Laptop showing a compromised password alert beside a phone with multifactor authentication

What to Do If Your Password Was Compromised: A Calm, Step-by-Step Checklist

Seeing “your password appeared in a data breach” is unsettling. It does not automatically mean someone is inside your account, but it does mean you should act—especially if you reused that password anywhere else.

The important part is doing the right things in the right order. Changing one password and moving on can leave your email, recovery settings, or reused accounts exposed. Here is the practical cleanup sequence I recommend.

First, make sure the warning is real

Do not click a password-reset link in an unexpected email or text. A real breach notification can be copied by scammers.

Instead:

  1. Open a fresh browser window or the company’s official app.
  2. Type the site address yourself or use a saved bookmark.
  3. Sign in and check the account’s security or notification area.
  4. If you want an independent check, search your email address at Have I Been Pwned. It can show whether that address appears in known breaches and what types of information were exposed.

If the warning came from your browser or password manager, open its password-checkup feature directly rather than following a link in the message.

The short version: do these things now

If you are in a hurry, start here:

  • Change the exposed password on the affected account.
  • Change it anywhere else you reused it.
  • Secure your email account before lower-priority accounts.
  • Turn on multifactor authentication.
  • Review recovery information and active sessions.
  • Watch for follow-up phishing attempts.

Now let’s walk through that list without skipping the details that matter.

1. Secure your email account first

Your email is often the reset key for everything else. If someone controls it, they may be able to reset passwords for banking, shopping, social media, cloud storage, and business tools.

If the breached password was ever used for your email—or if you are not sure—start there:

  • Create a new, unique password.
  • Turn on multifactor authentication (MFA).
  • Confirm the recovery email address and phone number belong to you.
  • Review recent sign-ins and sign out unknown devices.
  • Check for unfamiliar forwarding rules, filters, app passwords, or connected apps.

An attacker who briefly accessed an inbox may create a forwarding rule so copies of future messages continue going to them. That is why changing the password alone is not enough.

2. Change the password on the affected account

Go directly to the service and replace the exposed password with one you have never used anywhere else.

The Cybersecurity and Infrastructure Security Agency recommends long, random, unique passwords and says a strong password should be at least 16 characters. A password manager can generate and store one for you, so you do not have to invent or memorize a different complicated password for every account.

Do not make a tiny variation such as changing Summer2025! to Summer2026!. Attackers know people do that.

3. Find every account where you reused it

Password reuse is what turns one company’s breach into a problem across several accounts. Attackers can try a stolen email-and-password combination on other popular services; this is often called credential stuffing.

Search your memory, saved passwords, and password manager for places where you used the same password. Prioritize:

  1. Email and identity accounts such as Google, Apple, or Microsoft
  2. Banking, payment, and tax accounts
  3. Work and business systems
  4. Cloud storage and password managers
  5. Shopping accounts with stored cards
  6. Social media and messaging
  7. Everything else

Change every reused copy. Each replacement should be unique—not one new password reused everywhere again.

4. Turn on MFA—the strongest option available

MFA adds another requirement beyond the password. CISA notes that it protects an account even when a password has been compromised because an attacker still has to satisfy the second factor.

When the service gives you a choice, I would generally rank the options this way:

  1. Security key or passkey
  2. Authenticator app
  3. Push notification with number matching
  4. Text message or phone call

Any supported MFA is usually better than leaving it off. Text-message codes are not my first choice when stronger options exist, but they can still add protection.

Save the recovery codes somewhere secure. Do not keep the only copy in the same phone you may need to recover.

5. Review the account, not just the password

Look for signs that someone changed the account while they had access:

  • Unknown devices, sessions, or locations
  • Changes to your name, address, phone number, or recovery email
  • New connected apps or browser extensions
  • Purchases, transfers, posts, or messages you did not create
  • New email forwarding rules or filters
  • Disabled security alerts
  • New MFA methods, app passwords, API keys, or authorized users

Use the service’s “sign out everywhere” or “revoke all sessions” option when available, then sign back in on devices you trust.

For a business account, also inspect administrators, staff access, billing details, integrations, and API keys. A changed password may not revoke every token or connected application.

6. Match your response to what was exposed

Not every breach contains the same data. Read the breach details instead of assuming it was only a password.

Information exposedWhat to do
Email addressExpect targeted phishing and fake reset messages
PasswordChange it everywhere it was reused and enable MFA
Security questionsReplace answers where possible; use random stored answers
Phone numberBe cautious about verification-code requests and carrier-account changes
Payment cardContact the card issuer, review transactions, and replace the card if advised
Social Security number or identity dataUse the official identity-theft steps at IdentityTheft.gov; consider a credit freeze
Business credentials or API keysRotate them, review logs, revoke sessions, and notify the appropriate business contact

A breach can also surface old information. Even if the password was changed years ago, the email address, phone number, or personal details may still make phishing messages more convincing.

7. Watch for the second wave: phishing

After a public breach, scammers often pose as the affected company. They may claim you must “verify” the account immediately, provide a code, or pay to protect it.

Treat urgency as a reason to slow down. Go to the official site yourself. Never give someone a one-time code they requested from you, and do not approve an MFA prompt you did not initiate.

Should you change all your passwords after every breach?

No—not if every account already has a unique password. Change the affected password and any reused copies.

Routine password changes for no reason can encourage predictable variations. The better system is unique passwords, a password manager, MFA, and immediate changes when a password is exposed or compromise is suspected.

Is Have I Been Pwned safe to use?

The email search checks whether an address appears in known breaches. Its separate Pwned Passwords service uses a privacy-preserving method called k-anonymity: the full password or complete password hash is not sent to the service during the check.

Still, use the official site by typing haveibeenpwned.com yourself. Do not enter a current password into a random “breach checker” you found in an ad or unsolicited message.

Build a system so the next alert is easier

Once the immediate cleanup is finished:

  • Move remaining accounts to unique passwords.
  • Store them in a reputable password manager.
  • Enable MFA on email, financial, work, cloud, and social accounts.
  • Download and safely store recovery codes.
  • Sign up for free breach notifications from Have I Been Pwned.
  • For a small business, document who handles security alerts and account recovery.

You cannot prevent every company you use from having a breach. You can prevent one exposed password from unlocking the rest of your digital life.

Final takeaway

Do not panic, and do not stop after changing one password. Verify the alert, secure your email, replace every reused copy, enable MFA, review sessions and recovery settings, and respond to the specific information exposed.

That sequence closes the most common gaps without turning the cleanup into an all-day mystery.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.