Digital — Field report TQL-TEC-620
The Breach Letter on the Counter: Six Questions Worth Answering Before You Panic
An apologetic paragraph, a sentence about how seriously they take this, and an offer of monitoring. The part that matters is buried in the middle.

The letter arrives with an apologetic opening paragraph, a sentence about how seriously the company takes this, and an offer of credit monitoring, and somewhere in the middle sits the only part that matters, written to be technically accurate rather than clear. What follows is arranged as six questions with our own answers under each, because those are the questions readers actually ask about these letters. Nothing below is quoted from anybody and no interview sits behind it. The answers depend entirely on which of the six come back badly.
What Exactly Was Taken?
This is the whole question and everything else follows from it, because there is a hierarchy and the letter will name the categories even where it buries them. An email address alone is minor. An email address plus a password is serious, and serious everywhere that password was reused. A full name with a date of birth and a Social Security number is the worst case, since that combination is what opens new accounts in somebody else's name, and payment card numbers sit somewhere in the middle because cards can be reissued while a Social Security number cannot. Medical information and credentials for a financial institution both sit near the top of the list too.
Were the Passwords Stored in a Form Anybody Can Use?
Where credentials were involved the letter usually says something about encryption, and the wording repays a careful reading. Stored in plain text means the passwords are simply known. Hashed with a modern algorithm built for passwords means they are difficult to recover, although not impossible for weak ones. Hashed with an older general purpose algorithm means treat them as compromised, and encrypted with no further detail is ambiguous enough to treat conservatively.
Whatever the answer turns out to be, change that password and change it everywhere it was used, which is true even in the best case and is the single most useful thing anybody does in response to one of these letters. The reuse step is the one people skip, partly because it is tedious and partly because the letter never mentions it, the company having no idea where else you used the same string.
How Long Was It Open Before Anybody Noticed?
The letter gives two dates, the day the breach happened and the day it was discovered, and the gap between them is informative. A breach found within days is a different situation from one that ran for eight months before anyone noticed, because the second describes a much longer window in which the data could have been sold and used. The practical use of those dates is for your own review rather than for judging the company.
Pull statements covering the period from the breach date forward rather than just the last month, and look for small unfamiliar charges as carefully as large ones, since testing a stolen card with a trivial transaction before attempting a large one is a standard pattern. Where an account has been open a long time, this is also a reasonable moment to check the contact details on file, because an address or phone number changed by somebody else is the quiet first move in a takeover.
Is a Credit Freeze the Same Thing as the Monitoring They Offered?
No, and the difference matters more than the letter suggests. Monitoring reports damage after it has been done, while a freeze works a step earlier, because a lender who cannot reach your credit file has no way to approve a new account against it. A freeze is free at each of the major bureaus, must be placed with each one separately, can be lifted temporarily whenever you need to apply for something, and affects neither your existing accounts nor your credit score.
If a Social Security number was in the exposed categories, this is the response that actually protects you rather than the one that watches. Take the offered monitoring as well, since it costs nothing and provides another set of eyes, and simply do not mistake it for protection. A freeze is a right rather than a courtesy, so if a bureau makes difficulties about placing or lifting one, the complaint about that goes to the Consumer Financial Protection Bureau rather than back to the bureau that caused it.
What Else Can Be Reset Using This Information?
Here is the question most people skip. Look at what was taken and ask what it unlocks somewhere else, working outward from the breached account to everything connected to it. An email address together with a security question answer is a recovery path into other services. A phone number with an account number may be enough for a representative somewhere to authenticate a caller pretending to be you. And if the breached company is one you use to sign in to other services, the affected area is considerably wider than one account.
Does Any of This Reach Taxes or Benefits?
Where a Social Security number was exposed it does, and nothing in the letter will say so. Stolen numbers get used to file fraudulent returns claiming refunds and to claim benefits, both of which are discovered late and are tedious to unwind. Two protective steps handle most of it. Filing your own return early in the season shortens the window in which somebody else can file first using your number, and an identity protection personal identification number, issued to individuals who request one, prevents a return being processed under that number without it.
Put in order, the whole response runs like this. Change the password and every reuse of it. Turn on a stronger second factor there and on your email. Freeze credit at each bureau if a Social Security number was involved, pull statements across the exposed period, accept the monitoring, and tighten recovery settings on connected accounts. That is roughly ninety minutes for a serious breach and considerably less for a minor one. The households that come through these without lasting trouble are the ones who read the category list twice, worked out what it unlocked elsewhere, and closed those doors in the same week the envelope arrived.