Straight answers on hard choicesLast filed Sep 8, 2026

Tech

A Breach Letter With a Deadline on It? What the Response Actually Costs, in Fees and Hours

The enrollment deadline on a breach notice is the company's schedule, not yours; the real cost sits in hours, and the expensive errors are the fast ones.

Tech||Bram Voskuijlen

The envelope is designed to be acted on. There is a date by which the offered monitoring must be activated, a code that expires, a toll-free number staffed by a vendor the sending company hired last week, and a paragraph explaining that the incident has been contained. Almost every design choice in that letter serves the sender's timeline, which is set by state attorney general filing requirements and by the contract with the monitoring provider, not by anything happening to your accounts. Reading the deadline as a measure of your own urgency is the first and most expensive mistake, because it moves you fast in the wrong direction.

The clock printed on the page belongs to the sender

By the time the letter reaches your mailbox, the exposure is usually weeks or months old. Forensic work takes time, counsel reviews the language, and the notice goes out on a schedule shaped by disclosure rules and insurer expectations. Whatever was going to happen with your data has either already started or is sitting in a file somebody may open next year. The ninety days in which you can claim the free monitoring is a procurement term. Treating it as an emergency window produces rushed enrollment, duplicate services, and a set of half-finished protective steps that leave you paying for coverage you already had through another breach.

The useful question is not how quickly you can respond but what specifically was taken, because that single fact determines whether your response costs an afternoon or spreads across a year. A card number is reissuable and the bank absorbs the work. A Social Security number, date of birth, and driver's license number together are permanent, and the response is correspondingly permanent: freezes that stay in place, a tax filing habit that changes, and records you keep for as long as you file returns. Most letters bury that distinction in a sentence beginning "the information involved may have included."

Where the money actually goes

The out-of-pocket fees are small and mostly optional. Credit freezes at the three nationwide reporting agencies cost nothing to place, lift, or remove. Replacing a driver's license carries the standard fee at your state's DMV, and a new passport costs what a passport costs. Certified mail for a dispute, notarization for a minor's freeze documentation, and copies of a police report round out the cash side, and for most households the total lands somewhere between nothing and a couple of hundred dollars. Paid identity monitoring, if you choose it after the free period lapses, is the one recurring line item, and it is genuinely optional.

The real cost is hours, and hours are what nobody budgets. Placing freezes across three agencies means three identity verifications, three PINs or online accounts, and at least one call because a verification fails against an old address. Add a fourth and fifth agency if you want the specialty bureaus that feed check-acceptance and tenant screening. Then the follow-through: pulling your credit reports, reading them line by line, adding an Identity Protection PIN to your tax filing, updating the payment method on every subscription tied to a reissued card. Six to ten hours is a realistic first pass for one adult, and it roughly doubles per additional family member.

What drives that number up is not the severity of the breach. It is the number of institutions you touch, the number of people in your household, and whether any of them cannot verify their own identity online. A retiree with a thin file, a teenager with no file at all, and anyone who recently moved all generate manual work: mailed copies of a birth certificate, a utility bill, a Social Security card. That is why the same notice costs one person an evening and another person four separate mornings spread over a month.

What changed recently, and why it lowered the price of doing this well

Three things shifted, and together they make the unhurried response cheaper than the fast one used to be. Freezes became free nationwide under federal law, which removed the per-agency fees that once made people ration protection or choose the weaker fraud alert instead. The IRS opened its Identity Protection PIN program beyond confirmed victims, so any taxpayer who can verify identity may now request one, which converts the most costly downstream fraud, a fraudulent return filed against your Social Security number, into a solved problem rather than a nine-month wait for a refund. And the Federal Trade Commission, which is responsible for consumer identity theft reporting, maintains the recovery process that generates the affidavit institutions ask for.

The third change is who is writing to you. A growing share of notices come from companies you never chose: a file transfer vendor, a claims processor, a background screening firm, a debt collector holding an old account. That reshapes the economics of your response, because there is no relationship to lean on, no account to close, and no leverage to exercise. Your protection has to sit at the credit bureaus and the IRS rather than with the sender, which is precisely why the freeze-and-PIN combination has become the substance of a good response and the enrollment code has become the decoration.

The costly errors are all the fast ones

People who move quickly tend to make four moves that cost money later. They enroll through a link or a phone number they did not verify, because breach notices are impersonated constantly and a letter you were expecting is the easiest thing in the world to fake. They place freezes without recording the PINs, then pay for expedited handling or lose a mortgage rate lock while a lift is sorted out. They close a long-held credit card, shortening their credit history for no protective gain. And they stack two or three monitoring subscriptions from separate breaches, paying twice for the same alerts.

None of that comes from carelessness. It comes from a letter engineered to feel like an alarm, arriving on a Tuesday, read standing up. The counter-move is a sequence rather than a sprint: verify the sender independently, write down exactly which data elements the notice lists, place freezes and store the credentials somewhere durable, request the tax PIN, then decide about monitoring last, with the free period as a bonus rather than a deadline. Spread across two evenings, that costs almost nothing and holds for years.

A breach notice is a document about someone else's incident that quietly transfers a small administrative project to you. The project is finite, the fees are modest, and the protections available now are stronger and cheaper than they were even a few years ago. What it asks for is an hour of attention at a time of your choosing, which is the one thing the letter's design is least equipped to request.

More from this edition