Security

Your Account Was in a Data Breach — What to Do Right Now

Data breaches happen constantly. If your email or password has been leaked, acting quickly can prevent attackers from using those credentials before you do.

Step 1: Find Out What Was Leaked

Visit haveibeenpwned.com — enter your email address to see which breaches you've been included in and what data was exposed (passwords, phone numbers, addresses, etc.).

Step 2: Change the Leaked Password Immediately

Change your password on the breached service first. Use a unique, randomly generated password — at least 16 characters. Do not reuse this password anywhere.

Step 3: Check for Reused Passwords

If you used the same password on any other service, change it there too — immediately. Credential stuffing attacks try leaked credentials on hundreds of services within hours of a breach becoming available.

This is the primary way one breach becomes ten compromised accounts.

Step 4: Enable 2FA on the Affected Accounts

If you haven't already, enable 2FA on every account where you've changed the password. Use an authenticator app, not SMS. Use 2faco.com to generate codes instantly if you don't have an app.

Step 5: Check Your Email Inbox for Suspicious Activity

Look for password reset emails you didn't request, new device login notifications, or emails confirming changes you didn't make. If you find any, the affected accounts need immediate attention.

Step 6: Review Connected Apps and Sessions

On major services, go to Settings → Security → Active sessions or Third-party apps. Sign out all devices except your current one. Revoke access for apps you don't recognise.

Step 7: Set Up a Password Manager

The root cause of credential stuffing working is password reuse. A password manager generates and stores unique passwords for every service, making you immune to this class of attack.

Going Forward

  • ✓ Unique password for every account
  • ✓ 2FA enabled on all important accounts
  • ✓ Password manager in use
  • ✓ Set up breach alerts at haveibeenpwned.com to be notified of future breaches

How to Find Out If You Have Been Breached

The fastest way to check is haveibeenpwned.com — enter your email address and it shows which known data breaches included your credentials. Check every email address you use. For passwords specifically, haveibeenpwned.com also lets you check if a specific password has appeared in a breach (it uses a k-anonymity method so your actual password is never transmitted). Many password managers now automatically alert you when a saved password appears in a breach database.

Immediate Steps After a Breach

First, change the password on the breached site immediately. Second, if you used the same password anywhere else, change it on every site where you used it — check your password manager for reuse. Third, if the breach included payment information, contact your bank or card issuer and ask about monitoring or card replacement. Fourth, enable 2FA on the affected account if you have not already. Fifth, watch for phishing emails in the weeks following a breach — attackers often use stolen email addresses to craft targeted phishing messages.

Does 2FA Protect You After a Breach?

If your password was leaked but your 2FA is active, an attacker who tries to use the leaked password will be stopped at the 2FA verification step. They have the password but not the second factor. This is one of the clearest demonstrations of why 2FA matters — a breach of your password alone is not sufficient to access a 2FA-protected account. Enable 2FA now, before a breach happens, rather than scrambling to add it after.

Password Reuse — The Amplifier of Breach Damage

The reason data breaches cause so much downstream damage is password reuse. If you use the same password for 10 sites and one site is breached, attackers will test that password on the other nine within hours — this is called credential stuffing. Using a unique password for every account limits a breach to the single site that was compromised. A password manager makes this practical by remembering the unique passwords for you.

Long-Term Monitoring

Data breaches often go unreported for months. Set up free monitoring to catch future breaches early: sign up for alerts on haveibeenpwned.com (free for individual email addresses), enable breach alerts in your browser or password manager, and regularly check the account settings of your most critical services for any unrecognised sign-ins or changes. Early detection dramatically limits the damage from a breach.

Common Mistakes People Make After a Breach

One of the most common errors is changing the password on the breached site while leaving the same password active on other accounts — or worse, "updating" several accounts to one new shared password. Both give credential stuffing a fresh set of credentials to try. Another frequent mistake is assuming the danger is over once the password is changed; attackers often wait weeks or months after a breach before using leaked credentials, so continued monitoring matters.

People also overlook secondary data that was exposed. A breach that leaks your phone number and address enables targeted phishing and SIM-swap attempts, and leaked security-question answers can be used to reset passwords on other services. If the breach included answers to security questions or payment details, treat that data as compromised everywhere it was reused, and be especially suspicious of calls or texts that reference the breach while asking you to "verify" your identity — legitimate companies do not phone you to collect a code.

What Attackers Actually Do With Your Leaked Credentials

Leaked credentials are processed by automated tools within hours, not days. Bots run credential-stuffing lists against every major service, trying your email and password combinations in bulk; this is why a password you reuse on a forum can be tested against your bank within a day of a breach. The same data feeds targeted phishing — messages that quote your real password to look legitimate, or that impersonate the breached company and ask you to "confirm" account details.

Phone numbers and addresses from breaches enable SIM-swap attempts and smishing campaigns, while leaked security-question answers can be used to reset passwords elsewhere. Understanding the automation explains the urgency: the damage window is measured in hours, which is why the steps at the top of this article should happen the same day you learn about the breach.

If Financial Information Was Exposed

If the breach involved payment cards, contact your bank or card issuer and ask whether to replace the card or enable additional transaction monitoring. In many jurisdictions you can place a credit freeze with the three major bureaus — Equifax, Experian, and TransUnion in the United States — which blocks new accounts being opened in your name; a fraud alert is a lighter-weight alternative that requires lenders to verify your identity before approving credit.

If a national ID number leaked, go further: request a free credit report and check for accounts you did not open, consider an Identity Protection PIN where your tax authority offers one, and set a calendar reminder to re-check the report in six months, since identity thieves sometimes wait before using stolen IDs. Keep notes on what was exposed and when — they are useful when disputing fraudulent accounts later.

Three Real-World Breach Scenarios

Scenario one: a forum breach exposes a password you reused on your email. Within hours, stuffing tools hit the email account; you catch it via a new-device notification, change the password immediately, and enable 2FA — the attacker never gets in. Scenario two: a dating-site breach leaks your email and phone number but no password. Smishing messages referencing the site start arriving; you ignore them, enable 2FA anyway, and nothing further happens.

Scenario three: a payment breach leaks card details, and a card you stopped using months ago is charged for a small test purchase. You spot it on the statement, dispute it, and replace the card. In all three cases the outcome depended on acting quickly and treating every follow-up message as suspect — including emails that arrived with your real password in the subject line as "proof" the sender is legitimate.

Data Breach Questions, Answered

Should I change passwords for accounts that were never breached? Only where you reused the leaked password; a password manager makes this check instant by showing you duplicates.

How often should I check haveibeenpwned? The site offers a notification service for breached emails — sign up once and it emails you whenever a new breach involves your address.

Do old, inactive accounts matter? Yes — a stale account still holds whatever data was collected, and its password may still be in use on an active service.

Can I make the leaked data disappear? No. Data you never provided to the site cannot be removed from copies already circulated. Your leverage is speed, unique passwords, and 2FA — not deletion.

I received an email about a breach with my real password in it. Is it genuine? Be cautious — attackers append your leaked password to look legitimate. Open the email carefully, change the password through the service's own site, and never click links in the message itself.

Related Articles