PanicStation.org
uk Money & financial emergencies

What to do if…
you get an alert that your card details may have been exposed in a data breach

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat the alert as real until you have checked it safely. Use your bank or card issuer’s app, website typed in yourself, or the phone number on your card or statement to freeze or block the card and review recent transactions.

Do not do these things

  • Don’t click links or call numbers from the alert email, text, advert, pop-up or social media message.
  • Don’t share one-time passcodes, your card PIN, full password or banking security answers.
  • Don’t approve a security prompt, wallet setup, payment approval or “new device” request unless you started it.
  • Don’t assume “no money missing” means nothing can happen; exposed card details may be tested later.
  • Don’t cancel Direct Debits in panic. Card exposure mainly affects card payments, including saved card payments and subscriptions.
  • Don’t pay anyone who says they can remove your details from the dark web based only on a message.

What to do now

  1. Verify the alert without using the alert. Open your banking app, type your bank’s web address yourself, or use the number on your card or statement. Check whether your bank or card issuer has sent a matching secure message.
  2. Freeze, lock or block the card. Use the in-app freeze if your issuer offers it. If not, call the issuer and ask them to block the card and issue a replacement.
  3. Check transactions line by line. Look for small test payments, online purchases, new subscriptions or merchant names you do not recognise. If you see anything wrong, report it to your bank or card issuer as an unauthorised card payment.
  4. Turn on useful card alerts if they are available. Use instant spending notifications and any temporary controls your app already offers, such as online, international or contactless controls, until the replacement card is working.
  5. Check wallets and linked devices. In your banking app or wallet app, look for devices or digital wallets linked to the card. Remove anything you do not recognise and follow your issuer’s instructions for the replacement card.
  6. Remove the exposed card from places that can spend quickly. Start with major retailers, delivery apps, travel apps, ride-hailing apps, app stores, subscription services and merchant wallets.
  7. Secure the account that protects the others. If your email password was reused anywhere, change your email password first and turn on two-step verification if available. Then change passwords for accounts where the card was saved.
  8. Cut off follow-up scams. If someone contacts you about the breach, fraud, a refund, a safe account, remote access, or “confirming” codes, end the contact. Contact your bank again using the app, typed website, card number or statement number.
  9. If personal identity details were exposed too, consider extra identity checks. If the breach included your name, address, date of birth, documents, or enough information for credit applications, Cifas Protective Registration may be worth considering. It is optional, lasts 24 months, can slow genuine applications, and does not stop card transactions.
  10. Keep a short incident note. Record the date and time of the alert, what it said was exposed, what you did, who you spoke to, and any reference numbers. Save screenshots of suspicious transactions or messages.

What can wait

  • Switching banks or replacing unrelated cards.
  • Changing every password you have. Start with email and accounts where the exposed card was saved.
  • Complaining about the organisation that sent the breach notice.
  • Full fraud reporting, unless money has been taken, someone is in immediate danger, or the fraud is happening now. Locking or blocking the card comes first.
  • Credit-file checks, unless identity details were exposed or you later see signs of identity fraud.

Important reassurance

A card exposure alert is unsettling, but the first protective actions are small and practical: check through a trusted route, block the card, review transactions, and ignore pressure from anyone who contacts you unexpectedly. You do not need to solve every possible risk today.

Scope note

These are first steps for the hours and days after a card exposure alert. If you later find identity fraud, new credit applications, account takeover, or a dispute with your bank or card issuer, you may need specialist help.

Important note

This is general information, not financial, legal, cyber-security or professional advice. Bank processes and protections vary by provider and by the type of payment. If you see suspicious activity, contact your bank or card issuer using trusted contact details immediately.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us