Finding out your data was in a breach is unsettling, but the situation is almost always more manageable than that first jolt of panic suggests. Most breaches expose far less than people fear, and the right response is a short, methodical checklist — not an emergency. This guide walks you through it in priority order, so you spend your energy where it actually reduces risk.
Do this first: match your response to what leaked
Before anything else, find out what was exposed, because that single fact decides everything you do next. Breaches are not all equal, and the biggest mistake is treating a minor one like a catastrophe (or a serious one like a shrug). There are roughly three tiers:
- Email address only. The mildest case. The realistic risk is more spam and more targeted phishing — annoying, not dangerous by itself. No password change is strictly required, but stay alert for scam messages (see below).
- Email plus password. Now it matters. If that password was reused anywhere else — and for most people it was — every account sharing it is exposed. This is the most common and most fixable serious case, and the fix is step 2 below.
- Identity or financial data. A government ID or national insurance/social security number, date of birth, full card details, or bank information. This is the tier where a credit freeze belongs, because this is the data used to open new accounts in your name.
You usually learn which tier you’re in from the breach notification itself (companies are often required to say what was exposed) or from a breach-check service that lists the exposed data types. If you genuinely can’t tell, assume the middle tier — change the password and enable two-factor — and watch for signs of the third.
A quick word to calm the worst-case thoughts: a breach means a company lost control of data, not that someone has logged into your accounts. The data becomes dangerous only when someone uses it, and the steps below are about closing that window before they can.
Step-by-step: the breach response plan
1. Confirm exactly what leaked
Read the breach notice properly rather than skimming the scary headline. Note two things: which service was breached, and which data types were exposed. If you found out secondhand (a news story, a friend, a breach-check tool), confirm it against the company’s own statement where you can — impersonating a breach notification is itself a common scam.
If you want to see your fuller exposure across all known breaches, not just this one, run your main email addresses through a reputable breach-notification service. It’ll list the breaches your address has appeared in and, often, what was exposed in each. Don’t be alarmed by a long list — most people who’ve been online for a decade have several old, harmless entries. What you’re looking for is anything recent, and anything involving passwords or identity data.
2. Change the leaked password — and every place you reused it
This is the highest-leverage step in the whole guide. Change the password on the breached account first. Then — and this is the part people skip — change it everywhere else you used the same password or a close variant. Attackers automate exactly this: they take a leaked email-and-password pair and try it against banks, email providers, and shopping sites en masse. That’s called credential stuffing, and reuse is what makes it work.
If you don’t already have one, this is the moment to set up a password manager, because it makes the “change it everywhere” problem tractable — it can tell you where you reused passwords and generate a unique one for each.
Bitwarden
Free, open-source, and audited — it generates unique passwords and flags reused ones so you can see exactly how far one leak reached. A good default if you don't have a manager yet.
Give the breached account a fresh, unique, generated password. Do not reuse your new password anywhere either — the whole point is that each account stands alone, so a future leak of one can never spread.
3. Turn on two-factor authentication on the exposed accounts
A leaked password stops being dangerous the moment a second factor stands behind it. Turn on two-factor authentication (2FA) on the breached account and on your email, and prefer an authenticator app or a passkey over SMS codes where the option exists — SMS can be intercepted through SIM-swap attacks, though it’s still far better than no second factor at all.
With 2FA on, someone holding your leaked password hits a wall: they’d also need the code from your phone or the passkey on your device. This is the difference between a breach being a scare and a breach being a break-in. Our companion guide on how to secure your online accounts covers setting up 2FA and passkeys properly, including where to safely store your backup codes.
4. Lock down your email and money
Two categories deserve special attention regardless of what leaked, because they’re where damage concentrates.
Your email is the master key — every “forgot password” flow on the internet ends in your inbox, so whoever controls it can reset everything downstream. If it wasn’t the breached account, secure it anyway: unique passphrase, app-based 2FA, and a check that the recovery phone and backup email are current and yours. If your email was the breached account, treat this as the top priority.
Your financial accounts deserve a quick review even if no card data leaked. Log into your bank and card accounts directly (type the address; don’t click a link from an email) and scan recent transactions for anything unfamiliar. Turn on transaction alerts if you haven’t — a text for every charge is the fastest way to catch fraud early. If you spot something you didn’t authorize, contact the bank through the number on the back of your card, not any number from a message.
5. Freeze your credit if identity data leaked
If the breach exposed the kind of data used to open new accounts in your name — a national ID or social-security-style number, your date of birth, or full financial details — place a credit freeze. A freeze stops anyone (including you, until you lift it) from opening new credit in your name, which is the single most effective block against new-account identity fraud. It’s free to place and free to lift, and lifting it temporarily is quick when you genuinely need new credit.
The exact mechanics — which bureaus to contact, what they call it, and how you lift it — vary by country, so follow your national bureaus’ official instructions. [TODO: verify country-specific steps] We walk through the process in detail in how to freeze your credit.
If only your email and a password leaked, you can skip the freeze — it’s the right tool for identity-data exposure, not for every breach. Matching the response to the exposure is the whole theme of this guide.
6. Watch for the follow-up phishing wave
Here’s the part people don’t expect: the messages after a breach are often more dangerous than the breach itself. Leaked data gets sold and traded, and scammers use the real details it contains to craft convincing follow-ups — “We noticed suspicious activity on your [the exact service that was breached] account, verify immediately.” Because it references something true, it slips past your usual skepticism.
Learn the tells and they stop working:
- Manufactured urgency. Threats of suspension or “act in 24 hours” exist to short-circuit your judgment. Real services rarely demand speed.
- The almost-right sender. A display name that says the right company over an address that doesn’t match its real domain.
- Requests to “verify” what they should already know — passwords, full card numbers, one-time codes. No legitimate service asks for these.
- Unexpected 2FA prompts. A code arriving when you didn’t try to sign in means someone else did. Never approve it; change that password.
The universal safe move: don’t interact with the message. Go to the service yourself — type the address or use your bookmark — and check there. If something genuinely needs you, it’ll be waiting inside your account.
7. Stop the next leak
Once the immediate cleanup is done, spend twenty minutes making the next breach a non-event. The goal is that when — not if — some other service you use gets breached, your exposure is limited to that one account.
- Unique passwords everywhere, generated and stored in your password manager. This alone neutralizes credential stuffing for good.
- Turn on breach monitoring so you’re notified early next time. Most good password managers include it, and it beats finding out from the news.
- Delete accounts you no longer use. An account that doesn’t exist can’t leak. The dormant forum you signed up for in 2015 is pure downside.
- Give important accounts 2FA or passkeys as a standing habit, not a one-time reaction.
When a leak is serious: signs of active identity fraud
Most breaches never escalate. But if identity data leaked, it’s worth knowing what actual misuse looks like so you can act fast if it appears:
- Bills or debt-collector letters for accounts you never opened.
- A credit application you didn’t make showing on your report (checking your credit report periodically is a good habit; in many countries you’re entitled to free copies).
- Missing expected mail — sometimes a sign someone redirected it.
- Denied credit for no reason you recognize, which can mean fraudulent accounts are dragging your file down.
If you see these, a credit freeze becomes urgent rather than precautionary, and it’s worth reporting to the relevant national fraud or identity-theft authority for your country. [TODO: verify country-specific steps]
Should you pay for identity protection?
After a serious leak of identity data, many people consider a paid identity-protection service. It’s a reasonable add-on — not a substitute for the free basics above. What you’re paying for is convenience and coverage: monitoring across more sources than you’d track yourself, alerts when your data surfaces, and hands-on help (and often insurance) if fraud does happen.
Aura
An all-in-one option bundling identity monitoring, data-broker removal, and account alerts — worth considering after a leak that exposed identity or financial data, when you'd rather have monitoring handled for you.
Be honest with yourself about which tier of breach you’re in before paying, though. If only an email and password leaked, your money is better spent on nothing — the free password-and-2FA cleanup is the complete correct response. Save the paid tools for genuine identity-data exposure, where ongoing monitoring earns its keep. For a fuller look at the options, see our data removal services guide.
Common mistakes to avoid
- Panicking and doing nothing. The most common outcome of a scary breach email is paralysis. A 20-minute checklist beats a week of dread.
- Changing only the breached password. If you reused it, the leak reaches every account that shared it. “Everywhere you used it” is the load-bearing phrase.
- Trusting the breach notification blindly. Confirm it’s real before clicking anything in it — fake breach alerts are a phishing staple.
- Freezing your credit for a minor leak, or skipping it for a serious one. Match the response to the exposure.
- Leaving the fixes temporary. Unique passwords and 2FA are upgrades to keep, not a one-time reaction to undo later.
The bottom line
A data leak feels like something happened to you that you can’t control — but almost everything that reduces the risk is squarely in your hands, and most of it is free. Confirm what leaked, kill password reuse, add second factors, freeze your credit if identity data was exposed, and stay skeptical of the phishing that follows. Do that, and a breach goes from a threat to a non-event.
This guide is part of our Privacy & Security Kit. To go deeper, check whether your email has been in a breach, lock everything down with our afternoon account-security plan, and pick the tool that makes it all manageable with our best password managers guide — all part of the Privacy & Security Kit.