How to Report a Social Security Data Breach
If you believe your Social Security number or personal information held by the Social Security Administration has been exposed in a breach, report it to the Office of Inspector General (OIG) at the SSA. You can file a report online through their fraud hotline at oig.ssa.gov or call 1-800-269-0271. Have your Social Security number, the date you discovered the breach, and any documentation of the exposure ready when you contact them.
The OIG investigates reports of data theft, unauthorized access, and security failures within Social Security systems. When you report, describe what happened as specifically as you can — for example, whether you received a notice from SSA, discovered unauthorized activity on your account, or learned about the breach through news coverage. The OIG will log your report and may contact you for more details.
You can also report suspected breaches to the Federal Trade Commission (FTC) at reportidentitytheft.ftc.gov. The FTC maintains a database of identity theft reports and shares patterns with law enforcement. Reporting to both agencies creates a record and helps authorities identify whether the breach is widespread.
Key Takeaways
- Report suspected Social Security data breaches to the SSA Office of Inspector General by phone at 1-800-269-0271 or online at oig.ssa.gov.
- You can also file a report with the Federal Trade Commission at reportidentitytheft.ftc.gov to create an identity theft record.
- Provide specific details about how you discovered the breach and when you first noticed it.
- Monitor your credit reports and Social Security account for unauthorized activity after reporting a breach.
- A whistleblower who works at SSA and reports internal security failures may have additional protections under federal whistleblower laws.
What Happens After You Report
The OIG will assign your report a case number. Keep this number for your records. The agency does not always contact reporters with updates, especially if the investigation is ongoing. You can follow up by calling the OIG hotline and referencing your case number to ask about the status.
If the OIG determines that a breach occurred, they may issue a public notice and coordinate with SSA to notify affected individuals. SSA typically sends breach notification letters to people whose information was exposed. These letters explain what happened, what information was compromised, and what steps you should take to protect yourself.
Protecting Your Social Security Number After a Breach
Once your Social Security number is exposed, you cannot change it. Instead, focus on monitoring for misuse. Request your free credit reports from all three bureaus — Equifax, Experian, and TransUnion — at annualcreditreport.com. Check for accounts you did not open and inquiries you did not authorize.
Consider placing a fraud alert or credit freeze on your accounts. A fraud alert tells creditors to verify your identity before opening new accounts in your name. You can request one free fraud alert by contacting any of the three credit bureaus; they will notify the others. A credit freeze prevents creditors from accessing your credit report entirely, which stops most fraudulent account openings. You can place a freeze for free at each bureau's website.
Monitor your Social Security account online at ssa.gov/myaccount. Create an account if you do not have one already. This lets you check your earnings record, see if anyone has filed taxes using your number, and verify that no one has applied for benefits under your name.
If You Work at Social Security and Witnessed a Breach
Employees or contractors who discover security failures, data mishandling, or breaches at SSA have legal protections when reporting internally or to outside authorities. Federal whistleblower laws protect you from retaliation for reporting violations of law, gross mismanagement, or abuse of authority.
You can report to your supervisor, SSA's Office of Inspector General, or the Office of Special Counsel (OSC), which handles federal employee whistleblower complaints. The OSC can investigate retaliation and seek corrective action if you face negative consequences for reporting. Contact the OSC at osc.gov or 1-800-572-2249.
Document what you observed — dates, people involved, systems affected, and what you reported and to whom. Keep copies of emails, memos, or other records. This documentation protects you if retaliation occurs and helps investigators understand the timeline.
Understanding SSA's Data Security Responsibilities
The Social Security Administration is required by federal law to protect the personal information it holds. This includes your Social Security number, earnings history, address, and benefit payment details. SSA must implement security measures, limit access to sensitive data, and notify people when breaches occur.
When breaches happen, they are often caused by employee error, phishing attacks, stolen credentials, or outdated security systems. SSA publishes breach notifications on its website and in news releases. You can check ssa.gov for official announcements about data security incidents.
What Information Is Usually Exposed in SSA Breaches
Social Security breaches typically expose Social Security numbers, names, dates of birth, and sometimes addresses or benefit payment information. The scope depends on what system was compromised and how long the breach went undetected.
Criminals use exposed Social Security numbers to commit identity theft, file fraudulent tax returns, open credit accounts, or explore for government benefits. This is why monitoring your accounts and credit reports is critical after a breach. The sooner you spot unauthorized activity, the easier it is to stop and correct.
Frequently Asked Questions
Can I change my Social Security number after a breach?
The Social Security Administration rarely issues new numbers. You must show that you are experiencing ongoing identity theft or harassment directly related to your current number. Contact your local Social Security office to discuss whether you meet the criteria. Most people manage breach risk through monitoring and fraud protection instead.
How long does it take for the OIG to investigate a breach report?
Investigation timelines vary widely depending on the complexity and scope of the breach. Some cases take months; others take longer. The OIG does not always provide updates to individual reporters. You can call the hotline with your case number to ask about status, but do not expect frequent communication.
What if I see my Social Security number being used fraudulently?
Report it when ready to the Federal Trade Commission at reportidentitytheft.ftc.gov, place a fraud alert on your credit reports, and contact the companies where fraud occurred. If someone filed taxes using your number, contact the IRS at 1-800-908-4490. Report the fraud to SSA's OIG as well so it is part of the breach investigation record.
Do I need a lawyer to report a data breach?
No. You can report breaches to the OIG and FTC yourself at no cost. If you are an SSA employee reporting internal security failures and face retaliation, you may want to consult an employment attorney, but initial reporting to the OSC and OIG does not require legal representation.
Will SSA pay for credit monitoring after a breach?
SSA does not routinely offer free credit monitoring to breach victims. However, some breaches trigger settlements or court orders that include monitoring services. Check any official breach notification letter from SSA for information about what is being offered. You can also purchase credit monitoring independently or use free tools like credit freeze and fraud alerts.