligations under the Privacy Act and the Notifiable Data Breaches scheme.
- Document the incident, including dates, actions taken, and communications sent, for compliance and insurance purposes.
Monitoring for Ongoing Risk
Breached data often circulates for months after the initial incident. Ongoing vigilance is essential.
- Subscribe to a credential-monitoring service (such as Have I Been Pwned or your password manager's built-in dark-web watcher) for alerts involving your email domains.
- Set up transaction alerts on bank accounts and credit cards linked to the breached service.
- Consider a credit ban through Equifax, Experian, or Illion if government identifiers were exposed.
- Review your accounts monthly for the next six months and watch for password reset emails you did not request.
Preventing Future Impact
Reducing the blast radius of the next breach is largely about good hygiene today.
- Use a unique password for every account, stored in a reputable password manager.
- Turn on MFA on every service that supports it, especially email, banking, and cloud admin consoles.
- Limit third-party app connections and review them quarterly.
- Keep devices and operating systems up to date so leaked credentials cannot be paired with unpatched vulnerabilities.
Still Having Issues?
💻 Open a Ticket