At a glanceIf your data has leaked, work through seven steps in order: check what was exposed, change passwords and turn on two-factor authentication, secure your money, lock your Aadhaar, watch for scams, report any fraud to the cybercrime helpline 1930, and use your DPDP rights against the company. The steps to take after a data breach are the same whether you call it a leak or a breach — the priority is to contain the damage fast.
Educational resource only. This is a practical guide to the steps to take after a data breach or leak in India, including your rights under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
You’ve had a breach notification, seen your name in a leaked-database story, or started getting eerily well-informed scam calls. It’s unsettling — but a leak is manageable if you move through it calmly and in the right order.
What to do after a data breach: the 7 steps
Follow these in order — the first three are the most time-sensitive. Tap any step to jump to it.
- Check what was exposed — read the breach notice; check your email or phone on a tool like Have I Been Pwned.
- Change your passwords and turn on two-factor authentication — on the breached account and anywhere you reused it.
- Secure your money — alert your bank; block or replace any exposed card.
- Lock your Aadhaar — lock your biometrics via UIDAI or mAadhaar; use a masked Aadhaar in future.
- Watch for scams — treat the calls and messages that follow as suspect; never share an OTP.
- Report any fraud — call 1930 or file at cybercrime.gov.in.
- Use your DPDP rights — make the company disclose and delete, and complain to the Data Protection Board of India.
Step 1: Check what was exposed
Your whole response depends on which data leaked — pin that down first.
Not every leak is equal: a leaked email address is a nuisance, a leaked card number or Aadhaar is urgent. From the breach notice or news report, work out what’s out there:
- Login details — email and password → account-takeover risk.
- Financial data — card numbers, bank or UPI details → fraud risk (act fastest here).
- Identity documents — Aadhaar, PAN, passport, driving licence, Voter ID → impersonation and identity-theft risk.
- Contact data — phone, address → phishing and spam risk.
Not sure whether you’re caught up in a known breach? A free tool such as Have I Been Pwned lets you enter your email address or phone number and see which past breaches it has appeared in. It won’t catch every incident — very recent or India-only leaks may not be catalogued yet — but it’s a fast first read on your exposure.
Step 2: Change your passwords and turn on two-factor authentication
If any login was exposed, lock down your accounts before anything else.
- Change the password on the affected account — and on any other account where you reused it. Use a unique password for each.
- Turn on two-factor authentication (2FA) wherever it’s offered, so a stolen password alone isn’t enough to get in.
- Check for unfamiliar activity — logins, linked devices, email-forwarding rules — and remove anything you don’t recognise.
- Update recovery details (backup email, phone) in case an attacker tried to change them.
Step 3: Secure your money
If financial data leaked, treat it as urgent — and know the RBI rule that can leave you zero-liable.
- Report unauthorised transactions to your bank fast — the timing decides who pays. Under RBI rules, if you report an unauthorised electronic transaction within three working days of the bank’s alert, your liability is zero; report on days four to seven and it’s limited (and capped); delay longer and you may bear more. The moment you see a transaction you didn’t make, tell the bank — that window is the difference between losing nothing and losing everything.
- Block the card and claim the reversal. Call your bank’s official number, get the exposed card blocked or replaced, and raise a dispute. Once you report, the bank must provisionally credit a disputed unauthorised amount within about 10 working days.
- Lock down the channels. Turn on transaction alerts, lower your card and UPI limits, and raise a dispute in your UPI app for any unauthorised UPI debit.
- If your PAN was exposed, watch for unexpected credit enquiries or tax notices — signs someone may be using it to take credit in your name.
Step 4: Lock your Aadhaar
Unlike a card, your Aadhaar number can’t be reissued — so locking it is how you contain the damage.
- Lock your biometrics. Through the myAadhaar portal or the mAadhaar app, lock your biometrics so your fingerprints and iris can’t be used for authentication until you choose to unlock them — this neutralises the most damaging form of misuse.
- Check your authentication history. On myAadhaar you can review the recent authentication requests made against your Aadhaar — the date, the mode used, and the entity that asked — which is how you spot use you never authorised.
- Share it more safely from now on. Use a masked Aadhaar (which hides the first eight digits) instead of the full number, and a Virtual ID (VID) — a temporary 16-digit stand-in for your Aadhaar number — wherever a service accepts one.
- Report misuse to the UIDAI helpline 1947 or through the UIDAI grievance channel.
Step 5: Watch for the scams that follow a leak
The biggest harm after a leak is usually the fraud built on top of it — and leaked data makes the scam sound real.
A caller who already knows your name, your bank and your recent purchase sounds legitimate. In India these commonly arrive as a fake “your KYC/bank account will be blocked” call, a courier or customs problem, a bogus refund, or a “digital arrest” threat from someone posing as police. Protect yourself:
- Never install an app a caller tells you to. Remote-access or screen-sharing apps (AnyDesk-type) hand a stranger control of your phone — one of the most common fraud routes after a leak.
- Never share an OTP, PIN or password — no genuine bank, company or official ever asks for them.
- Treat urgency and threats as the red flag itself, and verify independently by calling the official number you look up — never one the caller gives you.
- Report the fraud call or SMS on the government’s Sanchar Saathi (Chakshu) portal, which takes reports of suspected fraud calls, SMS and WhatsApp messages.
Step 6: Report any fraud to 1930 and cybercrime.gov.in
Report financial fraud in the “golden hour” — the first hour is when the money can still be frozen.
For financial fraud or cybercrime, call the national helpline 1930 or file at cybercrime.gov.in immediately, with what happened and when. Speed isn’t a cliché here: the 1930 system alerts the banks and wallets along the money trail to freeze the stolen funds before the fraudster can withdraw them — which is why reporting within the first hour or so sharply improves your odds of getting the money back. Alongside:
- Keep the acknowledgement / complaint number you’re given — you’ll need it to follow up.
- cybercrime.gov.in covers non-financial cybercrime too — identity misuse, impersonation, harassment — not just money.
- If your bank doesn’t resolve the dispute, you can escalate to the RBI Ombudsman under the Reserve Bank’s grievance scheme, generally once the bank has had about 30 days.
Step 7: Use your DPDP rights against the company
The company that leaked your data owes you specific things under the DPDP Act — use them.
This is where you move from defence to holding the source accountable:
- They must tell you. A business that suffers a personal data breach must notify affected people without delay, in plain language — what happened, the likely consequences, and what you can do. (See what a company must tell you after a breach.)
- You can ask what they hold and demand deletion. Use your right of access to see your data, and your right to erasure (Section 12) to have it removed where there’s no lawful reason to keep it.
- You can complain. Start with the company’s grievance officer / Data Protection Officer, then escalate to the Data Protection Board of India — the regulator that can act against a business over a breach.
FAQ
What are the first steps to take after a data breach?
Check what was exposed, change your passwords and turn on two-factor authentication, and secure your money by alerting your bank. Those three come first; locking your Aadhaar, watching for scams, reporting fraud to 1930, and using your DPDP rights follow.
Is a data leak the same as a data breach?
In everyday use, yes — both mean your personal data has been exposed or accessed without authorisation. The DPDP Act’s formal term is “personal data breach,” but for a consumer the response is identical.
What’s the single most urgent step after a leak?
If financial data was exposed, securing your money comes first — alert your bank and, for any fraud, call 1930. If only a password leaked, change it (and any reuse) and turn on 2FA.
How do I protect my Aadhaar after a leak?
Lock your Aadhaar biometrics via the UIDAI website or mAadhaar app, and use a masked Aadhaar when you must share it. Locking prevents biometric authentication until you choose to unlock it.
Does the company have to tell me my data was leaked?
Yes. Under the DPDP Act, a business must notify affected people without delay after a breach, in plain language they can act on.
Can I get compensation if a company leaks my data in India?
Not from the DPDP Act directly — it’s a penalty regime, so fines for a breach are paid to the government, not to you as compensation. It holds the company accountable and can force it to fix things, but it doesn’t create a personal payout. Any claim for personal loss would run through separate legal routes, which are beyond this guide.
Where do I report data theft or financial fraud in India?
For financial fraud and cybercrime, use the helpline 1930 and the portal cybercrime.gov.in. For the data-protection failure itself, complain to the company and then the Data Protection Board of India.