Identity Data Exposed? A Country-Specific Guide

Identity Data Exposed? A Country-Specific Guide

After a LeakData match, check any available official breach notice for the affected data categories, then follow your country's route if identity data was involved.

A match found when checking an email address, password, domain or social account in LeakData does not by itself identify every other data category that may have been exposed. To establish whether passport or driving-licence data, names, dates of birth, addresses or financial information were affected, consult the provider’s official breach notice, if available, or other verified incident documentation.

Exposure is not the same as identity theft

The Office of the Australian Information Commissioner (OAIC) defines a data breach as occurring when personal information “is subject to unauthorised access or disclosure, or is lost.” The U.S. Federal Trade Commission (FTC) defines identity theft this way: “Identity theft is when someone uses your personal or financial information without your permission.” That distinction matters: a LeakData match or a breach notice that reports exposure alone does not prove that someone has used the identity information.

The OAIC also notes that information not about an individual on its own can become personal information when combined with other data that makes the person reasonably identifiable. The Canadian Centre for Cyber Security warns: “Once a threat actor has sufficient identity attributes, they can create fraudulent identity credentials or take control of existing credentials.” The assessment should therefore consider both the individual fields and how identifying they become when combined.

Response points vary by country

Official response steps vary by jurisdiction and circumstances. Canadian guidance includes determining which information may have been affected; UK guidance says lost or stolen documents should be reported to their issuer; and Australian guidance says to contact the bank or card provider immediately if a scam has occurred.

United States: Credit freezes and fraud alerts

For U.S. consumers, the FTC says a credit freeze requires contacting Equifax, Experian and TransUnion separately; this three-bureau requirement should not be generalized to other credit systems. While a freeze is in place, no one—including the consumer—can open a new credit account in their name; it can be lifted temporarily when needed. An initial fraud alert instead asks businesses to check with the consumer before opening a new account and does not prevent access to the credit report. Contacting one bureau is enough; that bureau must tell the other two to place the alert.

Canada: Credit reports, alerts and reporting

The Canadian Centre for Cyber Security includes identifying affected information in its guidance, with financial information and a Social Insurance Number as examples. It also recommends reviewing credit reports through Equifax and TransUnion, enabling alerts for unauthorized inquiries, and reporting the incident to the Canadian Anti-Fraud Centre online or by phone.

United Kingdom: Issuers, police and CIFAS

The ICO’s UK guidance says that lost or stolen items containing personal information, including passports, driving licences, credit cards and cheque books, should be reported to the issuing organization. The credit file should be checked for suspicious applications. Theft of personal documents and suspicious credit applications should also be reported to the police, with a request for a crime reference number. Optional CIFAS protective registration prompts member organizations to carry out extra checks when anyone, including the individual, applies for a financial service using those details.

Australia: Bank, IDCARE and Scamwatch

If a scam has occurred in Australia, Scamwatch recommends contacting the bank or card provider immediately and asking for the transactions to be stopped. IDCARE can help prepare a free plan to limit the damage. After the affected details have been secured, the scam can be reported to Scamwatch.

What this means for LeakData readers

When a LeakData check of your email address, password, domain or social account returns a match, use the provider’s official notice or another verified incident source to establish the affected data categories. If identity-document or financial data was affected, or if a name, date of birth and address were exposed together, follow the document, credit and fraud-reporting process for your country. If a password was also affected, change it for the relevant online account, as the OAIC’s example suggests.