The Social Security Administration confirmed a data breach in 2022 that exposed personal information of millions of people
In June 2021, the Social Security Administration (SSA) discovered that someone had accessed a non-public SSA website using stolen credentials. The breach exposed the personal information of approximately 8.8 million people — mostly children and retirees. The exposed data included names, dates of birth, Social Security numbers, and in some cases, mothers' maiden names.
The SSA did not publicly announce the breach until November 2022, more than a year after discovery. The delay meant many people whose information was compromised did not know to monitor their accounts or take protective steps for months. The SSA later stated that the stolen credentials came from a third-party vendor, not from SSA systems themselves.
The breach affected people who had never created an online my Social Security account. The compromised website was an internal SSA tool used for identity verification, not the public-facing portal where people manage their own benefits. This distinction matters because it means the breach exposed people's information even if they had never registered online.
Key Takeaways
- The 2021 SSA data breach exposed names, dates of birth, Social Security numbers, and sometimes mothers' maiden names for approximately 8.8 million people.
- The breach affected people who had never created a my Social Security account, because the compromised system was an internal SSA tool, not the public portal.
- The SSA did not announce the breach publicly until November 2022, leaving people unaware for over a year that their information had been exposed.
- If your information was in the breach, you can monitor your credit reports for free and place a fraud alert or credit freeze with the three major credit bureaus.
- The SSA offered free credit monitoring and identity theft protection services to affected individuals, though enrollment required action on your part.
Who was affected by the 2021 breach
The breach primarily affected children and retirees. The SSA later explained that the compromised website was used to verify identities for people explore for benefits, which skewed the exposed population toward those age groups. However, people of any age whose information was in SSA databases could have been affected if they had ever applied for a Social Security number or benefits.
The SSA did not release a complete list of affected individuals. Instead, the agency notified people through mail if their information was confirmed to be in the breach. If you received a letter from the SSA about the 2021 breach, your information was exposed. If you did not receive a letter and are unsure whether you were affected, you can contact the SSA directly at 1-800-772-1213 to ask.
What information was exposed and how it could be misused
The data stolen in the breach included names, dates of birth, Social Security numbers, and in some cases mothers' maiden names. This combination of information is valuable to identity thieves because it contains the core details needed to open fraudulent accounts, file false tax returns, or explore for loans in someone else's name.
Social Security numbers are particularly sensitive because they are used as a primary identifier across financial, medical, and government systems. A thief with your Social Security number and date of birth can attempt to open credit accounts, explore for government benefits, or commit tax fraud. Mothers' maiden names are often used as security questions on financial accounts, so their exposure increases the risk that a thief could reset passwords or gain account access.
The fact that the breach went unannounced for over a year meant that people whose information was exposed had no warning to take protective steps during the period when the stolen data was most likely to be actively used by criminals.
Steps to take if your information was in the breach
If you received a letter from the SSA confirming your information was in the breach, start by checking your credit reports. You can order free credit reports from all three major bureaus — Equifax, Experian, and TransUnion — at annualcreditreport.com. Review the reports carefully for accounts you did not open, inquiries you did not authorize, or other signs of fraud.
Next, consider placing a fraud alert or credit freeze with the three credit bureaus. A fraud alert tells lenders to verify your identity before opening new accounts in your name; it lasts one year and is free. A credit freeze prevents lenders from accessing your credit report entirely, which stops most fraudulent account openings; it is also free and lasts until you remove it. You only need to contact one bureau to place a fraud alert (it will notify the others), but you must contact each bureau separately to place a freeze.
The SSA offered affected individuals free credit monitoring and identity theft protection services through a third-party vendor. If you were notified of the breach, your letter included information about how to enroll in these services. Enrollment was not automatic, so you had to take action to sign up. If you received a letter and did not enroll, you may still be able to do so by contacting the vendor listed in your notification letter.
Monitoring your accounts and credit after the breach
After a data breach, ongoing monitoring is more important than a one-time check. Review your credit card and bank statements monthly for charges you do not recognize. Check your credit reports at least once a year, even after the initial review. Many people affected by breaches do not see fraudulent activity for months or even years, so continued vigilance matters.
If you notice suspicious activity, contact the relevant financial institution or creditor when ready. If you discover fraudulent accounts opened in your name, file a report with the Federal Trade Commission (FTC) at identitytheft.gov. The FTC provides a recovery plan and documentation that you can use when disputing fraudulent accounts with creditors and credit bureaus.
You can also set up account alerts with your banks and credit card companies. Many financial institutions offer alerts when new accounts are opened, large purchases are made, or password changes occur. These alerts can help you catch fraud quickly.
How the SSA responded and what changed
After the breach was discovered, the SSA took the compromised website offline and revoked the stolen credentials. The agency also strengthened security on its identity verification systems and required multi-factor authentication for access to sensitive tools. However, the delayed public notification drew criticism from lawmakers and privacy advocates, who argued that people should have been informed much sooner.
The breach highlighted vulnerabilities in how the SSA protects personal information, particularly the reliance on third-party vendors for critical systems. The SSA has stated that it is implementing additional security measures, but the specifics of those measures and their timeline have not been fully detailed publicly.
The 2021 breach was not the first time the SSA's systems have been compromised. In 2015, hackers accessed the my Social Security portal and stole information from approximately 21.8 million people. The pattern of breaches has raised ongoing questions about the SSA's cybersecurity practices and the adequacy of resources devoted to protecting sensitive data.
Your rights if you experience identity theft related to the breach
If you discover that someone has used your information to open accounts, file taxes, or commit fraud in your name, you have legal rights to dispute the fraudulent activity. You can file a dispute with credit bureaus to have fraudulent accounts removed from your credit report. You can also contact creditors directly to report fraud and request that accounts be closed.
The FTC's identitytheft.gov website provides a step-by-step recovery plan tailored to your situation. The plan includes templates for letters to send to creditors and credit bureaus, guidance on filing a police report, and information about your rights under the Fair Credit Reporting Act and the Fair and Accurate Credit Transactions (FACT) Act.
If you are a victim of identity theft, you may also be may have access to to free credit monitoring or other remedies depending on the circumstances. Some states have laws requiring companies that experience breaches to provide affected individuals with credit monitoring services at no cost.
Frequently Asked Questions
How do I know if my information was in the 2021 Social Security breach?
The SSA mailed letters to people whose information was confirmed to be in the breach. If you received a letter from the SSA about the 2021 breach, your information was exposed. If you are unsure, you can contact the SSA at 1-800-772-1213 to ask whether your information was affected.
Can I sue the Social Security Administration for the breach?
The SSA is a federal agency, and federal agencies have limited liability for data breaches under the Federal Tort Claims Act. However, you may have other remedies available depending on your state's laws and the specific circumstances. Consulting with an attorney who specializes in privacy law can help you understand your options.
Will the SSA pay for credit monitoring if I was affected?
The SSA offered free credit monitoring and identity theft protection services to affected individuals through a third-party vendor. Enrollment was not automatic — you had to take action to sign up. If you received a notification letter and did not enroll, contact the vendor listed in your letter to see if you can still register.
What should I do if I see fraudulent charges on my credit report?
Contact the creditor or financial institution that issued the fraudulent account when ready to report the fraud and request that the account be closed. Then file a dispute with the credit bureau reporting the account. You can also file a report with the FTC at identitytheft.gov, which provides a recovery plan and documentation to support your disputes.
Is my Social Security number still at risk if it was in the 2021 breach?
Your Social Security number does not expire or change, so it remains at risk indefinitely once it has been compromised. This is why ongoing monitoring of your credit and accounts is important. A credit freeze can prevent most fraudulent account openings, even if your number is used by criminals.