The steps below are the ones that actually reduce your risk. None of them costs anything.
Change your Quarterdeck password
Your password was among the data copied, so this one is not optional. See Do I need to change my Quarterdeck password?
More importantly, change it anywhere else you have used the same one. Whoever holds this data also holds your email address, and that combination is what makes an attempt on your other accounts worth trying.
Watch for accounts opened in your name
Identity details cannot be reissued the way a card can. Look out for letters, emails or calls about accounts, loans or credit applications you did not make. If something arrives that you do not recognise, follow it up rather than filing it.
If you are weighing up whether your passport itself needs replacing, that question has its own answer: Do I need to replace my passport?
Put a marker on your credit file
Most countries have credit reference agencies or credit bureaus that will place a fraud alert or a freeze on your file at no charge. A freeze stops most new credit being opened in your name until you lift it. The bodies differ by country, so search for the ones where you live, or ask us and we will point you to them.
This is worth doing wherever you are tax resident, not only where you worked.
If you invoice for your work, protect the payment route
This applies to fewer people but matters more to them. If your bank details were among the records copied, the realistic risk is not theft from your account — it is someone telling a client that your details have changed. See My bank details were included — what should I do?
Even if your bank details were not involved, it is worth telling anyone who pays you regularly to verify by voice before changing where they send money.
Slow down on unexpected contact
Expect more convincing approaches than usual, by email, message and phone. Someone referencing your assignments, the trips you worked or your dates is not thereby proving they are us. Verify independently before acting, and never through a link or number supplied in the message itself.
We are not making outbound calls about this incident, so any call claiming to be Quarterdeck about it is not us.
Your documents are not the exposure here
Your uploaded passport copies, licences and certificates were not taken. That is the reassuring part of this, and the reasoning is set out in Were my passport or licence documents taken?
If something does happen
If you see anything that looks like misuse of your information, tell us at the notice address on your security notice and we will look at your case individually rather than sending you the general guidance again.
