Grahak Mitra

Your data was in a company's breach: what to do, calmly (India)

Last updated: 2026-07-11

If a company or service you use had a data breach and your details were exposed, don't panic — you can't un-leak data, but you can limit the damage. The first, most important move is to change your password on that service and anywhere you reused the same one, then turn on two-factor authentication, and stay alert to scam calls and messages that use your leaked details to sound convincing. This is a third-party leak — the company was breached, not necessarily your account — which is different from your own account being hacked. If a login of yours looks compromised right now, go straight to the account-recovery steps linked below.

Take a breath. A breach at a company is not your fault, and being in one doesn't mean money is already gone. It means some of your information is now in the wrong hands, so the job is to close the doors that information could open.

Breach vs. hacked account — which one is this?

These need different responses, so it's worth being clear which you're facing:

The two can overlap — a breach can lead to an account takeover if a leaked password still works. That is exactly why changing reused passwords comes first below.

After a breach — what to check and change, in order

  1. Change the password on the breached service to a new, unique one — don't reuse an old password or a small variation of it.
  2. Change it everywhere you reused that password. This is the big one. If the leaked password (or a close version) unlocks your email, bank, UPI, or shopping accounts, change each of those to its own unique password. Attackers try leaked passwords across many sites automatically.
  3. Turn on two-factor authentication on the important accounts — especially email, which can reset almost everything else. Then a leaked password alone is no longer enough to get in.
  4. Expect phishing that uses your leaked details. Scammers who buy breached data will call or message quoting real details about you — your name, what you bought, part of a card number — to sound credible. Do not act on an unsolicited "your account is at risk" call or message, however genuine it seems. Hang up and reach the organisation only through a number you find yourself, on your card or its official site.
  5. If payment-card data was in the breach, watch your card and bank statements closely for anything you don't recognise, and consider asking your bank for a replacement card. Report any transaction you didn't make to your bank at once.
  6. If a login of yours may be compromised now, don't wait — follow the account-specific recovery steps at think an account is compromised? first steps, and where to go next.
  7. Keep the notice and your notes. If the company told you about the breach, keep that message, and note the dates and what you changed. It's your record if anything follows.

If the breach leads to fraud

A breach on its own is a data problem. But if leaked details are then used against you — money leaves an account, someone opens something in your name, or you're tricked by a phishing call that used your data — that has become fraud, and speed matters. Report it at cybercrime.gov.in, and if money has moved call 1930, the national cyber-crime helpline. See how to report online fraud to cybercrime.gov.in and 1930 for what to have ready before you file.

At the national level, India has a dedicated agency — the Indian Computer Emergency Response Team (CERT-In) — that handles cyber-security incidents, and organisations have their own obligations to respond to and report breaches. As an individual, though, your practical, direct routes are the ones above: secure your accounts, watch for the scams that follow, and use the official reporting channels (cybercrime.gov.in / 1930) if a breach turns into fraud.

Exercising your data rights after a breach

Beyond limiting the damage, you have rights over your personal data — including asking an organisation what it holds and asking for it to be corrected or erased on the law's terms. What those rights are, and the honest scope of how they work today, is in your data protection rights under the DPDP Act, in plain language.

The honest bottom line

You cannot un-leak data that is already out — no one can promise to pull it back. What you can do is close the doors it opens: change reused passwords, switch on two-factor, treat every unsolicited "urgent" contact with suspicion, watch your statements, and report it fast if it turns into fraud. Doing those, calmly and in order, is what limits the damage. If you can't get back into an account, the National Consumer Helpline (1915) can guide you, and the account-recovery guides are linked above.

Was this helpful? (anonymous — no sign-up, nothing stored about you)

Official sources (verify everything here — and you can act directly through them)