Skip to content
VaultPass

Breaches

What to do if your password is leaked, step by step

The VaultPass desk5 min read
Shattered glass with cracks spreading from the point of impact

Getting the notice that your password is in a breach turns your stomach, but it rarely means anything has been stolen yet. It means you have a window of time, usually short, to close the door before somebody pushes it.

A breach is not an attack on you. It is an accident at a company that held your data: someone got into their servers, took the user database, and that list ended up circulating. Your password was in it because you had an account there, not because anyone singled you out.

The good news is that the response is short and always the same. The bad news is that you have to follow all of it, not just the first point.

Step 1. Change the password on the affected account

Go to the official site or app by typing the address yourself. Do not use a link from an email, even one that looks legitimate: fake breach notices are one of phishing’s favourite excuses, precisely because they arrive when you are rattled.

Create a new password that is completely different. Not a variation. If the old one was Barcelona2024, the new one cannot be Barcelona2025: attack tools try those variants systematically.

Step 2. Change it everywhere you reused it

This is the step people skip, and it is the one that matters.

When a list of emails and passwords is published, what follows is automatic: a program tries every pair across dozens of popular services. It is called credential stuffing. Nobody is deciding to attack you; a script is working through a list of millions.

Make an honest mental list and start in this order:

  1. Email. The master key. Whoever gets into your email can request a reset on almost everything else.
  2. Banking and anything with a saved card: your bank, PayPal, Amazon, shops.
  3. Identity accounts: government services, insurance, health.
  4. Social media and messaging, for the reputational damage and because your contacts get scammed from there.
  5. Everything else.

If making that list reveals the same key was on fifteen sites, that is the underlying problem, not this particular breach.

Step 3. Turn on two-factor authentication

With two-factor enabled, a stolen password is no longer enough: a code from your phone or a physical key is also needed.

If you have to prioritise, do email first and banking second. Where the service lets you choose, an authenticator app or a physical key resist better than SMS.

Save the recovery codes the service gives you when you enable it. You need them precisely on the day you lose your phone, which is the worst day to discover you do not have them.

Step 4. Check whether someone already got in

Changing the password shuts out anyone who has not entered yet, but it does not evict someone already inside or undo whatever they set up. Check these four things on the important accounts:

  • Active sessions. Almost every service has a “connected devices” screen. End every session you do not recognise. Many accounts have a “sign out everywhere” button: use it.
  • Email forwarding rules. The quietest trap: the attacker creates a rule that forwards a copy of everything you receive, then leaves. You change the password and they keep reading your mail. Check your forwarding and filter settings for anything you did not create.
  • Recovery email and phone number. If those have been changed, they can take the account back whenever they like.
  • Authorised apps. Revoke anything you do not use or recognise.

Step 5. Watch what comes next

Over the following weeks it is normal to receive more phishing attempts: whoever bought a leaked list knows your email, and sometimes your name and phone number. Expect messages that quote real details about you to gain credibility.

The rule that saves grief is simple: no legitimate service will ask for your password by email, by phone or over a messaging app. And faced with any message in a hurry, hang up and go to the official site yourself.

If your card number leaked too, tell the bank and ask for a new one. If an identity document leaked, pay attention for months to anything odd: identity data gets used to sign contracts in your name, and that damage takes longer to surface.

What you do not need to do

Delete the account in a panic. It rarely helps, and sometimes leaves you without something you need. Changing the key and enabling two-factor covers the normal case.

Pay for an “identity monitoring” service straight away. Most of what they offer — telling you your email appeared in a breach — your browser and password manager do for free.

Change every password you own each time. If you already use unique keys, one breach only affects one site. That is exactly the point of not reusing them.

How to find out before you are told

You do not have to wait for an email. You can check whether a specific password appears in known breaches with the VaultPass checker. It uses a technique called k-anonymity: your password becomes a hash inside your browser, only the first five characters of that hash are sent, and the final comparison happens on your machine. The service queried never learns what you were checking.

The summary

  1. Change the key on the affected account, going to the official site yourself.
  2. Change it everywhere you reused it. Email first.
  3. Turn on two-factor authentication.
  4. End open sessions and check email forwarding rules.
  5. Be suspicious of urgent messages in the following weeks.

Done that, the breach stops being a problem and becomes a warning: the one that pushes you to stop reusing passwords.

Frequently asked

The questions that keep coming up

How do I know if my password has been leaked?

You can check it in a verifier that uses k-anonymity, which sends only the first five characters of a hash and never the password. Modern browsers and password managers also warn you automatically.

My password leaked but nothing has happened. Do I need to act?

Yes. Nothing happening yet does not mean nothing will. Leaked lists circulate for years and are tried automatically long after the original breach.

Is changing it on the affected site enough?

Not if you reused it. You have to change it everywhere you used it, starting with your email and any account with money attached.

Does changing one character of a leaked password help?

No. Attackers try the obvious variants of leaked passwords, including appended numbers and swapped letters. The new key has to be completely different.

Keep reading