What Your Leaked Data Actually Lets Someone Do
A breach notice tells you how many records were exposed. That number says nothing about you. What matters is which fields leaked and, more than anything, which combination — a leaked name is nothing, but a name with a date of birth and a home address is what a call centre asks to verify you.
What this allows
What this allows
Account risk
Enough to get into accounts or pass as you. Act this week.
Across the 1,033 breaches on record, 11.8% exposed a name, date of birth and address together — the set that lets someone pass as you. Only 4.5% exposed a government ID, bank account or passport, so most exposure is the common, fixable kind.
What someone can actually do
-
Passing as you on the phone
Name, date of birth and home address are the three things a call centre asks to verify you. Together they are the identity-theft starter kit — individually, none of them matters much.
-
Every other account where you reused that password
Leaked passwords get tried automatically across thousands of sites. The breached account is rarely the target — the damage lands wherever else you used it.
-
Convincing you they are your bank
Partial card digits are not spendable, but reading them back to you is how a caller proves they are legitimate. Paired with your name or address it is a persuasive script.
-
Taking over your phone number
A phone number with identifying details supports a SIM-swap attempt. If your two-factor codes arrive by text, the number is the account.
-
Phishing that knows things about you
An email address paired with real details makes a convincing approach. Expect messages naming the breached company — that second wave is where most actual losses happen.
What to do, in order
-
Change that password everywhere you reused it
Start with email and banking — email first, because it can reset everything else. If the same password is anywhere else, it is already being tried there.
-
Turn on two-factor authentication
An app-based code beats a text message, particularly if your phone number also leaked. This is the single step that makes a leaked password survivable.
-
Place a fraud alert with both Canadian credit bureaus
Equifax Canada and TransUnion Canada are separate — an alert with one does nothing at the other. It is free, and it makes lenders verify identity before opening credit.
-
Expect the second wave
Messages naming the breached company arrive within days and are where most real losses happen. A company that has just leaked your data will not phone to ask you to verify it.
-
Watch the address from here on
Data from one breach is routinely recombined with the next. The exposure that matters is often assembled over years rather than delivered at once.
Account risk. 5 things someone could do with this, and 5 steps to take.
- 47 of 1,033breaches leaked a government ID
- Canadianbureaus, CAFC, Service Canada
- $0to use, no signup
The combination matters more than the count
Coverage of a breach reports a record count and stops. Half a million records exposed tells a reader nothing about their own position, because the harm does not come from the size of the breach — it comes from what was in it.
And the fields interact. Your name on its own is in a phone book. Your date of birth is on your social media. Your address is on a parcel. Any one of them is close to harmless; all three together are the three things a bank, a telco or a government line will ask to confirm you are you.
Most breaches are the common, fixable kind
Of the 1,033 breaches catalogued by Have I Been Pwned, only 47 exposed a government ID, a bank account number or a passport. That is roughly one in twenty-two.
The overwhelming majority are an email-and-password problem. That is genuinely serious — leaked passwords get tried automatically everywhere else you used them — but it is fixable in an afternoon. A tool that treats every breach as a catastrophe is not being careful, it is being useless, so this one says plainly when your exposure is the ordinary kind.
A leaked password is not about the site that leaked it
The breached account is rarely the target. Leaked credentials are fed into automated tools that try the same email and password against thousands of other sites — banks, email providers, retailers. The practice is called credential stuffing and it is the reason reuse, not the breach itself, is the real exposure.
It is also why changing the password on the breached site alone achieves very little. The work is changing it everywhere you used it, starting with your email account, because whoever controls that can reset everything else.
A leaked SIN has an uncomfortable answer
Most guidance a Canadian finds for a leaked government number is written for an American Social Security Number, and the remedies do not transfer.
Service Canada does not issue a new Social Insurance Number because yours was exposed. A replacement is available only where fraud has actually occurred and can be demonstrated. So for an exposed SIN the remedy is monitoring rather than replacement — a fraud alert at both Equifax Canada and TransUnion Canada, which are separate companies and must be contacted separately, and a report to the Canadian Anti-Fraud Centre.
The second wave does more damage than the breach
Within days of a large breach becoming public, messages start arriving that name the breached company and ask you to verify or secure something. They are convincing precisely because the event is real and you have been told to expect contact about it.
The rule that survives contact with a panicking reader: a company that has just leaked your data will not telephone to ask you to confirm it. If you want to check something, close the message and go to the organisation yourself.
Frequently asked questions
My email was in a breach. Is that bad?
On its own, no — it is a nuisance that ends up on spam and marketing lists. It becomes serious when paired with something else, particularly a password. Tick what else leaked above and the answer changes accordingly.
What is the most dangerous thing that can leak?
Not a single field — a combination. A Social Insurance Number alongside your name or date of birth is the worst, because it is what a lender needs to run credit as you. But only 47 of 1,033 catalogued breaches have ever exposed one.
Can I get a new Social Insurance Number if mine leaked?
Not simply because it was exposed. Service Canada replaces a SIN only where fraud has actually occurred and been demonstrated. For an exposure without fraud, the remedy is a fraud alert at both credit bureaus and ongoing monitoring.
Do I need to contact both credit bureaus?
Yes. Equifax Canada and TransUnion Canada are separate companies and do not share alerts. Placing a fraud alert with one does nothing at the other, and both are free.
Only part of my card number leaked. Does that matter?
Not for spending — partial digits cannot be used to make a purchase. It matters because reading your last four digits back to you is how a caller proves they are your bank. Paired with your name or address it makes a persuasive script.
How do I know if I was actually in a breach?
This page tells you what a given combination of leaked data allows; it cannot tell you whether your address was in any particular breach. That needs your email checked against the breach records themselves, which NotchUp Shield does free with no account.
Sources
Every rate, threshold and formula on this page was verified against these primary sources. If a figure here disagrees with one of them, the source is right and we want to know.