Your SSN or SIN Leaked in a Breach? Do These 8 Things
Breach notification letters tend to follow a template. The one the FTC gives companies as a model has four headings: What Happened, What Information Was Involved, What We Are Doing, and What You Can Do. The second heading is the one to read closely. If the answer includes your Social Security number or Social Insurance Number, the rest of this list applies to you.
Those letters are going out right now. In September, the Pentagon began notifying about 2.8 million living people that their records, including Social Security numbers, had been taken from the Defense Manpower Data Center. TechCrunch reported the records were stored unencrypted and the intrusion ran from October 2025 to mid-July 2026. The Defense Department says it has seen no sign of misuse. That’s a reasonable thing to hope for and a bad thing to plan around.
The problem with a leaked ID number is that you mostly can’t replace it. The US Social Security Administration issues a new number only if misuse continues after you’ve tried everything else, and warns that a new number may not fix things because credit bureaus already file your history under the old one. Canada’s SIN Program won’t issue a new SIN “without proof that your SIN was used to commit fraud.” Since you’ll be keeping the number, the goal is to make it useless to anyone else. These steps are in order of how much each one protects you, with the US and Canadian versions side by side.
1. Freeze your credit, which is the strongest step
US: A credit freeze stops lenders from pulling your report, which stops almost every new account a thief could open in your name. The FTC says it’s free to place and lift, lasts until you lift it, and doesn’t affect your score. You have to do it separately at each bureau: Equifax, Experian and TransUnion. Save each bureau’s login or PIN, because you’ll need it to lift the freeze before applying for a mortgage or a new card.
Canada: It’s less straightforward here. The Financial Consumer Agency of Canada says a security freeze “locks your credit report,” but availability varies by province or territory. Ask Equifax Canada and TransUnion Canada directly what you’re eligible for.
2. Place a fraud alert, especially in Canada
A fraud alert doesn’t block lenders. It tells them to confirm it’s really you before they approve credit. In the US it’s free and lasts a year, and you only need to contact one bureau because “the credit bureau you contact must tell the other two.” If your identity has already been stolen, an extended alert lasts seven years.
In Canada, a fraud alert is the main tool, and you have to contact both bureaus yourself. Service Canada lists Equifax Canada at 1-800-465-7166 and TransUnion Canada at 1-800-663-9980, and notes “there may be a fee.”
3. Lock down your tax and benefits accounts
US: An exposed SSN is all someone needs to file a fake tax return and collect your refund. The IRS Identity Protection PIN is “a six-digit number that prevents someone else from filing a tax return using your Social Security number.” Anyone with an SSN or ITIN who can verify their identity can get one, fastest through an IRS online account. If you can’t verify online and your adjusted gross income is under US$84,000 (US$168,000 for joint filers), you can apply with Form 15227. A new PIN is issued every year.
While you’re at it, sign in to or create your my Social Security account and check the earnings record for jobs you never had.
Canada: SIN fraud often shows up as employment fraud: someone works under your number, and their income lands on your tax file. Service Canada says to watch for unfamiliar employment records in My Service Canada Account. If you suspect misuse, the CRA can give you a list of every employer that issued T4 slips under your SIN in the past three years (1-800-959-8281).
4. Check Have I Been Pwned for what else leaked
Breaches that expose ID numbers usually expose email addresses too, and email is how attackers get into everything else. Have I Been Pwned is a free service that “aggregates breaches and enables people to assess where their personal data has been exposed.” It searches by email address, not SSN or SIN. Sign up for its notifications so you hear about the next breach from the service and not from a stranger.
5. Move email and banking to passkeys or app-based 2FA

Your email account is the one that can reset all the others, so secure it first, then your bank. The FTC ranks the options: text message codes are the weakest because of SIM-swap attacks, authenticator apps are safer, and hardware security keys are “the strongest method”. Where a site offers passkeys, use them. The FIDO Alliance, the industry group behind the standard, calls them “phishing resistant and secure by design.” A thief who has your SSN and a reused password can’t get past a passkey.
6. Pull your reports and read your statements
Freezes and alerts stop new accounts. They do nothing about the accounts you already have. Americans can get free reports at AnnualCreditReport.com, which the SSA also recommends checking periodically. Canadians can access both bureau reports online for free. Look for accounts you didn’t open and inquiries you didn’t make. Then check card and bank statements every month for charges you don’t recognize, small ones included.
7. If it’s been misused, report it the official way
US: Report it at IdentityTheft.gov, the FTC’s site, or call 1-877-438-4338. You’ll get a step-by-step recovery plan. If someone filed taxes in your name, the SSA’s guidance says to also contact the IRS at 1-800-908-4490.
Canada: File a police report and keep the file number. Then report to the Canadian Anti-Fraud Centre online or at 1-888-495-8501 (weekdays, 10 a.m. to 4:45 p.m. ET). The CAFC also tells victims to flag their accounts, change their passwords, and report to both Equifax and TransUnion.
8. Learn to spot fake breach letters
A breach is an opening for scammers too, and plenty of follow-up messages are fake. A real notice explains what happened and what you can do. It doesn’t ask you to confirm your number over the phone. “The IRS will never ask for your IP PIN,” the agency says, and calls, emails or texts asking for one “are scams.” Service Canada warns about messages claiming your SIN is “compromised” or about to be locked or cancelled, and says never to give your SIN by phone “unless you made the call.”
If a letter offers free credit monitoring, don’t use its links or phone numbers. Find the company’s official site yourself and sign up there. The CAFC adds one more warning. Fraudsters often go after victims “a second or third time with the promise of recovering money.”
Sources
- FTC: Data Breach Response, A Guide for Business (model letter)
- TechCrunch: Hackers stole millions of US military personnel records during months-long data breach
- SSA: Identity Theft and Your Social Security Number (EN-05-10064)
- Service Canada: SIN fraud, misuse and data breaches
- FTC Consumer Advice: What To Know About Credit Freezes and Fraud Alerts
- FCAC: Checking your credit report for errors and fraud
- FCAC: Getting your credit report and credit score
- IRS: Get an Identity Protection PIN
- SSA: my Social Security
- Have I Been Pwned: FAQs
Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.
Latest from prompt/power
- Thomson Reuters Won the First AI Training Appeal. Footnote 7 Is the CatchOct 7
- The Family Safe Word: How to Beat AI Voice-Clone Emergency ScamsOct 7
- Reflection AI’s Beam, Explained: The 501B Open-Weight Model Aimed at ChinaOct 7
- Apple’s Oct. 13 Event Rumour, Plus iPhone Duo Pre-Order Dates for CanadaOct 7
- Why Grindr Is Paying US$250M for Calgary PrEP Clinic FreddieOct 7
Leave a Reply