Skip to main content

Guide

What to do after your data appears in a breach

Change the password for the breached service first, then everywhere you reused it, then treat the leaked data as known to strangers.

Most breach notifications are less urgent than they feel and more consequential than they look. The data is already out; what matters is what that data can still unlock.

The sequence below is ordered by impact, not by anxiety. Working through it in order fixes the things that actually get used first.

In this order

  1. 1Change the password for the breached service itself, from a device you trust.
  2. 2List everywhere you used that same password and change those too, starting with email and banking. This is the step that matters most.
  3. 3Turn on two-factor authentication on those accounts, so the next leak of the same password does nothing.
  4. 4Check the account's active sessions and any forwarding rules, especially in email.
  5. 5If card numbers were included, check statements closely for small unfamiliar charges and ask for a replacement card.
  6. 6If identity documents were included, treat the document number as public and expect impersonation attempts that quote it.

What not to do

  • Do not pay for 'breach removal' services. You cannot withdraw data that has already been copied.
  • Do not click links in the notification email itself. Open the provider's site yourself and change the password there.
  • Do not assume a small breach is harmless. Reuse is what turns a forum password into a banking problem.
  • Do not delay because the notification sounds routine. The passwords worth changing are the reused ones, and they are worth changing today.

How to tell whether you were affected

  • Check your own accounts for the leaked details rather than trusting a forwarded screenshot: breach claims are themselves a phishing theme.
  • Search your email address against a service that reports known breaches, and read the description of what was exposed.
  • If the leak contains a password you still use anywhere, assume it is known and change it — regardless of how the leak was reported.

Frequently asked questions

The breach is old. Is there any point doing anything now?

Yes. Old leaked credentials are exactly what gets replayed years later against new accounts. If the password is still in use anywhere, treat it as new information about an old leak.

Only my email address leaked. Does that matter?

On its own it is low risk, but it confirms the address is live and is often sold as a 'verified' list for spam and phishing. Expect more unsolicited mail, and be quicker to doubt it.

How do I stop this happening again?

One unique password per service, a password manager to keep them, and two-factor authentication on email and banking. That combination removes the value of almost any future leak.

Written by The BaitScan team

Last updated September 16, 2026

Results are automated risk estimates based on public indicators and heuristics.