The Civic Bulletin

Straight reporting on money, work and home.

Technology

A Breach Letter Ten Years Ago and One Today Ask You to Make Different Decisions

Notification deadlines shortened and credit freezes became free, which means the letter now arrives earlier, says less, and calls for a slower first move than it used to.

Technology·Harriet Bosworth

An opened breach notification letter on a kitchen table beside a laptop showing a credit bureau freeze confirmation screen, with a second unopened envelope f...
An opened breach notification letter on a kitchen table beside a laptop showing a credit bureau freeze confirmation screen, with a second unopened envelope f...

The envelope looks the same as it did a decade ago. Same apologetic first paragraph, same passive voice around who lost what, same offer of monitoring at the bottom with a code you have ninety days to redeem. What has changed is everything behind it: when the company was required to write, how much it knew at the time, and what the cheapest protective step available to you actually costs. Those three changes point in the same direction, and the direction is not the one the letter implies. The letter wants a fast response. The situation increasingly rewards a deliberate one.

The letter arrives earlier now, and earlier means thinner

Every state has a notification statute, most of them written or rewritten in the last fifteen years, and the clear trend has been toward shorter outside deadlines and fewer excuses for missing them. Health data has long carried its own federal timetable, and public companies now face a securities disclosure obligation triggered by a materiality judgment rather than by the completion of an investigation. Regulators tightened those clocks for a defensible reason: companies used to sit on findings for months while the stolen material circulated. The fix worked. The second-order effect is that the letter you receive today was often drafted while the forensic work was still open.

That is why the data element list in a modern notice reads the way it does. Name and Social Security number, possibly date of birth, possibly driver's license number, possibly financial account information. The hedging is not evasion in most cases, it is an honest account of what the investigators could confirm by the date the clock ran out. Ten years ago a letter that arrived four months after an incident had the luxury of specificity, and you could act on it once. A letter that arrives inside a tight statutory window is a first installment, and treating it as final is how people spend an afternoon protecting the wrong thing.

The freeze stopped being the expensive option

This is the change that reorders the whole decision, and it is easy to miss because it happened quietly. For most of the period when breach letters became routine, placing a security freeze at each of the three nationwide credit bureaus carried a fee in many states, and lifting it carried another, so a household weighing a freeze against a year of free monitoring was making a real financial comparison. Federal law removed that fee nationwide in 2018, for placing, lifting and removing, at all three bureaus. The comparison collapsed. The strong option became the free one, and it stays in force until you lift it rather than expiring when the enrollment year runs out.

Which means the monitoring code in the letter is no longer the main event, and the urgency attached to it is largely borrowed from an era when it was. Monitoring tells you after the fact that someone opened an account in your name. A freeze makes the opening substantially harder in the first place, because a lender that cannot pull your file usually will not extend the credit. Both are worth having and the code is worth redeeming, since it costs nothing and sometimes carries an identity restoration service. But nothing about the ninety-day window should drive the sequence of your first hour.

What the first letter can tell you, and what waits for the second

Read the notice for two things before anything else: the categories of data named, and the language describing how confident the company is about them. Those categories determine which levers matter. A Social Security number in the mix points at credit freezes and at the IRS Identity Protection PIN, which blocks a fraudulent return filed under your number. A driver's license number points at your state motor vehicle agency, which has its own process and its own timeline. Payment card data points at the issuer and at a card replacement, which is a fifteen-minute call rather than a structural change to your credit file.

The second letter, when it comes, is the one that changes answers. Supplemental notices go out when forensic review finds an additional file share, an additional affected population, or a data element nobody had confirmed on the first pass, and they are common enough now that assuming one is a reasonable default. Someone who froze all three bureaus in response to the first letter has already covered most of what a supplement can add. Someone who spent the first evening enrolling in monitoring, changing a dozen unrelated passwords and drafting a complaint has spent the effort and will have to spend it again.

The order that holds up under a supplement

Freeze first, at all three bureaus, because it is free, reversible in minutes with a PIN, and unaffected by anything a later letter might reveal. Redeem the enrollment code second, since it costs nothing and the window is real even if the urgency is overstated. Third, deal with the specific identifiers the letter names, one at a time, in the order of what an impostor could do fastest with each. Fourth, and only then, put the letter in a folder with the date you received it, because a claim, a dispute, or a tax filing problem eighteen months out will turn on your ability to show what you knew and when.

The Federal Trade Commission oversees identity theft reporting and recovery for consumers, and its role here is worth understanding in advance rather than in a panic. A formal identity theft report is the document that unlocks certain rights with creditors and bureaus, including blocking fraudulent information from your file. A breach letter is not that report, and filing one before anything has actually happened to you accomplishes little. Knowing where the report lives, and what it does, is the part to do early. Filing it is the part to hold until there is something to describe.

The decade's worth of regulatory work behind that thin envelope was aimed at getting you information sooner, and it succeeded. The cost of succeeding is that the information is provisional when it reaches you, and the protective step that answers nearly all of it now costs nothing and never expires. Read the letter twice, freeze, and let the second notice find you already covered.

Also gathered here

January 2026
December 2025