What should I do if my data was in a breach?
Assessing what was exposed, changing what matters, and the ongoing vigilance that follows a serious breach.
- Difficulty
- beginner
- Time
- 45 min
- Read
- 2 min
Short answer
Change the password on that service and anywhere you reused it, turn on two-factor authentication, and watch for targeted phishing using the leaked details. Reused passwords are what turn one breach into several.
Breaches vary enormously in seriousness. An exposed email address is an annoyance; exposed passwords or financial details are not. The response depends on what was actually taken, which the notification should state.
What you'll need
- The breach notification
- A password manager (optional)
Step by step
- Read what was actually exposed.Email addresses only, or passwords, payment details, addresses, identity documents? The response differs enormously between them.
- Change the password on that service immediately.To something long and unique. Do this even if the notification says passwords were encrypted — encryption is sometimes weaker than claimed.
- Change it anywhere you reused that password.This is the critical step. Attackers try breached credentials across other services automatically, and it is how one breach becomes many.
- Turn on two-factor authentication.It means a stolen password alone is not enough. Prioritise email, banking and anything holding payment details.
- Watch for targeted phishing.Breached details make convincing scams — messages that know your name, address or recent purchases. Expect them for months afterwards.
- Monitor financial accounts if payment details were involved.Check statements, and consider asking your bank to reissue the card. Small test transactions often precede larger ones.
- Check whether your details appear in other known breaches.Reputable breach-checking services let you search by email address and show which services were affected.
- Consider a credit freeze if identity documents were exposed.Where available, it prevents new credit being opened in your name and is the strongest protection against identity fraud.
Tips
- A password manager makes unique passwords practical, which is the single most effective defence against breaches spreading.
- Be suspicious of anyone contacting you about the breach. Breach notifications themselves are a common phishing pretext.
- Companies sometimes take months to disclose breaches. Assume anything you gave a service may eventually be exposed and use unique passwords accordingly.
Common mistakes
- Only changing the password on the breached service — Attackers try the same credentials elsewhere automatically. Every account sharing that password is at risk.
- Ignoring a breach because 'only' the email address leaked — It enables targeted phishing that is far more convincing than generic spam, and it often comes with other details.
- Clicking links in messages about the breach — Breach notifications are a favourite phishing pretext. Go to the service's website directly instead.
Questions people ask
What should I do if my password was in a data breach?
Change it on that service, then change it everywhere you reused it, and turn on two-factor authentication. Reused passwords are how one breach spreads to other accounts.
Is a breach serious if only my email address leaked?
It is less serious than exposed passwords, but it enables targeted phishing that is far more convincing than generic spam. Be more sceptical of messages for a while afterwards.