What Your Leaked Data Actually Lets Someone Do

A breach notice tells you how many records were exposed. That number says nothing about you. What matters is which fields leaked and, more than anything, which combination — a leaked name is nothing, but a name with a date of birth and a home address is what a call centre asks to verify you.

What did the breach expose?

Tick everything the notice listed — or start from a real breach below. The combination matters far more than any single item.

Start from a real breach

Field sets from the public Have I Been Pwned record. Selecting one fills in what it exposed — it does not check whether you were in it.

Contact details
Login details
Identity details
Financial details
Government ID

What this allows

Account risk. 5 things someone could do with this, and 5 steps to take.

The combination matters more than the count

Coverage of a breach reports a record count and stops. Half a million records exposed tells a reader nothing about their own position, because the harm does not come from the size of the breach — it comes from what was in it.

And the fields interact. Your name on its own is in a phone book. Your date of birth is on your social media. Your address is on a parcel. Any one of them is close to harmless; all three together are the three things a bank, a telco or a government line will ask to confirm you are you.

Most breaches are the common, fixable kind

Of the 1,033 breaches catalogued by Have I Been Pwned, only 47 exposed a government ID, a bank account number or a passport. That is roughly one in twenty-two.

The overwhelming majority are an email-and-password problem. That is genuinely serious — leaked passwords get tried automatically everywhere else you used them — but it is fixable in an afternoon. A tool that treats every breach as a catastrophe is not being careful, it is being useless, so this one says plainly when your exposure is the ordinary kind.

A leaked password is not about the site that leaked it

The breached account is rarely the target. Leaked credentials are fed into automated tools that try the same email and password against thousands of other sites — banks, email providers, retailers. The practice is called credential stuffing and it is the reason reuse, not the breach itself, is the real exposure.

It is also why changing the password on the breached site alone achieves very little. The work is changing it everywhere you used it, starting with your email account, because whoever controls that can reset everything else.

A leaked SIN has an uncomfortable answer

Most guidance a Canadian finds for a leaked government number is written for an American Social Security Number, and the remedies do not transfer.

Service Canada does not issue a new Social Insurance Number because yours was exposed. A replacement is available only where fraud has actually occurred and can be demonstrated. So for an exposed SIN the remedy is monitoring rather than replacement — a fraud alert at both Equifax Canada and TransUnion Canada, which are separate companies and must be contacted separately, and a report to the Canadian Anti-Fraud Centre.

The second wave does more damage than the breach

Within days of a large breach becoming public, messages start arriving that name the breached company and ask you to verify or secure something. They are convincing precisely because the event is real and you have been told to expect contact about it.

The rule that survives contact with a panicking reader: a company that has just leaked your data will not telephone to ask you to confirm it. If you want to check something, close the message and go to the organisation yourself.

Frequently asked questions

My email was in a breach. Is that bad?

On its own, no — it is a nuisance that ends up on spam and marketing lists. It becomes serious when paired with something else, particularly a password. Tick what else leaked above and the answer changes accordingly.

What is the most dangerous thing that can leak?

Not a single field — a combination. A Social Insurance Number alongside your name or date of birth is the worst, because it is what a lender needs to run credit as you. But only 47 of 1,033 catalogued breaches have ever exposed one.

Can I get a new Social Insurance Number if mine leaked?

Not simply because it was exposed. Service Canada replaces a SIN only where fraud has actually occurred and been demonstrated. For an exposure without fraud, the remedy is a fraud alert at both credit bureaus and ongoing monitoring.

Do I need to contact both credit bureaus?

Yes. Equifax Canada and TransUnion Canada are separate companies and do not share alerts. Placing a fraud alert with one does nothing at the other, and both are free.

Only part of my card number leaked. Does that matter?

Not for spending — partial digits cannot be used to make a purchase. It matters because reading your last four digits back to you is how a caller proves they are your bank. Paired with your name or address it makes a persuasive script.

How do I know if I was actually in a breach?

This page tells you what a given combination of leaked data allows; it cannot tell you whether your address was in any particular breach. That needs your email checked against the breach records themselves, which NotchUp Shield does free with no account.

Sources

Every rate, threshold and formula on this page was verified against these primary sources. If a figure here disagrees with one of them, the source is right and we want to know.

About this calculator

Written by
NotchUp Editorial Team
Reviewed by
India Varga
Last reviewed

This calculator is an informational tool, not legal or financial advice. Employment standards rules have exceptions, and your contract or collective agreement may give you more than the legal minimum. For a binding answer about your own situation, contact your provincial employment standards branch or an employment lawyer.

NotchUp Financial Inc. is a licensed lender in British Columbia. License Disclosure: British Columbia, January 11, 2024 License #86443.