
Eighty percent of U.S. consumers received at least one data breach notice in the past year, and nearly 40% got three to five separate ones, according to the Identity Theft Resource Center’s 2025 consumer survey.
Yet 46% of people who received a notice did nothing about it, not from carelessness but because they felt there was genuinely nothing useful they could do.
Table of Contents
Why Most Breach Notices Produce a Shrug, Not Action
The notices themselves are part of the problem. The same ITRC survey found that 70% of breach notices in 2025 gave no meaningful information about how the breach actually happened, up from 65% in 2024 and 45% in 2023.
“Personal information may have been affected” satisfies a legal minimum. It tells the reader almost nothing about what to do next.
A password and a Social Security number carry very different levels of urgency. Without knowing which was exposed, a reader has no real way to judge how seriously to take the notice.
That vagueness shows up directly in why people disengage. Among those who took no action, notification fatigue and a sense of helplessness were the two most common reasons cited, ahead of simply doubting the notice was legitimate.
What an Actual Action Plan Requires
A workable response starts with specifics the original notice usually withholds: exactly which category of data was exposed, and where else that specific piece of information might already be circulating.
That’s the gap PureVPN’s Identity theft protection is built to close. It runs continuous scans against breach databases, data broker listings, and dark web sources rather than depending on the breached company’s own disclosure.
It also separates what it finds by severity. Social Security numbers, dates of birth, and home addresses are flagged as high-risk, distinct from lower-risk items like an old password or a spam-linked email.
That severity rating is the missing piece from most breach notices. Instead of one generic warning, a reader gets an exposure report showing exactly what surfaced and a risk score attached to it, updated as new matches appear rather than delivered once and forgotten.
Because the scanning runs continuously, it also catches exposure that has nothing to do with a single headline breach: older leaks, data broker listings, and dark web postings that never generated a notice at all. A one-time notice becomes an ongoing risk picture instead.
The Part Most People Still Get Wrong Even When They Do Act
Even people who respond to a breach notice often fix the wrong thing. Bitwarden’s 2025 World Password Day survey found that 59% of Gen Z respondents recycle an existing password, with minor tweaks, when updating an account after a company discloses a breach.
The habit isn’t rare or generational. A separate analysis of 19 billion breached passwords found that 94% were reused or duplicated across multiple accounts, according to Cybernews’ 2025 research.
The gap isn’t awareness, either. In a separate 2025 survey, 91% of workers said they understood the risks of reusing passwords, yet 66% admitted doing it anyway, according to 1Password’s enterprise research. Knowing the risk and having a fast way to fix it are two different things.
That’s the specific friction a password manager is built to remove. PureVPN’s password manager generates a fully unique password per account and fills it in automatically, so replacing a compromised login takes less effort than typing a memorable variant would.
It also runs its own check across a person’s saved logins, flagging which ones are weak, reused, or duplicated elsewhere in the vault. That turns “change your password” from a vague instruction into a specific, visible list of accounts that actually need attention.
What the Actual Plan Looks Like
A real response to a breach notice looks like three specific steps, not one vague one.
- Confirm exactly what category of data was exposed, not just that “something” was. An exposure report does this; a generic notice usually doesn’t.
- Replace the affected password with a fully unique one, not a variation of the old one. A password manager makes the unique option the fast option instead of the slow one.
- Check whether that same password already shows up anywhere else in use, especially on financial or email accounts, where reuse carries the most downstream risk.
None of this asks for more concern than the reader already has. It asks for a notice specific enough to act on, and tools that make the correct response as easy as the cosmetic one.
That’s the real distance between a shrug and a plan: not attitude, but information.

