One question, one page, one clear answer
Cybersecurity
Updated 6 October 2026

What Should You Do If You Get A Notification That Your Password Was Found In A Data Breach?

A breach alert can feel alarming, but a few quick, methodical steps can shut down the risk before anyone uses that leaked password against you.

General information, not professional advice — see terms of use.

If you get a notification that your password appeared in a data breach, the first thing to do is change that password immediately, on the account where it was used and on any other account where you reused the same or a similar password. Don't just tweak it slightly (adding a "1" or "!" at the end); criminals try common variations, so create a completely new, unrelated password.

Start with the account tied to the breach itself, then move on to anything else that shared the same password or a close variation, especially email, banking, and shopping accounts. Email is the highest priority because it's often used to reset passwords on everything else, so if a hacker gets into your email, they can cascade into your other accounts.

Turn on two-factor authentication (2FA) wherever it's offered, ideally using an authentication app or a physical security key rather than text messages, which can be intercepted through SIM-swapping scams. Even if a password leaks again in the future, 2FA adds a second barrier that stops most automated attacks cold.

Check whether the breach notification came from a legitimate source. Services like Have I Been Pwned, your browser's built-in breach checker, or alerts from a password manager are trustworthy. Be suspicious of unsolicited emails or texts claiming your password leaked and urging you to click a link to "verify" or "secure" your account, since that's a common phishing tactic. Go directly to the website by typing the address yourself rather than clicking any link in the alert.

If you've been reusing passwords across multiple sites, this is the moment to stop. Use a reputable password manager to generate and store a unique, complex password for every account. This single habit does more to protect you than almost anything else, because it means one leaked password can't unlock your entire digital life.

Review the affected account for signs of unauthorized activity, such as unfamiliar login locations, password reset emails you didn't request, purchases you didn't make, or messages sent from your account that you didn't write. Log out of all active sessions if the service allows it, which forces anyone else logged in with your old credentials to be kicked out.

If financial information was part of the breach, such as credit card numbers, bank details, or a Social Security number, monitor your statements closely and consider placing a fraud alert or credit freeze with the major credit bureaus. Watch for phishing attempts that reference details from the breach, since scammers often use leaked information to make follow-up scams look convincing.

Finally, make breach checking a regular habit rather than a one-time reaction. Many password managers and browsers will proactively scan for compromised credentials and alert you going forward. Treat each alert as a prompt to tighten security everywhere that password was reused, not just on the single account named in the notice.

Follow-up questions

How do I know if a breach notification is real and not a phishing attempt?

Legitimate alerts typically come from your password manager, browser, or a site like Have I Been Pwned, not from unsolicited emails with urgent links. Always navigate to the actual website yourself instead of clicking a link, and check official breach-notification pages from the company involved if you're unsure.

Should I close the account if my password was leaked in a breach?

Usually not; changing the password and enabling two-factor authentication is enough for most accounts. Only consider closing it if the service has a history of repeated breaches, poor security practices, or you no longer need the account at all.

Can changing my password undo damage that's already been done?

Changing it stops future unauthorized access but doesn't reverse anything that already happened, like data that was copied or purchases made before you noticed. That's why it's important to also review account activity, financial statements, and connected accounts for signs of misuse after a breach.

More cybersecurity answers

This page is general information, not professional advice, and it may not reflect the latest rules where you live. For your own situation, talk to a qualified adviser. Spotted an error? Email per@upperia.se and we will fix it.