What to Do If Your Password Has Been Breached
A breach notification is unsettling, but the actual response is simple and mostly mechanical once you know the order to do things in. Here's exactly what to do in the first few minutes, the first hour, and the days after, so nothing important gets missed.
How you find out
Breach notifications arrive a few different ways: a direct email from the affected company, a browser or password manager warning that flags a saved password as compromised, or you proactively checking a password yourself. Don't wait to be told — our Password Breach Checker lets you test any password against a database of known breaches any time, without ever sending the password itself over the network.
Companies are sometimes slow to disclose a breach, occasionally by months, and some breaches are discovered by security researchers long before the affected company issues any notice at all. Checking proactively, especially for passwords you've used for years or across more than one account, closes that gap and puts the timeline back in your control instead of a company's.
The first five minutes
Do these in order, starting with the account that was actually named in the breach:
- Change the password immediately, replacing it with a freshly generated, unique one — not a variation of the old one.
- Enable two-factor authentication on that account if it isn't already on, following our 2FA guide.
- Check the account's active sessions or connected devices list, if the service offers one, and sign out anything you don't recognize.
Change it everywhere it was reused
This is the step people skip, and it's the one that matters most. If the breached password was used anywhere else, change it there too, immediately — automated credential-stuffing tools test leaked passwords against other major services within hours of a breach going public, sometimes faster. Our guide on why you should never reuse passwords covers exactly why this single habit causes so much downstream damage.
If you don't remember every place you used it, prioritize email first — it's usually the recovery path for everything else — then banking, then anything storing payment details. This is precisely the problem a password manager solves going forward, since it can show you instantly everywhere a given password was reused. Trying to remember this list from memory under time pressure is exactly the situation that habit is meant to eliminate.
Check for signs of account takeover
Before assuming the worst, look for concrete evidence: unexpected password-reset emails you didn't request, login notifications from unfamiliar locations or devices, changes to your recovery email or phone number that you didn't make, or messages or purchases you don't recognize. If you find any of these, follow the affected service's account-recovery process immediately and consider that other linked accounts may also be at risk.
It's worth checking your email account with particular care, even if it wasn't the service named in the original breach. Email is usually the recovery path for every other account you own, so an attacker who gains access there can often reset passwords on accounts that had nothing to do with the original breach at all. A quick scan of your "sent" folder and any account-recovery emails is a fast way to catch this early.
A response timeline
| Timeframe | Action |
|---|---|
| Immediately | Change the breached password; enable 2FA on that account. |
| Within the hour | Change the same password everywhere it was reused, starting with email. |
| Same day | Review account activity and connected sessions for signs of takeover. |
| This week | Move affected accounts into a password manager with unique, generated passwords. |
| Ongoing | Recheck important passwords periodically with a breach checker. |
Preventing the next one
You can't prevent a company from being breached, but you can make sure any single breach stops mattering the moment it happens. A unique, randomly generated password per account means a leak at one company never becomes a working key anywhere else. Two-factor authentication means a leaked password alone still isn't enough to get in. And a password manager makes both of those genuinely sustainable across the 100-plus accounts most people actually have — see our complete guide on how to keep your online accounts secure for the full picture.
It also helps to accept that breaches are now a routine part of using the internet, not a rare emergency. Treating "was I in this one?" as a quick, five-minute habit — rather than a stressful event each time — makes the whole process far less draining, and a password manager with built-in breach monitoring can even automate the checking part for you going forward.
Frequently asked questions
How do I find out if my password has been breached?
Services you use will sometimes notify you directly, but the more reliable approach is to check yourself. Our Password Breach Checker tests any password against a database of known-exposed credentials without ever transmitting the password itself, using a privacy-preserving technique called k-anonymity.
Do I need to change the password even if my account looks fine?
Yes. A breach means the password is now public knowledge among anyone who has that data, whether or not it's been used against you yet. Automated tools continuously test known-exposed credentials against other services, so "nothing has happened so far" can change at any time.
Should I close the affected account?
Usually not necessary. Changing the password and enabling two-factor authentication addresses the actual risk. Closing the account only makes sense if you no longer use the service and want to reduce your overall exposure to future breaches at that company.
What if I don't remember everywhere I used that password?
This is exactly the scenario a password manager is built to solve going forward — it can show you every saved login using a given password. Without one, prioritize email, banking, and any account tied to your real identity, since those cause the most damage if compromised.
How quickly do attackers actually try breached passwords elsewhere?
Often within hours of a breach becoming public, sometimes faster. Credential-stuffing tools are fully automated and test leaked username-and-password pairs against major services continuously, which is why speed matters more than most people assume when responding to a breach notification.
Conclusion
A breach notification feels alarming, but the response is a short, mechanical checklist: change the password, change it everywhere else it was reused, turn on 2FA, and check for signs of takeover. Do those four things quickly and the breach stops being a live threat. Build the habit of unique passwords and a manager going forward, and the next breach notification becomes a non-event instead of an emergency — a five-minute check rather than a stressful scramble.
Related articles
Why You Should Never Reuse Passwords
Understand credential stuffing and why one shared password can expose every account you own.
Read article →How Hackers Crack Passwords
A clear look at brute force, dictionary attacks, and phishing — and how to defend against each one.
Read article →Common Password Mistakes
Ten everyday habits that quietly put your accounts at risk, with a clear fix for each one.
Read article →Two-Factor Authentication Guide
Every 2FA method compared, from SMS codes to hardware keys, plus how to set it up properly.
Read article →Free tools for this guide
Password Generator
Create a strong, random password in one click, right in your browser.
Open tool →Password Strength Checker
See entropy, crack-time estimates, and tips for any password you type.
Open tool →Password Breach Checker
Check if a password has appeared in a known data breach, privately.
Open tool →