Skip to content
All guides

Security guide

Breach Exposure Checks vs Identity Theft Protection: What Each One Actually Covers

One answers whether your data leaked; the other answers whether someone is using it. Which you need depends on which fields were exposed — and neither prevents anything.

Written by
Cengiz YILMAZ
Updated
Breach Exposure Checks vs Identity Theft Protection: What Each One Actually Covers

Quick answer

Breach exposure checking answers "has an identifier of mine appeared in leaked data?" Identity theft protection answers "is someone using my identity to open accounts or borrow money?" They watch different things and overlap barely at all. Which you need depends on what was exposed: credentials point at the first, government identifiers and financial data point at the second. Neither prevents anything — both tell you after the fact.

Two products, two questions

Breach exposure checking

The question: does this email address, username or phone number appear in known breach datasets?

What it watches: collections of data taken from breached companies.

What a finding tells you: a service you used lost data containing your identifier, and possibly a credential.

What you do about it: change passwords, enable multi-factor authentication, expect phishing.

Cost: free to low. Many checks cost nothing.

Identity theft protection

The question: is someone using my personal information to impersonate me financially?

What it watches: credit files and applications, new account openings, sometimes public records, court records, payday lending databases and change-of-address filings. Usually bundled with breach-data scanning as a secondary feature.

What a finding tells you: an account or credit application appeared in your name that you did not initiate.

What you do about it: dispute it, freeze your credit file, follow a formal recovery process.

Cost: typically a monthly subscription.

The distinction in one line: breach checking looks at data that leaked out; identity monitoring looks at what is being done with it.

Which one your situation calls for

The deciding input is which fields were exposed. If you do not know, which fields were exposed explains how to read a notification.

Passwords or credentials exposed. This is a credential problem. Change the password everywhere it was reused and enable MFA. Identity monitoring will not help — nobody opens a credit card with your Spotify password.

Email address, username or phone only. Mild. Expect phishing. Neither product is really required; scepticism about unexpected messages does more.

Government identifier, date of birth, or name plus address plus date of birth together. This is the identity-theft-relevant combination, because it is what identity verification checks. A credit freeze is the strongest single response where your jurisdiction offers one, and it is usually free. Monitoring is a reasonable addition; it is not a substitute for the freeze.

Full payment card details. Neither product. Call your bank and get the card replaced.

Nothing exposed that you know of. Preventive controls only, which cost nothing.

What neither of them does

Worth being blunt, because both categories are marketed as protection.

Neither prevents anything. Both are detective controls. They tell you something has already happened. The preventive controls — unique passwords, MFA, a credit freeze — are the ones that stop the event, and all three are free.

Neither removes your data from anywhere. Once a dataset circulates it exists in copies nobody controls. Services promising deletion from breach data or "the dark web" are selling something undeliverable.

Neither sees everything. Breach services hold what they hold. Identity monitoring typically covers a subset of credit bureaux and databases, and an account opened somewhere outside that subset does not appear.

Neither stops the fraud in progress. They alert; you act. If the alert arrives on a Friday evening, the gap is yours.

The parts of identity protection worth paying for

If you are evaluating a subscription, the components differ a lot in value.

Credit monitoring is the core. Useful, and in some jurisdictions available free from bureaux or via your bank. Check what you already have before paying twice.

Credit freeze — usually not a product feature at all, because you can do it yourself, generally for free, and it is stronger than monitoring: monitoring tells you a credit file was accessed, a freeze prevents it. In the US the FTC documents freezes and fraud alerts; other jurisdictions have equivalents under other names, and some have none.

Restoration services — help from someone who has done it before, with the paperwork and phone calls after identity theft. This is often the genuinely valuable part, because recovery is administratively grim and slow. In the US the FTC's IdentityTheft.gov provides the official process and recovery plan for free, which is a fair benchmark for what you are paying to avoid doing yourself.

Insurance — usually reimburses documented costs of recovery rather than stolen funds, and typically excludes a lot. Read what is actually covered before treating it as meaningful. This article makes no guarantee about any policy; the terms are the terms.

Dark web scanning — commonly bundled, commonly the same breach datasets a free checker uses under a more alarming name. What dark web monitoring can and cannot tell you covers this.

A note on jurisdiction

Most writing on identity theft assumes the US credit system: three bureaux, freezes, fraud alerts, IdentityTheft.gov. Elsewhere the picture differs — different bureaux, different rights, sometimes no freeze mechanism at all, and different regulators handling data protection complaints.

Two things generalise. First, the preventive controls do: unique passwords, MFA, and scepticism about unexpected contact work everywhere. Second, the decision rule does: credentials exposed points at credential remediation; permanent identifiers exposed points at whatever financial-identity protection your jurisdiction provides. Look up the local mechanism rather than assuming the American one exists where you are.

Where Compromised sits

Precisely, because vague capability language is what this article is arguing against.

Compromised does breach exposure checking. You submit an identifier, the server queries a configured breach intelligence provider, and you get a point-in-time answer about whether it appears in known breach data, along with the categories of data involved.

It does not do identity theft protection. No credit monitoring, no financial account monitoring, no insurance, no restoration service. It also has no continuous monitoring, no saved alerting and no domain-wide scanning — searches are point-in-time.

If your exposure is credential-shaped, that is the relevant tool and you can check whether an identifier appears in known breach data. If your exposure is identity-shaped, you need a credit freeze and, possibly, a monitoring product — and it would be dishonest to point you here instead.

Frequently asked questions

My bank offered free identity monitoring after a breach. Should I take it?

If it costs nothing, yes — a free detective control has no downside beyond the alerts. Do not let it substitute for a credit freeze, which is stronger and usually also free.

Is identity theft protection worth paying for?

It depends on which data was exposed and what you already have. If government identifiers or financial data were involved and you have no free monitoring, it is defensible. If only credentials leaked, the money is better spent on nothing at all — the fixes are free.

Can I do what these services do myself?

Largely yes, for the detective part: check breach exposure with a free checker, freeze your credit file, review statements, and set up whatever alerts your bank offers. What you cannot easily replicate is the restoration help, which is where a subscription earns its keep if you ever need it.

Which should I do first after a breach?

Credential remediation, every time — it is free, immediate, and closes the most likely path. Then decide whether the exposed fields justify the identity side. The breach exposure guide has the full sequence, and how often to check covers what to do afterwards.