Accounts · Procedure
Your Data Was in a Breach. Now What?
Your details are almost certainly in several already. What that does and does not mean, and the short list of things that help.
Anyone with a decade of internet use has appeared in breaches. Treating each notification as an emergency is exhausting and unhelpful; ignoring them entirely is worse. The useful response depends on what was exposed.
What a breach actually exposes
Email address only. Very common, low direct impact. The consequence is more phishing and more spam, aimed at you with the knowledge that you used a specific service.
Email plus password hash. The severity depends entirely on how it was hashed. Modern algorithms make recovery expensive; older ones make it trivial. Assume the password is recoverable and act accordingly.
Email plus plaintext password. Assume compromised immediately, and everywhere you reused it.
Personal details — name, address, date of birth, phone. Not directly usable to access accounts, and useful for impersonation, account recovery attacks and convincing phishing.
Government identifiers. Social security numbers and similar. The serious category, because they cannot be changed and they enable identity fraud.
Payment details. Usually partial. Full card numbers are less common than the headlines suggest, and worth acting on immediately when present.
Security question answers. Underrated. Mother's maiden name and first school do not change, and they are used for account recovery at institutions that should know better.
Checking
Reputable breach-notification services let you search by email address and tell you which known breaches include it. Both major browsers and most password managers now do this automatically for stored credentials.
Turn that on and let it work. It is the practical version of this task.
Be careful what you search. Enter your email address on a well-known service. Do not enter passwords into a site you are not confident about, and do not use search tools you found through an advertisement.
What to actually do
Scale the response to what was exposed.
Email address only: nothing urgent. Expect targeted phishing referencing that service.
Password exposed: change it there, and change it anywhere you reused it. Reuse is what turns one breach into many. If you cannot remember where you reused it, that is the argument for a password manager's reuse audit.
Password reused on your email account: treat as urgent. Change it, review recovery settings, check for forwarding rules, sign out of all sessions, register a second factor.
Personal details exposed: be more sceptical of unsolicited contact. Someone who knows your address and recent purchases sounds legitimate. Nothing about knowing your details proves who they are.
Government identifier exposed: freeze your credit with the major bureaus. In the US this is free, reversible and the single most effective action available against new-account fraud. It is more effective than credit monitoring, which tells you after the fact.
Payment card exposed: ask the issuer for a new number. Cards are replaced routinely and it costs nothing.
What not to bother with
Changing every password immediately. Prioritise: email first, financial next, then anything sharing the breached password. Blanket changes are exhausting and people abandon them halfway.
Paying for identity monitoring you do not need. Monitoring detects after the fact. A credit freeze prevents. Free breach notification covers the alerting part.
Deleting the breached account in a panic. Deletion does not remove data already taken. Secure it, then decide.
Responding to messages about the breach. Breach notifications are a favoured phishing pretext, and they arrive in volume right after a real breach is reported. Go to the service directly.
Reducing future exposure
Unique passwords everywhere. This converts a breach from a systemic problem into a local one, and it is the entire game.
A second factor on anything that matters.
Address aliases. Many providers allow per-service addresses, so a breach reveals an address used nowhere else — and tells you which service leaked it.
Answer security questions with random text stored in your manager. They are secondary passwords, not a quiz, and truthful answers are frequently public.
Give less. Date of birth and phone number are optional at more services than people assume.
What is out of your control
Data held by organisations you never chose to deal with — brokers, credit bureaus, aggregators — will be breached, and you have limited influence over it.
What remains in your control is that a breach elsewhere does not cascade into your accounts. Unique passwords and a strong second factor on your email are what stop the cascade, and they are worth more than any monitoring product.