You get the email. A company you've done business with — a retailer, a health app, a subscription service — tells you your information may have been exposed in a data breach. They're sorry. They recommend you change your password. They're offering free credit monitoring for a year.
And then most people close the email and move on.
Here's what's actually happening on the other end of that breach. And why the risk doesn't end when the news cycle does.
Where your data goes first
When a large batch of personal information gets stolen, it doesn't go straight to someone trying to drain your bank account. It gets sold.
Stolen data is packaged and listed on dark web marketplaces, often within days of the breach. The price depends on what's in it. A basic email and password combination sells for very little. Add a Social Security number, a date of birth, and a financial account number, and the value goes up significantly.
Buyers on these markets range from low-level scammers running phishing campaigns to organized groups running sophisticated identity theft operations.
How long does it stay active?
This is the part most people don't expect.
Stolen data doesn't expire quickly. A username and password combination from a breach can circulate for months or years, passed from buyer to buyer and used in waves. Financial account information stays valuable until the account is closed or the credentials change. Social Security numbers, dates of birth, and other identity details don't change at all. Which means they stay useful indefinitely.
The breach notification you received today might be protecting you from an attack that won't happen for another 18 months.
What criminals actually do with it
The most immediate use is credential stuffing. Taking your exposed username and password and automatically trying them on dozens of other websites. If you've reused that password anywhere else, those accounts are now vulnerable too. This is why password reuse is so dangerous and why the "change your password" advice matters even when it feels like overkill.
Beyond that, stolen information gets used to open new accounts in your name, file fraudulent tax returns, apply for loans and credit cards, and build synthetic identities that combine real and fake information into a profile that can take years to unravel.
What the realistic risk window looks like
The months immediately following a breach are the highest-risk period for direct account takeover. But the broader risk of identity theft extends much further.
The people most likely to act quickly are the ones who bought fresh data. The slower, more methodical fraud often comes later. Sometimes years after the original breach, when the victim has long stopped paying attention.
This is why a one-year credit monitoring offer, while helpful, doesn't close the window. The habit of watching your accounts, checking your credit report, and staying alert to unusual activity needs to become permanent, not temporary.
What actually helps
Change the exposed password everywhere you've used it. Not just on the breached site.
Turn on two-factor authentication wherever it's available. Credential stuffing can't get past a one-time code it doesn't have.
Freeze your credit if you're not planning to apply for anything soon. It's free, reversible, and the single most effective way to block new account fraud.
Check your credit report regularly. You're entitled to a free report from each of the three major bureaus. Spread them out across the year so you're checking more often.
And pay attention longer than feels necessary. The breach that happened six months ago is still worth thinking about today.
We're here when you need us
If you're concerned about fraud on your First Commonwealth accounts or want to know what to watch for, our Fraud Center has resources to help. And if something looks wrong, reach out. Catching it early makes all the difference.
