Recommended Free Tools
After a data breach, scammers may use stolen details or the breach itself to make fake emails and texts seem believable. Don’t trust a message just because it names the affected company or includes information about you. Verify it through a channel you find independently, and never use a suspicious message’s link, phone number, QR code, or attachment to do so.
Why phishing attempts may follow a breach
Phishing is a deceptive message designed to get you to reveal information, visit a malicious site, open a harmful attachment, or give an attacker access. A breach can give scammers personal details that make an impersonation feel timely or authentic.
In a September 2017 alert about the Equifax breach, CISA relayed warnings that scam emails or calls might claim to be from Equifax and that phishing volume often increases after major breaches. The alert also noted that stolen data can make messages more credible. This is a historical warning, not a current measurement or a guarantee that every breach will lead to a surge: CISA’s archived Equifax alert.
How to recognize a suspicious message
Check the message for several clues rather than relying on its logo, tone, or apparent knowledge of your situation. CISA’s 2024 phishing tip sheet highlights:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- A sender address that does not match the organization the message claims to represent.
- A shortened or otherwise untrusted link.
- Urgent or emotionally pressuring language that pushes you to act immediately.
- A request for personal, account, or financial information.
- An unexpected attachment.
- Poor writing, misspellings, or other inconsistencies. CISA notes that poor writing is less common, so polished wording does not prove a message is genuine.
A detail that is correct—such as your name, a recent transaction, or the company involved in a breach—is not proof of identity. Scammers may have obtained enough information to personalize a convincing impersonation. See CISA’s Avoid Phishing Scams with Three Simple Tips.
How to verify a breach notice safely
- Stop before acting. Don’t reply, click a link, open an attachment, scan a QR code, or call a number supplied only in the message.
- Open a trusted route yourself. Use the organization’s app, type its known web address into your browser, or find its official website independently. Look there for a notice or instructions about the incident.
- Contact the organization using independently found details. Use a phone number on an official website or on your card—not a number in the suspicious message. CISA’s Phishing Tip Card recommends contacting the company directly by phone when in doubt.
- Follow the verified incident instructions. If the organization confirms a breach or account issue, use its official guidance for affected customers rather than following directions in an unverified message.
What to do with a suspicious email or text
- Don’t reply, click any link, open an attachment, or use an unsubscribe link.
- Report the message with your email or messaging service’s spam or phishing reporting feature.
- If it impersonates a trusted organization, alert that organization through contact details found on its official website.
- Delete the message after reporting. Keep a copy only if it is needed for an official complaint or an account investigation; don’t forward it to other people as a warning.
CISA’s 2024 tip sheet puts the handling advice plainly: “Delete the message. Don’t reply or click on any attachment or link, including any ‘unsubscribe’ link.”
Rank #2
- FIDO2 + FIDO U2F certified and supported USB security key
- Secured by NXP semiconductors
- Works in every browser and application without installing any drivers
- Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
If you clicked a link or shared information
Act promptly, but don’t assume that a single step can undo data exposure or prevent every misuse. Use contact details you find independently, not those in the suspicious message.
- If a bank, store, or card account may be affected, contact the institution that owns it through a trusted channel and follow its instructions.
- If you entered a password, change it for the affected service and for any other account where you reused it. Use a different computer that you control to make the changes, as CISA advises. Set a unique password for each account.
- If you suspect identity theft, use the official U.S. government recovery resource IdentityTheft.gov.
- If the breached organization has issued a notice, contact it using its official website or another independently verified channel and follow its incident-specific steps.
CISA’s device and account recovery guidance advises contacting the affected bank, store, or credit-card company and changing passwords from a different computer you control.
Rank #3
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
Make important accounts harder to take over
Turn on multifactor authentication
Multifactor authentication (MFA) requires more than one way to verify your identity at sign-in. Enable it where available, prioritizing email and financial accounts; email access can affect password recovery for other services. Check whether your email provider, bank, and healthcare provider offer MFA. CISA explains the basics in Turn On MFA.
Use unique passwords
Use a strong, different password for each account. A password manager can help you create and manage unique credentials. If a password was exposed in a breach—or reused on an affected account—change it on the affected and reused accounts rather than relying on an arbitrary schedule. CISA’s MFA guidance also discusses password protection.
Rank #4
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Consider a security key if your accounts support it
A physical FIDO security key is one possible MFA method, and CISA identifies physical security keys as an option for phishing-resistant MFA. Before choosing one, check that each account you need to protect supports the key and that you have a workable recovery method if it is lost. CISA’s MFA guidance for businesses describes security keys; it does not establish compatibility across consumer services or rank specific devices.
Quick Recap
Best Value
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →




