About this tool
Build an employee response plan from the data categories in your company's breach notice, scored only against the steps that actually apply.
The Employer Data Breach Employee Checklist turns the data categories listed in your company's breach notice into the specific steps that apply to you, then scores your progress against those steps only. Tick what the notice says was involved — payroll bank details, a tax or national ID number, health plan data, ID scans, work credentials — and the plan reshapes: payroll banking leads to salary-diversion defences, a tax number to credit and refund fraud defences, credentials to password-reuse work. It also rates the severity of the notice itself, because the monitoring an employer offers is a reporting service, not protection.
Open Employer Data Breach Employee Checklist on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Steps appear only when the data category that makes them relevant was actually involved.
The percentage is calculated over applicable steps, so ticks on irrelevant advice never inflate it.
One score rates how bad the breach is, another rates how far you have got — they are different questions.
Ask HR in writing which fields were involved, whether your record specifically was in the dataset, and whether the data left the network or was only accessible. Notices are deliberately broad, and the rest of your response depends entirely on that answer.
No. Monitoring reports fraud after it happens; it does not prevent an account being opened. Take it, because it usually has an enrolment deadline and costs you nothing, but pair it with a credit freeze if a tax or national ID number was exposed.
Through payroll diversion: the attacker emails payroll posing as you with new bank details, timed just before pay day. Ask payroll to confirm they call the employee on a number already on file before changing any account, and check the account shown in the self-service portal before the next two pay runs.
Yes, wherever you reused the work password or a variation of it. Credential stuffing replays a leaked address and password against banks, email and shopping sites automatically, often within hours of a dump circulating. If you are considering a claim or compensation, take legal advice before signing any release.