Confirm what was exposed
Read the notification carefully and identify the specific data categories involved: passwords, password hashes, payment details, identity documents, addresses or only email addresses. The response differs sharply depending on the answer.
Treat any breach notification arriving by email as unverified until you check the company's official site directly. Fake breach warnings are themselves a common phishing tactic.
The first hour
Change the password on the breached service, then on every account where you reused it, starting with your email. Sign out of all active sessions on those accounts and enable a strong second factor.
If payment details were exposed, notify your bank or card issuer, enable transaction alerts and consider a replacement card. Freezing a card is faster than recovering a fraudulent payment.
- Change the breached password and every reuse of it
- Secure your primary email address first
- Revoke active sessions and connected apps
- Enable or upgrade two-factor authentication
- Alert your bank if payment data was involved
The first day
Review recovery settings on important accounts: recovery email, phone number, backup codes and trusted devices. Attackers frequently change these quietly so they can return later even after you reset the password.
Check connected third-party applications and remove anything you do not actively use, since forgotten integrations retain access long after you stop using them.
Expect targeted follow-up fraud
Breached data is used to make later scams convincing. Expect messages that quote a real order number, your address or the last digits of a card, and calls claiming to be from the breached company's security team.
A genuine organisation will never ask you to move money to a safe account, read out a code or install remote-access software. Treat any such request as fraud regardless of how much the caller knows about you.
Reduce the standing exposure
Move to unique passwords stored in a password manager, so a future breach affects exactly one account. Use email aliases for sign-ups where possible, which also tells you which service leaked your address.
Consider a monitoring or data-removal service if your details are widely exposed. These cannot prevent breaches, but they shorten the time between exposure and action.
When identity documents are involved
Exposure of identity numbers, passports or proof-of-address documents deserves a stronger response, because the data enables account opening in your name. Contact the relevant national authority or credit reference agency in your country and ask what protective markers are available.
Keep a written record of what happened, when you were notified and every step you took. If fraud follows, that timeline is what makes disputes straightforward.
How to check exposure safely
Use a reputable breach-checking service to see which of your addresses appear in known incidents, and enable notifications so that future exposures reach you quickly. Do not enter passwords into any site that asks whether they have been leaked; legitimate services check addresses or use privacy-preserving lookups.
Where a password manager offers breach monitoring, use that instead: it compares your saved credentials against known leaks locally and tells you exactly which entries to change.
Business and employer breaches
If the breached service was a workplace system, report it internally before acting alone, because the organisation may need to preserve evidence and notify a regulator within a fixed deadline. Change your own credentials and any personal reuse immediately.
Employees are also targeted after company breaches with convincing internal-looking messages. Verify unusual payment or access requests through a separate channel for several weeks afterwards.
Building resilience for next time
Assume more breaches will happen and design around them: unique passwords everywhere, a strong second factor on the accounts that unlock others, aliases for sign-ups, and minimal data shared with services that do not need it.
Once those four habits are in place, an average breach becomes an administrative task rather than a crisis, which is the realistic goal.
Which accounts matter most
Not every account deserves the same urgency. Rank them by what they unlock: the email address used for password resets sits at the top, followed by your password manager, banking and payment services, cloud storage holding documents and photos, then shopping and social accounts.
Working in that order means that even if you run out of time, the accounts an attacker would use to reach everything else are already secured.
Recognising fake breach notifications
Attackers send breach warnings of their own, because a security alert is one of the few messages people act on immediately. The fake versions include a convenient link to reset your password, which leads to a copy of the real sign-in page.
Never use the link. Open the service directly from a bookmark or type the address yourself, and check the company's official status or security page for the announcement.
