Data Breaches
My Password Was Found in a Data Breach. What Should I Do?
September 10, 2026 · 8 min read
Finding a password in breach data does not necessarily mean someone has accessed your account. It means that password should no longer be trusted.
Attackers collect leaked email-and-password pairs and replay them on other sites. The risk is reuse, not a single forgotten forum from 2014. Work through the steps below in order—especially email—before you treat the incident as closed.
1. Change the password on the affected account
Sign in to the account you just checked, if you still can, and replace the password immediately. Do this even if you have not noticed suspicious mail or charges. A match in breach data is enough.
If you cannot sign in, use the official password-reset flow for that service. Do not click reset links from unexpected emails.
2. Find everywhere you reused the same password
This is the most important part. Credential stuffing works because one leak becomes many logins. Search your password manager, browser saved passwords, and memory for every place that shared this secret—shopping, social, old forums, work tools, Wi-Fi admin pages.
Write the list down privately. You will rotate those next. A “small” site is not low-risk if it used the same password as email or banking.
3. Change reused passwords
Replace the reused password on every account on that list. Each account gets its own new secret. Do not wait for the next breach notification; the pair is already public.
4. Start with your email account
Because email can often be used to reset other accounts, treat your inbox as the first high-value target after the original match. If the leaked password was also your email password, change that before anything else.
Then check forwarding rules, recovery addresses, and app passwords. Attackers who land in email quietly add a forwarder so they keep access after you “fix” the password.
5. Enable MFA or a passkey
A new password is not enough if the next phishing kit can still steal a code. Turn on multi-factor authentication, preferably a passkey or an authenticator app. SMS is better than nothing; it is weaker than a passkey against real-time phishing.
Do email, banking, cloud storage, and work first. Save backup codes offline, not in the same inbox you are protecting.
6. Check active sessions and recent logins
On each recovered account, open security or device settings and sign out sessions you do not recognize. Look at recent logins, new recovery emails, and OAuth apps you did not approve.
If a session stays open after a password change, end it manually. Then change the password again if you see activity you cannot explain.
7. Don’t simply modify the old password
Summer2025! → Summer2026! isn’t a good recovery strategy. Attackers try season swaps, year bumps, and a trailing digit as soon as they have the original.
Close variants are still the same password for stuffing tools. The replacement must be unrelated to the leaked string.
8. Generate a new unique password
Use a password manager if you have one. If you need a secret right now, create it in the browser with our password generator. Generate it locally, copy it once, and store it—do not email it to yourself.
9. Check other important passwords
After you rotate the match, test other long-lived secrets the same way: email, banking, Apple/Google/Microsoft, work SSO, password manager master password if you ever reused it. Use the Password Breach Checker. Each check hashes the password in your browser and never uploads it.
10. If you need to give the new password to someone
Do not paste it into chat, email, or a ticket. Share it once through PrivateNote, let the other person store it in a password manager, and let the note expire. That is delivery, not a second copy sitting in an inbox.
Replace the leaked password, then check the rest
Generate a unique secret locally, then run other important passwords through the Password Breach Checker. Nothing you type is sent to us.