General EditionThe Daily StandardNo sponsors, no sales pitch

Clear reporting on the choices people actually face.

Technology

No Evidence of Misuse: What a Data Breach Letter Is Actually Telling You

The letter says there is no evidence of misuse and offers two years of monitoring. Both statements are true and neither is the part that matters.

A kitchen table with an opened envelope and a printed letter face down beside a laptop and a set of reading glasses
A kitchen table with an opened envelope and a printed letter face down beside a laptop and a set of reading glasses

The envelope arrives in March about something that happened the previous autumn, and it is written in a register that manages to be alarming and soothing at the same time. There has been an incident. Certain files were accessed. There is no evidence that any information has been misused. Two years of credit monitoring are being provided at no cost. Every one of those statements is likely to be literally true, and none of them is the sentence that decides what a recipient should do next, which is buried in a list somewhere on the second page.

Reading the Paragraph That Says What Was Taken

The only genuinely load bearing part of the letter is the list of data elements involved, and it usually appears once, in a single sentence, without emphasis. Name and email address is a nuisance. Name, date of birth and Social Security number is a different category of event entirely, because those three items do not expire, cannot be changed on request, and are precisely what somebody needs to open an account in another person's name. Everything else in the envelope is written around that sentence.

Financial account numbers sit somewhere in between and depend on what accompanied them. A card number on its own gets reissued and the exposure ends. A bank account and routing number combined with a name and address is harder to unwind, and a driver's license number matters more than people expect because it is used as an identity check in places that never issue licenses. Read the list, decide which of those three groups the letter describes, and let that determine how much of an afternoon this is worth.

What No Evidence of Misuse Actually Means

The phrase is accurate and it is also close to meaningless as a forecast. Organizations detect misuse when somebody reports it back to them, which means the sentence describes the state of the company's knowledge at the moment the lawyers approved the letter rather than the state of the world. Stolen identity data is frequently held for a considerable time before it is used, partly because the market for it is not in a hurry and partly because the alerts and the free monitoring both expire.

The same applies to the reassuring detail that the incident has been contained and law enforcement notified. Both are true, both are appropriate, and neither changes anything for the person holding the letter. The useful reading of a breach notice treats it as a statement about what left the building, not as a prediction about what will happen next, and the correct response is proportionate to the first thing rather than to the tone of the second.

Monitoring Watches, and a Freeze Prevents

Credit monitoring tells you after something has happened. A security freeze stops the thing from happening in the first place, by preventing a new creditor from pulling the file at all, which is what almost every fraudulent account application depends on. A freeze is free at each of the three major credit bureaus, can be lifted temporarily whenever a genuine application requires it, and does not affect existing accounts, credit scores or the ability to use cards already in a wallet.

The offered monitoring is still worth accepting, since it costs nothing and it will notice things a freeze does not cover, such as an existing account being taken over. But treating it as the response, rather than as a supplement to the response, is the mistake the letter's structure gently encourages, because the monitoring is the thing the letter has to offer and the freeze is the thing that would have to be done by the reader. The Federal Trade Commission maintains the federal identity theft resource, which walks through the freeze process bureau by bureau and produces a recovery plan if something has already gone wrong.

The Accounts That Are Actually at Risk

Most fraud that follows a breach is unglamorous and reuses old material. If the exposed password was one you have used elsewhere, that is the immediate job, and it is more urgent than anything involving credit. Change it wherever it appears, starting with the email account, because email is the reset route into everything else and its compromise makes the rest of the cleanup pointless. Turn on a second factor for that account while you are already in the settings.

Deciding How Much of This Is Worth Your Afternoon

The proportionate response to a name and email address exposure is a raised eyebrow and slightly more suspicion of unexpected messages, since the practical consequence is better targeted phishing rather than fraud. The proportionate response to a Social Security number exposure is a freeze at all three bureaus, a password change, and a note in the calendar to check the credit file in six months when the free monitoring has lapsed and everyone has stopped thinking about it.

Keep the letter itself, filed rather than recycled, because it is the document that proves a specific exposure on a specific date, and that proof occasionally matters a year later when something has to be disputed. That is the quiet value of the envelope that arrived in March about an incident from the previous autumn. It was never really a warning, and it was never really an apology. It was a record, and the recipient is the only person likely to need it.