Is That Data Breach Email Real? How to Tell (2026)

Reviewed by India Varga
Is That Breach Email Real: envelope with question mark icon on a purple background
Updated September 2026

That breach notification in your inbox is probably real, and you can confirm it without clicking a thing. Under PIPEDA, Canadian companies have been legally required to notify you since November 1, 2018, so legitimate breach emails are common. The problem is that scammers send near-identical fakes. The reliable difference isn’t how the email looks; it’s what the email asks you to do.

Key Takeaways

  • Real breach notifications tell you what leaked and ask for nothing. Fake ones pressure you to click a link, open an attachment, or hand over a password or SIN.
  • You never have to trust the email. Go to the company’s website yourself, check their newsroom, or search the news. If the breach is real, evidence of it exists outside your inbox.
  • Under PIPEDA, organizations must notify individuals when a breach creates a “real risk of significant harm” and report it to the Privacy Commissioner. Genuine breach emails are a normal thing to receive in Canada.
  • Phishing campaigns launch within days of a publicized breach, impersonating the breached company. The timing is the whole trick: you’re already expecting an email.
  • Once you’ve confirmed the breach is real, your next step depends on what leaked, not on how alarming the email sounded. Check our Canadian data breach list or use the data breach risk checker to see what your combination enables.

This article reflects Canadian privacy law as of September 2026. PIPEDA requirements and organizational practices can change. Check each source for current details.



Why Fake Breach Emails Follow Real Breaches

Every large breach comes in two waves. The first is the breach itself. The second is the phishing campaign that impersonates the breached company, and it starts within days. Scammers read the same headlines you do. They know that after a well-publicized incident, millions of customers are half-expecting an email that says “we regret to inform you.” An inbox that would normally be suspicious of such a message suddenly treats it as overdue.

That timing is the whole trick. The fake email doesn’t need to be clever. It needs to arrive when you’re primed to believe it and give you one urgent thing to click. The breach being real tells you nothing about whether this particular message is.

It also helps to know that genuine notifications aren’t rare. Under PIPEDA, Canada’s federal privacy law, organizations have been required since November 1, 2018 to notify individuals when a breach creates a “real risk of significant harm.” They must also report the breach to the Privacy Commissioner of Canada. So a legitimate breach email is a normal thing to receive. The question isn’t “would a company really email me about this?” They would. The question is whether this specific email behaves like a real one.


Signs a Breach Notification Is Genuine

Real notifications follow a recognizable pattern. A genuine breach email typically:

  • Tells you specifically what information was involved, such as names, email addresses, or account details, even when the answer embarrasses the company.
  • Never asks for your password, your SIN, or your payment details. A company that lost your data doesn’t need you to send it again.
  • Doesn’t make you log in through an emailed link to “verify” or “secure” your account. It may tell you to change your password, but it expects you to go to the site on your own.
  • Points you to the company’s own website, where the same notice usually appears publicly.
  • If it offers credit monitoring, names a provider you can verify independently, often with an enrollment code rather than a login link.

The common thread: a real notification informs you and then gets out of your way. It needs nothing from you inside the email itself.


Signs It’s Phishing

Fake notifications flip that pattern. Instead of informing you, they pressure you. Watch for:

  • Urgent deadlines, such as “secure your account within 24 hours.” Real notices almost never carry a countdown.
  • Links to look-alike domains, like a company name with an extra word, a hyphen, or a strange ending.
  • Requests to confirm your card number, password, SIN, or one-time codes. No genuine breach notice asks for these, ever.
  • Attachments. A real notification is text. A “secure document” or “incident report” attachment is a red flag on its own.
  • Threats of account closure or legal consequences if you don’t act. Fear is the product being sold.

The Uncomfortable Truth: Real Ones Can Look Fake

Some genuine notifications look phishy. Companies often send them through third-party mailing services, so the sender address is an unfamiliar domain. Breaches handled through legal settlements sometimes arrive from a law firm or a claims administrator you’ve never heard of. Greetings are frequently generic (“Dear Customer” rather than your name), sometimes deliberately, because the company doesn’t want to confirm personal details in an email.

Meanwhile, some fakes are flawless. Perfect logo, perfect grammar, a sender address one letter off from the real one. Modern phishing kits copy a company’s actual email templates.

So polish proves nothing in either direction. The reliable tell is behaviour: what the email asks you to do. A message that informs you and points you to public sources behaves like a notification. A message that needs you to click its link, open its attachment, or type your credentials behaves like a trap, no matter how official it looks.


The Safe Way to Check, Every Time

You never have to decide whether an email is trustworthy, because you can verify its claim without touching it at all:

  1. Don’t click anything in the email. Not the main link, not “unsubscribe,” not the logo.
  2. Go to the company’s website yourself. Type the address, use your bookmarked link, or open the official app. If you need to change a password, do it there.
  3. Check the company’s newsroom or announcements page. Notification campaigns almost always come with a public statement.
  4. Search the news. A breach big enough to email you about is usually big enough to be reported.
  5. Check our running list of Canadian data breaches to see whether the incident is real and what actually leaked.

The principle behind all five steps: if the breach is real, evidence of it exists outside your inbox, somewhere the scammer doesn’t control. This is also why an independent breach alert you set up yourself is worth having. You chose the source in advance, so it can’t be spoofed the way an inbound email can. That’s exactly what NotchUp Shield is: you set it up once, and it tells you when your email address shows up in a newly verified breach.


If the Email Was Real

Once you’ve confirmed the breach through the company’s own site or the news, your next move depends on what leaked, not on how alarming the email sounded. If a password was exposed, start with our guide to a leaked password. If payment card details were involved, see what to do when your credit card is leaked. If the breach touched your Social Insurance Number, that has its own playbook in our SIN leak guide.

Confirmed it is real? Check what the fields enable

Your next move depends on what leaked, not on how alarming the email sounded. Tick what the notice listed in our free data breach risk checker and get the Canadian answer: what that combination lets someone do, and which step to take first.

Check what your leaked data enables →


Frequently Asked Questions

How do I know if a data breach email is real?

Judge it by what it asks, not how it looks. A real notification tells you what leaked, asks for nothing, and can be confirmed on the company’s website or in the news. If it needs you to click a link, open an attachment, or provide a password, card number, or SIN, treat it as phishing. You can also check our Canadian data breach list to verify whether the breach actually happened.

Do companies in Canada have to notify me about a breach?

Yes. Under PIPEDA, Canada’s federal privacy law, organizations have been required since November 1, 2018 to notify affected individuals when a breach creates a “real risk of significant harm.” They must also report the breach to the Privacy Commissioner of Canada. Provincial privacy laws in Quebec, Alberta and British Columbia have their own notification rules that may also apply.

Should I click the link in a breach notification?

No, and you never need to. Even when the email is genuine, the safest habit is to go to the company’s site by typing the address or using your bookmarked app, then take any action there. A real notice loses nothing when you ignore its links. A fake one loses everything.

What if I already clicked a fake breach email?

Clicking the link alone is usually survivable. If you entered a password, change it immediately on the real site, and on any other account that shares it. If you entered card details, call your bank or card issuer. Turn on two-factor authentication where you can, and watch your statements for a few weeks. Acting within hours makes the biggest difference. If you gave up your SIN, follow the steps in our SIN leak guide.

Why did a law firm or third party email me about a breach?

Breach notifications are often outsourced to mailing services, claims administrators, or law firms handling a settlement, so an unfamiliar sender isn’t proof of a scam. Search the firm’s name plus the breach, and confirm the story on the breached company’s own site before responding to anything.

What should a real breach notification include?

Under PIPEDA, a legitimate notification must describe the circumstances of the breach, specify what personal information was involved, explain what the organization is doing to reduce the risk, and tell you what steps you can take to protect yourself. It should also include contact information for someone who can answer your questions. If the email you received is missing most of these, it may be a poor notification rather than a fake, but verify through the company’s website either way.

Can I check if my data was in a breach without waiting for an email?

Yes. You don’t have to rely on companies to tell you. NotchUp Shield monitors whether your email address appears in newly verified breaches and alerts you directly. You can also check our Canadian data breach list to see whether a specific company has reported an incident and what data types were involved.

What’s the difference between a breach notification and a phishing email?

A breach notification informs you about something that already happened and asks for nothing in return. A phishing email pretends to inform you but actually needs something from you: a click, a password, a card number, your SIN. The distinction is always in the behaviour, not the appearance. Both can have professional logos, correct grammar, and your real name. The safe default is to verify every breach email through the company’s own website before acting on anything inside it.


This article is for informational purposes only and doesn’t constitute professional legal, financial, or cybersecurity advice. If you believe you’re a victim of identity fraud or a phishing attack, report it to the Canadian Anti-Fraud Centre at 1-888-495-8501 (weekdays 10 a.m. to 4:45 p.m. Eastern) and contact your local police.

Related Reading

An alert you set up yourself cannot be spoofed the way an inbound email can. You can check your own email address against roughly a thousand verified breaches free, with no account, at NotchUp Shield, and hear about the next one from a source you chose.

Breach data referenced from Have I Been Pwned, licensed CC BY 4.0.

How Much Credit Card Debt Do Canadians Actually Have? (2026)

How Much Credit Card Debt Do Canadians Actually Have? (2026)

NotchUp Editorial TeamSep 8, 2026
How to Pay Off Credit Card Debt on a Low Income in Canada

How to Pay Off Credit Card Debt on a Low Income in Canada

NotchUp Editorial TeamSep 8, 2026
How Long Does It Really Take to Pay Off a Credit Card in Canada?

How Long Does It Really Take to Pay Off a Credit Card in Canada?

NotchUp Editorial TeamSep 8, 2026
India Varga, reviewer at NotchUp

Written by the NotchUp Editorial Team. Reviewed by

India Varga

Operations and Content Specialist at NotchUp

India Varga is an operations and content specialist at NotchUp with more than nine years of experience across fintech and digital operations. She reviews every article on the blog for accuracy, clarity, and relevance so Canadians can make informed borrowing decisions.

Get up to $1,500 Apply Now