Your email is in a data breach – what now?

Your email address or password turned up in a data breach? Do not panic. This step-by-step plan gets you secure again in a few minutes.

Only five minutes? Do these three things
  1. Change the password on your email account – it is the master key to everything else.
  2. Turn on two-factor authentication for email and banking.
  3. Change the password everywhere else you used that same password.

First, size it up

A data breach usually means a website or service was hacked and login details were stolen. That is annoying, but not a reason to panic. It becomes dangerous mainly when you use the same password in several places, because criminals then try the stolen details automatically on other services.

Check first Find out for free where your address shows up: Have I Been Pwned lists the known breaches. It is not a guarantee of completeness, but it is a good first indication of which accounts to secure first.

Which accounts come first?

Work in order of damage. Start with your email account – it is the master key, because almost everything else can be reset through it. Then banking and payment services, then shopping accounts with a card on file, and last social media. Anywhere the same password was in use, replace it with something new and unique, ideally from a password manager .

The full recovery plan

Step by step

  • Change your email password and turn on two-factor authentication
  • Give the breached account a new, unique password
  • Stop reusing that password: change it everywhere it was the same or similar
  • Review account activity: any logins, forwarding rules or orders you do not recognize?
  • Watch your bank and payment accounts and dispute charges you did not make
  • Expect a wave of phishing. Targeted scam emails often follow a breach – stay alert
  • Document it: keep screenshots and dates in case you need to report anything

The thing that matters

The dangerous part is not the breach itself – it is reused passwords. If every account has its own password and two-factor authentication is switched on, a breach barely touches you.

Protecting yourself long term

A breach is a good excuse to set your baseline up properly, once:

Giving away less next time

So the next breach does not hit your main address, you can use a separate alias address for each service. If an alias shows up in a leak, you immediately know which company lost your data – and you can switch that one address off without changing your real one.

Warning signs of identity theft

Most of the time a new password is the end of it. Take it seriously, though, if:

  • unexpected bills, collection notices or order confirmations arrive,
  • you suddenly cannot log in any more, or accounts get locked,
  • mail or important emails stop arriving – a possible sign of a forwarding rule someone else set up,
  • you notice accounts, contracts or charges you do not recognize.

At that point it is more than a breach. Follow the plan in Identity theft: what to do .

That is how a nasty surprise turns into a permanent security upgrade.

Frequently asked questions

How do I know whether my email is affected?

Check your address for free at Have I Been Pwned. It shows you which known breaches your data appears in. Many password managers run the same check automatically for every login you have saved.

Do I really have to change the password everywhere?

Everywhere you used the same or a similar password, yes. That is exactly why unique passwords, ideally from a password manager, make such a difference.

Should I switch to a new email address?

Usually not. What matters far more is changing the password on the email account itself and turning on two-factor authentication, because your inbox is the master key to most of your other accounts.

Topics: Data Breach, Identity Protection, Passwords