Change the exposed password through the real service and replace it anywhere else you reused it. Then end unfamiliar sessions, verify recovery information, turn on two-factor authentication, and review the account for changes. Do not follow a password-reset link in an unexpected breach alert until you confirm the notice independently.
What to do first
- Go to the service through its official app or a known address.
- Change the password to a unique one that has never been used elsewhere.
- Sign out of other sessions and remove unknown devices.
- Review recovery email addresses, phone numbers, passkeys, and connected apps.
- Turn on two-factor authentication.
- Check login history and account activity.
If you cannot sign in, use the providerâs official account-recovery process. Secure the associated email account because it may receive password-reset links for many other services.
Change every account that reused the password
Credential-stuffing attacks test stolen username and password combinations on other services. Start with accounts that can reset or fund others: email, banking, payment apps, password managers, cloud storage, mobile carriers, and social media.
Small variations such as adding a number or changing one symbol remain predictable and may be included in automated guessing. Create a different password for each account. A password manager can generate and store long random passwords so you do not have to memorize each one.
How to verify a breach alert
An alert may come from the affected company, a monitoring service, a browser, or a security product. It may also be phishing. Do not sign in through the message. Open the service independently and check its security notices, account activity, and support page.
A password in a breach record may be old, hashed, partially exposed, or associated with a different site. Treat a matching or reused password as compromised even when there is no known unauthorized login.
The Breach Report can alert users when credentials associated with a registered email address appear in known breach data. It cannot guarantee that every breach is known or that an exposed credential has already been used.
Protect your email account first
Email often controls recovery for other accounts. Change its password if it was exposed or reused, end all other sessions, enable strong two-factor authentication, and review forwarding rules, filters, recovery addresses, and sent or deleted messages.
Warn contacts if the account sent messages you did not create. An attacker may impersonate you to distribute links or request money even after you regain access.
Review what happened before the password change
Changing a password does not always reverse actions already taken. Check for:
- unfamiliar devices, sessions, and locations;
- new recovery methods or passkeys;
- email forwarding and mailbox rules;
- connected apps and API access;
- purchases, transfers, saved payment methods, or shipping addresses;
- messages, posts, or files created or deleted;
- changed security and privacy settings.
Use the serviceâs âsign out everywhereâ or session-revocation option when available. Some providers do not automatically close every session after a password change.
Keep a short record of the breach notice, affected account, password changes, revoked sessions, and reports made to the provider or financial institution. Do not record the new password in that incident note. The timeline can help if another account shows related activity later.
Does two-factor authentication solve the breach?
It reduces the chance that a stolen password alone can open the account. It does not make an exposed password safe, remove an attacker who already has a session, or prevent every phishing and recovery attack.
Prefer phishing-resistant authentication when the service supports it. A passkey may replace the account password, while a FIDO/WebAuthn security key can serve as the additional factor on a password-based account. If neither is practical, an authenticator app is generally less exposed to phone-number takeover than SMS. Never approve a sign-in prompt you did not initiate.
What if a financial password was exposed?
Contact the bank or financial provider through its official app or number. Change the credential, review transactions and linked accounts, update alerts, and ask whether account numbers, cards, or access methods need replacement. Do not move money at the direction of an unexpected caller claiming to help with the breach.
PSafeâs analysis of exposed passwords
Replacing the password prevents future sign-ins with that credential, but it does not undo account changes or revoke every active session. Review recovery details, forwarding rules, connected apps, and session history before considering the account secure.
Frequently asked questions about leaked passwords
Can I add a number to the old password?
No. Use a new, unrelated password. Predictable variations are easier to guess and preserve the risk across accounts.
Should I delete the affected account?
Deletion is not the first response. Secure and review the account, preserve records, and decide whether you still need it. Deletion may not erase information already copied in a breach.
Is a password manager safe?
A reputable password manager can support unique passwords and reduce reuse. Protect the manager with a strong unique master password and multifactor authentication.
Do I need a new email address?
Usually not. An email address can remain usable after exposure. Secure the mailbox and expect more targeted phishing. Change the address only when the provider recommends it or the account cannot be recovered safely.
Does changing the password sign out an attacker?
Not always. Use the providerâs session and device controls to revoke other access.
What if I no longer use the breached service?
The password still matters if it was reused. Secure or close the old account through the real provider and change matching credentials elsewhere.