How to Check If Your Email or Password Has Been Compromised and What to Do Next

Finding out that your email address or password may have appeared in a data breach can be alarming. You might receive a security notification, notice an unfamiliar login, or discover that one of your accounts was included in a recently reported cyberattack. However, an exposed email address does not always mean that someone has successfully entered your inbox.

There are several possible situations. Your email address may have appeared in a breached customer database, an old password may have been leaked, or criminals may have obtained a current combination of your email address and password. In more serious cases, someone may already be accessing your account, reading your messages, changing settings, or using your inbox to reset passwords elsewhere.

The most important thing is to stay calm and act in the correct order. Changing one password may help, but it may not completely solve the problem if that password was reused, an attacker still has an active session, or malware is collecting information from your device.

This guide explains how to check whether your email address or password has been compromised, identify signs of unauthorized access, secure affected accounts, and reduce the risk of further damage.


Table of Contents


How to Check If Your Email or Password Has Been Compromised and What to Do Next


How to Find Out What Was Exposed and Secure Your Accounts

Before changing every password you own, you should first determine what happened and which accounts may be affected. A breach involving only an email address requires a different response from one that exposed a current password, financial information, or access to the email account itself.

Start by checking whether your email address appears in a known data breach. You should then review any warnings from your browser, password manager, email provider, or security software. These tools may identify passwords that have been exposed, reused across several accounts, or considered too weak to provide reliable protection.

Next, inspect your email account’s recent security activity. Look for unfamiliar devices, login locations, password changes, recovery-information updates, connected applications, and active sessions. You should also review your inbox rules and forwarding settings because attackers sometimes use them to quietly copy messages or hide security alerts.

If you confirm that a password was exposed, replace it with a new and unique password. Do not simply add a number or symbol to the old one. You should also change that password anywhere else it was reused, beginning with your primary email account, password manager, financial accounts, and other services that contain sensitive information.

Finally, enable multifactor authentication, sign out unfamiliar sessions, remove unauthorized applications, and scan your device for malware. Following these steps in the correct order can help you regain control of your accounts and prevent one exposed password from creating a much larger security problem.


What Does It Mean When an Email or Password Is Compromised?

The word compromised can describe several different security problems. It does not always mean that a criminal has entered your email account or taken control of it. In some cases, it simply means that information connected to your email address appeared in a leaked database.

Understanding what was exposed can help you respond without overlooking a serious risk or taking unnecessary steps.

Your Email Address Appeared in a Data Breach

An email address exposure usually happens when a company, website, or online service experiences a data breach. The compromised database may contain customer email addresses along with other personal or account information.

Depending on the incident, the exposed information could include:

  • Your name and email address
  • A username or account number
  • Your phone number or physical address
  • Your date of birth
  • An encrypted or hashed password
  • Answers to security questions
  • Purchase or subscription history
  • Financial or payment information

This does not necessarily mean that someone accessed your inbox. For example, your email address could appear in a breach involving an online store, social network, forum, or streaming service. The email provider itself may not have been affected.

However, exposed personal details can still help criminals create convincing phishing messages. They may contact you while pretending to represent the breached company, refer to real account details, and pressure you into clicking a malicious link or revealing more information.

Your Password Was Exposed

A password is considered exposed or compromised when it appears in known breach data, credential collections, malware logs, or other stolen records.

Even if the password is several years old, you should not assume it is harmless. Criminals can keep stolen credentials and test them long after the original breach occurred. They may also try common variations of the password, such as changing a year or adding a symbol.

An exposed password should no longer be used for any account. This is especially important when you have reused the same password—or a similar version of it—across multiple websites.

Attackers frequently use a technique called credential stuffing, in which automated tools test leaked email-and-password combinations on many different services. A password stolen from an old shopping account could therefore put your email, social media, cloud storage, or financial accounts at risk.

Your Email Account Was Accessed

An account compromise means that someone has successfully gained unauthorized access to the account.

The intruder may be able to:

  • Read, send, delete, or forward messages
  • View personal documents and attachments
  • Change the account password
  • Replace recovery information
  • Create inbox rules or forwarding settings
  • Reset passwords for other online services
  • Impersonate you when contacting friends, relatives, or coworkers
  • Search your inbox for financial or personal information

Your email account is particularly valuable because it often serves as the recovery method for many other accounts. If someone controls your inbox, they may be able to request password resets and gradually take over additional services.

Your Device May Be Compromised

Sometimes, the problem does not begin with a company data breach. Malware on your computer or phone may steal credentials directly from the device.

Infostealer malware can collect saved browser passwords, login cookies, autofill information, cryptocurrency wallet data, and other sensitive details. A malicious browser extension may also read information entered into websites or redirect you to fake login pages.

This possibility is important because changing a password may not solve the problem if the device remains infected. The malware could simply capture the replacement password the next time you enter it.

In simple terms, a breach indicates that your information was exposed, while unfamiliar account activity suggests that someone may have used that information. Both situations deserve attention, but an actively accessed account requires immediate action.


A data breach can also make phishing attempts more convincing because scammers may already know your email address, name, or other personal details. Learn more about phishing and how these attacks work before responding to unexpected security warnings, payment requests, or account-verification messages.


Warning Signs That Your Email Account May Have Been Hacked

Some account compromises are obvious. You may suddenly lose access to your inbox, see messages that you did not send, or receive a warning about a password change. Other attackers try to remain unnoticed so they can quietly monitor your email or wait for an opportunity to misuse it.

Review your account carefully when you notice any of the following warning signs.

Unfamiliar Login or Device Alerts

Most major email services send a notification when someone signs in from a new device, browser, or location. An unfamiliar alert could mean that another person knows your password or has gained access through a stolen session.

Do not assume that every unusual location indicates an attack. Mobile networks, VPNs, and internet providers can sometimes make a legitimate login appear to come from another city or region. Compare the location with the device type, browser, time, and recent activity before deciding whether it belongs to you.

If you do not recognize the activity, use the email provider’s official website or app to secure the account. Do not use a link inside an unexpected security message, since the warning itself could be a phishing attempt.

Password-Reset Messages You Did Not Request

An unexpected password-reset email may indicate that someone is trying to enter one of your accounts.

A single message does not necessarily mean the attacker succeeded. Anyone who knows your email address may be able to request a reset. However, repeated requests—especially for several different services—could suggest that your address is being actively targeted.

Never approve a reset or enter your credentials unless you initiated the request. Open the affected service directly and review its security activity.

Emails You Did Not Send

Check the Sent, Drafts, Trash, Spam, and Archived folders for messages you do not recognize.

Attackers may use a compromised account to:

  • Send phishing links to your contacts
  • Request money or gift cards
  • Distribute malicious attachments
  • Reset passwords for other accounts
  • Continue an existing business or financial conversation
  • Impersonate you during a scam

Some attackers delete sent messages afterward, so an empty Sent folder does not prove that the account is safe. Friends, relatives, or coworkers may be the first people to notice that unusual messages are coming from your address.

Messages Are Missing or Marked as Read

Emails that disappear, move into unexpected folders, or become marked as read without your involvement can be another warning sign.

An attacker may search for messages containing:

  • Password-reset links
  • Bank or payment information
  • Tax documents
  • Identification records
  • Business invoices
  • Travel plans
  • Personal conversations

They may delete security warnings or move them into a hidden folder to prevent you from noticing suspicious activity.

Before assuming the account was hacked, confirm that another legitimate device or email application did not open or organize the messages. Synchronization between a phone, computer, tablet, and desktop email client can sometimes create confusing changes.

Unknown Forwarding Rules or Inbox Filters

Email forwarding and automatic rules are useful features, but they can also provide attackers with a quiet way to monitor an account.

A malicious rule might:

  • Forward all messages to an unknown address
  • Copy messages containing words such as invoice, payment, or password
  • Delete security notifications
  • Move replies into an obscure folder
  • Mark certain messages as read
  • Hide emails from a bank or account provider

These changes may remain active even after you replace the password. That is why you should inspect forwarding settings, inbox rules, filters, delegated access, and connected applications whenever you suspect an account compromise.

Changes to Your Password or Recovery Information

Treat any unrecognized change to your password, recovery email address, phone number, security questions, or trusted devices as a serious warning.

Attackers often modify recovery settings so they can regain access after the account owner changes the password. They may also add their own phone number or email address as a backup method.

Check that every recovery option belongs to you and that the information is still current. Remove unknown details and review any recent security events connected to the changes.

Unexpected Multifactor Authentication Requests

An unexpected authentication prompt may mean that someone has already entered the correct password and is attempting to complete the login.

Never approve a prompt simply to make it disappear. Attackers sometimes send repeated requests in the hope that the account owner will eventually tap Approve out of frustration or confusion. This technique is sometimes called MFA fatigue or push bombing.

Deny the request, change the account password from a trusted device, sign out other sessions, and review recent activity.

Unrecognized Purchases or Password Changes on Other Accounts

A compromised email account can become a gateway to other services. Watch for unexpected purchase receipts, subscription confirmations, password changes, account-recovery messages, or new-account notifications.

These events may indicate that someone is using your inbox to access:

  • Online banking or payment accounts
  • Shopping websites
  • Social media
  • Cloud storage
  • Mobile carrier accounts
  • Gaming platforms
  • Workplace or school services

The absence of obvious warning signs does not guarantee that an account is secure. A careful attacker may quietly read messages or collect information without changing the password or sending anything. Reviewing recent login activity, active sessions, forwarding rules, and connected applications provides a more reliable picture than checking the inbox alone.


Step 1: Check Whether Your Email Appeared in a Known Data Breach

The first step is to determine whether your email address has appeared in a publicly documented data breach. A breach-checking service can compare your address with collections of account information exposed during known security incidents.

One of the best-known options is Have I Been Pwned, which allows you to search for an email address and see whether it appeared in supported breach records. The results may show the affected company, the approximate date of the incident, and the types of information that were exposed.

To perform the check safely:

  1. Open a trusted breach-checking service directly in your browser.
  2. Enter the email address you want to investigate.
  3. Review each listed breach carefully.
  4. Note which company or service was affected.
  5. Check what types of information were exposed.
  6. Repeat the process for any older or secondary email addresses you still use.

It is safer to enter the website address yourself or access it through a trusted bookmark. Avoid clicking a breach-checking link in an unexpected email, text message, pop-up, or social media post. Criminals sometimes create fake security tools designed to collect email addresses, passwords, or payment information.

What a Positive Breach Result Means

If your email address appears in a breach result, it means the address was included in data connected to a known security incident. It does not automatically mean that someone entered your email account.

For example, an online retailer may have exposed a customer database containing names, email addresses, shipping information, and encrypted passwords. Your inbox may not have been affected directly, but the leaked information could still be used for phishing, password guessing, or account takeover attempts.

Pay close attention to the categories of exposed data. A breach involving only an email address creates a different level of risk from one involving:

  • Passwords or password hashes
  • Security questions and answers
  • Phone numbers
  • Home addresses
  • Payment information
  • Identification records
  • Dates of birth

The presence of a password or recovery information means you should take faster and more extensive action.

What a Clean Result Means

A result showing no known breaches is reassuring, but it is not a guarantee that your information has never been exposed.

A breach may be:

  • Too recent to appear in the database
  • Known only to the affected company
  • Privately traded among criminals
  • Connected to malware rather than a company breach
  • Missing from the breach-checking service
  • Associated with a different email address or username

You should still investigate unfamiliar logins, unexpected authentication prompts, password changes, or suspicious account activity even when a breach search returns no results.

Check Every Email Address You Use

Many people focus only on their current primary address. However, an older address can still create security risks when it remains connected to active accounts.

Check addresses used for:

  • Shopping and subscriptions
  • Social media
  • School or work
  • Gaming
  • Banking and payments
  • Old forums and online communities
  • Account recovery
  • Newsletter registrations

An old email address may also reveal passwords or personal information that you continue to use elsewhere. Treat each breach result as a clue that helps you identify which accounts need attention.


Step 2: Check Your Saved Passwords for Breach Warnings

After checking your email addresses, review the passwords saved in your browser, operating system, or password manager. Many modern password tools can warn you when a saved password appears in known breach data.

Depending on the service you use, the warning may describe a password as:

  • Compromised
  • Exposed
  • Leaked
  • Reused
  • Weak
  • At risk

These labels describe different problems. A compromised password has appeared in known stolen data, while a reused password is saved for more than one account. A weak password may be easy to guess even when it has not appeared in a documented breach.

Where to Look for Password Warnings

Password-security checks may be available through:

  • Your browser’s password manager
  • A dedicated password-management application
  • Your phone or computer’s built-in password tools
  • Your main Google, Apple, or Microsoft account
  • Security software with identity-monitoring features

Look for an area called Password Checkup, Security Recommendations, Password Health, Security Dashboard, or something similar. The exact name and location may differ depending on your device and software version.

The tool may show a list of affected accounts and direct you to their websites. However, it is often safer to open the official website or app yourself rather than following a link you were not expecting.

Prioritize Compromised and Reused Passwords

You do not necessarily need to change every saved password at once. Start with the accounts that create the greatest risk.

A useful order is:

  1. Primary email account
  2. Password manager
  3. Banking and payment accounts
  4. Google, Apple, or Microsoft account
  5. Mobile carrier
  6. Cloud storage
  7. Work or school accounts
  8. Social media
  9. Shopping and subscription services
  10. Less important accounts

A password that is both compromised and reused should receive immediate attention. If attackers have the password, they may test it automatically across many popular services.

Replace it with a completely different password for each account. Do not make small adjustments such as changing Password2025! to Password2026!. Predictable variations may still be easy to guess.

Do Not Enter Your Password Into Random Leak Checkers

Some websites claim that they can tell you whether a password has been leaked. Be extremely careful with these tools.

You should never type a current password into an unfamiliar website, online quiz, pop-up, or form. A malicious site could simply record the password and use it against you.

Use password checks provided by:

  • A trusted password manager
  • Your browser or operating system
  • An established breach-checking service
  • The official account provider

A legitimate tool should not ask you to submit your email address and current password together as proof that the account belongs to you.


Step 3: Review Your Email Account’s Recent Security Activity

A breach result tells you that information was exposed, but it does not tell you whether someone actually used it. To look for signs of unauthorized access, review your email provider’s recent security and login activity.

Most major providers maintain a record of recently used devices, browsers, sessions, and security changes. Open the provider’s official website or app and look for an area labeled Security, Recent Activity, Devices, Sessions, or Sign-In Activity.

Review information such as:

  • Recently used devices
  • Login dates and times
  • Browser types
  • Operating systems
  • Approximate locations
  • IP addresses, when available
  • Successful and unsuccessful login attempts
  • Password changes
  • Recovery-information updates
  • New application permissions
  • Multifactor authentication changes

Compare More Than the Location

An unfamiliar city or country can be concerning, but location data is not always exact.

A legitimate login may appear in a different place because of:

  • A mobile network
  • A VPN
  • Your internet provider’s routing
  • Travel
  • A workplace or school network
  • Cloud-based security services

Instead of relying only on location, compare several details:

  • Do you recognize the device?
  • Does the browser match one you use?
  • Did the activity occur while you were online?
  • Were you travelling at the time?
  • Did the session change any account settings?
  • Did it happen before an unexpected MFA prompt?
  • Are there repeated attempts from several locations?

A login from a nearby city on your usual phone may be legitimate. A login from an unknown computer followed by a recovery-email change is much more suspicious.

Review Active Sessions and Trusted Devices

An attacker may remain signed in even after you notice the problem. Check the list of active sessions and trusted devices for anything you do not recognize.

Remove unfamiliar devices and use the option to sign out of all other sessions when available. You may need to sign back in on your own phone, tablet, computer, or email application afterward.

Signing out sessions is important because changing the password may not always end every existing connection immediately. It can also help remove access obtained through a stolen browser session or login cookie.

Record Suspicious Activity Before Removing It

When possible, save basic evidence before signing out an unfamiliar session.

You may want to record:

  • The device name
  • Approximate location
  • Date and time
  • IP address
  • Browser type
  • Security changes
  • Related notification emails

Screenshots can be useful if you later need to contact the provider, report fraud, notify an employer, or explain unauthorized activity to a bank.

Do not delay securing the account simply to collect extensive evidence. Capture what you can quickly, then remove the session and protect the account.


Step 4: Check Forwarding Rules, Filters, and Connected Apps

Changing the password is not enough if an attacker has created another way to access your messages. They may add a forwarding address, create hidden inbox rules, approve a third-party application, or generate an app-specific password.

These changes can allow information to continue leaving the account even after the main password has been replaced.

Review Automatic Email Forwarding

Open your email settings and check whether incoming messages are being forwarded to another address.

A forwarding address may be legitimate if you set it up for work, school, or another inbox. Remove it immediately when you do not recognize it.

Attackers may forward:

  • All incoming messages
  • Password-reset emails
  • Bank notifications
  • Invoices and payment messages
  • Travel confirmations
  • Messages from specific contacts
  • Emails containing sensitive keywords

Some providers send a warning when forwarding is enabled, but an attacker may delete or hide that notification.

Inspect Inbox Rules and Filters

Inbox rules automatically move, label, archive, forward, or delete messages. Attackers can misuse them to hide evidence of account activity.

Look for rules that:

  • Delete security alerts
  • Mark messages as read
  • Move emails into unusual folders
  • Hide replies from banks or online services
  • Forward messages to another account
  • Target words such as password, payment, invoice, or verification
  • Apply to messages from the email provider itself

Delete any rule you did not create or cannot explain.

Also check the Trash, Spam, Archive, and custom folders for missing security alerts or password-reset emails. A malicious filter may have been routing them away from the main inbox.

Review Connected Applications

Many websites and applications allow users to sign in with an email, Google, Microsoft, or Apple account. Others request permission to read messages, access contacts, or manage files.

Review the list of third-party applications connected to your account and remove anything that:

  • You do not recognize
  • You no longer use
  • Requests more access than it needs
  • Was added around the time suspicious activity began
  • Has an unclear name or publisher
  • Came from an unknown browser extension or mobile app

Removing a connection may sign you out of the related service or stop it from working. That inconvenience is preferable to leaving an unknown application with access to your inbox.

Check App-Specific Passwords and Email Clients

Some accounts support app-specific passwords for older email programs or devices that cannot use standard multifactor authentication. These passwords may continue working separately from your normal login.

Delete unfamiliar app passwords and recreate only the ones you genuinely need.

You should also review access through:

  • Desktop email programs
  • Mobile mail applications
  • IMAP and POP connections
  • Calendar and contact applications
  • Browser extensions
  • Automated business tools
  • Backup and archiving services

An email client you no longer use may still have an active connection to the account.

Confirm Recovery and Delegated Access Settings

Before leaving the security settings, check:

  • Recovery email addresses
  • Recovery phone numbers
  • Trusted devices
  • Emergency contacts
  • Delegated mailbox access
  • Shared-account permissions
  • Account aliases

Remove any address, phone number, person, or device you do not recognize. Attackers sometimes add their own recovery method so they can regain control after the owner changes the password.

Once you have reviewed forwarding, filters, connected apps, and recovery options, sign out other sessions and change the password if you have not already done so. These checks help close the less obvious access points that can remain after an account compromise.


What to Do Immediately If Your Password Was Exposed

If a password appears in a breach warning or password-security check, you should treat it as unsafe. Even when the related account looks normal, criminals may already possess the password and could try using it now or in the future.

The response should go beyond changing a single login. You also need to consider where else the password was used, whether someone is still signed in, and whether the account contains access to more sensitive services.

Change the Exposed Password

Open the affected service through its official website or app and replace the password as soon as possible.

Create a password that is:

  • Completely different from the old one
  • Unique to that specific account
  • Long enough to resist guessing
  • Unrelated to your name, birthday, address, or other personal details
  • Not based on a common phrase or keyboard pattern

Avoid making a small change to the exposed password. Adding a number, replacing one letter with a symbol, or updating the year does not create a strong replacement.

For example, changing Mountain2025! to Mountain2026! leaves the main pattern intact. Attackers frequently test these predictable variations.

A password manager can generate and store a random password so you do not need to remember it yourself.

Change It Everywhere You Reused It

Password reuse is one of the main reasons a single breach can lead to several account takeovers.

Attackers often use automated tools to test stolen email-and-password combinations on many popular websites. This technique is called credential stuffing. It relies on the fact that many people use the same login details for email, shopping, social media, streaming, and financial services.

Search your saved passwords and think carefully about where you may have reused the exposed credential. Change every account that uses the same password or a closely related version.

Prioritize accounts in this order:

  1. Your primary email account
  2. Your password manager
  3. Banking and payment services
  4. Your main Google, Apple, or Microsoft account
  5. Mobile carrier accounts
  6. Cloud storage
  7. Work or school services
  8. Social media
  9. Shopping accounts
  10. Entertainment and subscription services

Do not reuse the new password on any of these accounts. Each one should receive its own unique credential.

Sign Out Other Devices and Sessions

Changing the password may not immediately remove every active connection to the account.

Look for an option such as:

  • Sign out everywhere
  • Log out all devices
  • End other sessions
  • Remove trusted devices
  • Revoke active sessions

Use this option when you suspect that someone else may already be signed in. You may need to log back in on your own phone, computer, tablet, browser, or email application afterward.

Ending active sessions is particularly important when an attacker may have stolen a browser cookie or session token. In some situations, this type of access can remain active without requiring the password again.

Remove Unrecognized Access

Review the account’s security settings for changes made by someone else.

Remove any unfamiliar:

  • Devices
  • Recovery email addresses
  • Phone numbers
  • Connected applications
  • Browser extensions
  • App-specific passwords
  • Trusted sessions
  • Forwarding addresses
  • Inbox rules
  • Delegated users

Do not assume the problem is solved simply because the main password has changed. An attacker may have created another way to regain access later.

Enable Multifactor Authentication

Turn on multifactor authentication, also known as MFA or two-factor authentication, wherever it is available.

MFA adds another verification step beyond the password. Depending on the account, this could involve:

  • An authenticator app
  • A passkey
  • A hardware security key
  • A push notification
  • A text-message code
  • A code sent to another trusted device

An authenticator app, passkey, or hardware security key generally provides stronger protection than relying only on text messages. However, any supported MFA method is usually safer than using a password alone.

Store backup or recovery codes in a secure location. Do not leave the only copy inside the email account they are meant to protect.

Watch the Account After Securing It

Continue monitoring the account after making these changes.

Look for:

  • New login alerts
  • Unexpected MFA prompts
  • Password-reset messages
  • Changes to account settings
  • Purchases you do not recognize
  • Messages sent without your knowledge
  • New connected applications
  • Attempts to recover the account

An exposed password may have been copied or traded among several groups. Blocking one attempt does not guarantee that no one else will try using it later.


Secure Your Email Account Before Fixing Other Accounts

When several accounts may be at risk, start with your primary email account.

Your inbox often acts as the recovery centre for nearly everything else you use online. Banks, shopping sites, social networks, cloud services, and other platforms may send password-reset links or security codes to that address.

If an attacker still controls your email, they may be able to undo password changes made elsewhere.

Why Your Email Account Comes First

A compromised inbox may allow someone to:

  • Reset passwords for other services
  • Approve account-recovery requests
  • Read security notifications
  • Find usernames and account numbers
  • Access personal documents and attachments
  • Impersonate you to friends or businesses
  • Search for financial or identity information
  • Intercept verification links

For this reason, changing a social media or shopping password first may not help for long. An attacker with access to the email account could simply request another reset.

Use a Trusted Device

Secure the email account from a device you believe is safe.

Ideally, use:

  • A computer or phone you regularly control
  • An updated operating system and browser
  • A device without suspicious software or extensions
  • A familiar home or mobile connection

When you suspect that your usual device contains malware, use another trusted device for urgent account changes. You can return to the potentially infected device after the most important accounts are protected.

Avoid changing passwords from public or shared computers.

Follow the Correct Order

A practical recovery order is:

  1. Check the device for obvious malware or suspicious software.
  2. Change the email password.
  3. Confirm the recovery email address and phone number.
  4. Enable MFA or add a passkey.
  5. Save fresh recovery codes.
  6. Sign out all other sessions.
  7. Remove unfamiliar devices.
  8. Inspect forwarding rules and filters.
  9. Revoke unknown connected applications.
  10. Begin securing other affected accounts.

This order helps prevent an attacker from using the email account to regain access elsewhere.

Verify Recovery Information

Check every recovery option connected to the email account.

Make sure that:

  • The recovery email belongs to you
  • The listed phone number is correct
  • Trusted devices are familiar
  • Backup contacts are legitimate
  • No unknown alias has been added
  • Security questions have not been changed

Attackers may replace recovery information before changing anything obvious. Their goal may be to return later, even after you notice the original intrusion.

Update outdated recovery details as well. An old phone number or inaccessible email address can make it harder for you to recover the account during an emergency.

Save Recovery Codes Safely

Many email providers offer one-time recovery or backup codes when MFA is enabled.

Store these codes somewhere that is:

  • Secure
  • Accessible during an account lockout
  • Separate from the protected inbox
  • Not visible to other people

A password manager, encrypted file, or securely stored printed copy may be appropriate. Avoid saving the only copy in the email account itself.

Use the Official Recovery Process If You Are Locked Out

If someone changed the password or recovery information, begin the provider’s official account-recovery process.

Use a familiar device and network when possible. Providers may use your previous login habits, location, device, recovery information, and account history to verify ownership.

Be prepared to provide details such as:

  • A previous password
  • The approximate account-creation date
  • A recovery address or phone number
  • Frequently contacted addresses
  • Recent account activity

Do not trust strangers who claim they can recover the account for a fee. So-called account-recovery hackers commonly target people who are already worried and vulnerable. Only the provider can legitimately restore access to its account.


Check the Device for Malware Before Entering New Passwords

Not every stolen password comes from a company data breach. Malware may collect credentials directly from your computer, phone, or browser.

If the device remains infected, changing your passwords may offer only temporary protection. The malicious software could capture each replacement password as soon as you enter it.

How Malware Can Steal Login Information

Credential-stealing malware may collect:

  • Saved browser passwords
  • Information entered into login forms
  • Browser cookies
  • Active session tokens
  • Autofill information
  • Cryptocurrency wallet data
  • Screenshots
  • Clipboard contents
  • Files and documents
  • Email and messaging credentials

Some threats focus specifically on stealing information and sending it to criminals. These programs are often called infostealers.

Attackers may also use malicious browser extensions, fake login pages, remote-access tools, or software designed to record keyboard input.

Consider What Happened Before the Warning Signs Began

Think about any recent activity that could have exposed the device.

Risk may be higher if you recently:

  • Installed cracked or pirated software
  • Opened an unexpected attachment
  • Downloaded a fake browser or software update
  • Installed an unknown browser extension
  • Ran a file from an advertisement or pop-up
  • Disabled antivirus protection to install something
  • Allowed an unfamiliar person to access the computer remotely
  • Downloaded software from an unofficial website
  • Opened a suspicious archive or executable file

A password leak warning does not prove that malware is present, but suspicious activity around the same time deserves investigation.

Update the Device First

Install available updates for:

  • The operating system
  • Web browsers
  • Security software
  • Email applications
  • Frequently used programs

Updates may fix security weaknesses that malware or attackers could exploit.

Restart the device after completing important updates when prompted.

Remove Suspicious Programs and Extensions

Review installed applications and browser extensions.

Remove anything that:

  • You do not remember installing
  • Appeared around the time the problem began
  • Has an unclear name or publisher
  • Claims to provide unnecessary browser features
  • Changes search results or the home page
  • Displays excessive pop-ups
  • Requests access to every website you visit
  • Was downloaded from an unofficial source

Be cautious when deleting software from a work or school device. Contact the organization’s IT team if you are unsure whether a program is legitimate.

Run a Full Security Scan

Use trusted, updated security software to perform a full system scan rather than only a quick scan.

A full scan may take longer, but it examines more files and locations. Follow the security program’s recommendations for quarantining or removing detected threats.

You may also use the operating system’s built-in offline or restart-based scanning option when available. This can help detect malware that tries to hide while the normal system is running.

Avoid installing several real-time antivirus products at the same time, since they may conflict with one another.

Review Startup Programs and Browser Settings

Check whether unfamiliar applications automatically start when the device turns on.

Also review the browser for:

  • A changed home page
  • An unfamiliar search engine
  • New extensions
  • Modified notification permissions
  • Unwanted proxy settings
  • Saved passwords you do not recognize
  • Unexpected site permissions

Resetting the browser may help when its settings have been heavily modified, but make sure important bookmarks or data are backed up first.

Use Another Device for Urgent Password Changes

When you strongly suspect malware, use a different trusted device to secure your primary email, password manager, and financial accounts.

After the affected device has been cleaned, change critical passwords again if you entered them while the malware may have been active.

This extra step is important because you cannot know with certainty which credentials the malware captured.

Revoke Active Sessions

Some malware steals browser sessions rather than only passwords. A stolen session token may allow an attacker to access an account without entering the password or completing MFA again.

Sign out all active sessions and remove unfamiliar trusted devices after changing your credentials. This helps invalidate access that may have been copied from the infected device.


What to Do If Someone Has Already Accessed the Account

When recent activity confirms that another person entered the account, treat the situation as an active security incident.

Your goal is to remove the intruder, prevent them from returning, identify what they may have accessed, and limit damage to other accounts.

Secure the Account Immediately

From a trusted device:

  1. Change the password.
  2. Sign out all active sessions.
  3. Enable MFA.
  4. Remove unfamiliar devices.
  5. Restore the correct recovery information.
  6. Delete unauthorized app passwords.
  7. Revoke suspicious connected applications.
  8. Remove unknown forwarding rules and filters.

Do not reuse a password from another account.

When the provider gives you the option, review recent security changes and mark unfamiliar activity as unauthorized.

Examine the Entire Mailbox

Do not check only the main inbox.

Review:

  • Sent messages
  • Drafts
  • Deleted items
  • Trash
  • Spam
  • Archived messages
  • Custom folders
  • Forwarding settings
  • Inbox filters

Look for messages you did not create, password resets you did not request, and replies from contacts who received suspicious messages.

Attackers may delete evidence after using the account, so missing messages or unusually empty folders may also be significant.

Check Other Accounts for Damage

Search the inbox for recent account notifications, including:

  • Password changes
  • New-device alerts
  • Purchases
  • Money transfers
  • Subscription changes
  • Recovery requests
  • New accounts
  • Verification codes
  • Shipping confirmations

Open the relevant service directly rather than clicking links inside suspicious emails.

Change passwords and review activity for any account that shows unexplained changes.

Warn Your Contacts

If the attacker sent messages from your account, notify the people who may have received them.

Tell them not to:

  • Click recent unexpected links
  • Open unusual attachments
  • Send money
  • Purchase gift cards
  • Share passwords or verification codes
  • Continue suspicious conversations

Keep the warning simple and factual. Criminals may imitate your usual tone, continue an existing conversation, or refer to real details found in your inbox.

Contact Financial Providers Quickly

When you find an unrecognized purchase, transfer, or payment-account change, contact the bank, card issuer, or payment service immediately.

Use the phone number on the official website, app, bank card, or statement. Do not call a number supplied in a suspicious email or text.

Ask the provider to:

  • Block or reverse unauthorized transactions when possible
  • Secure the account
  • Replace affected cards
  • Review recent activity
  • Add stronger verification
  • Document the fraud report

The faster you report financial fraud, the more options the provider may have to limit the damage.

Notify Your Workplace or School

If the affected account belongs to an employer, school, or organization, report the incident to its IT or security team immediately.

Do not attempt to investigate or clean a managed device on your own unless instructed. The organization may need to:

  • Preserve evidence
  • Reset credentials
  • Review network activity
  • Check whether other accounts were affected
  • Notify customers or staff
  • Meet legal or regulatory obligations

Even a personal email compromise should be reported when it exposed workplace documents, customer information, internal messages, or company passwords.

Preserve Basic Evidence

Save relevant information such as:

  • Security-alert emails
  • Screenshots of login activity
  • Dates and times
  • Device names
  • Approximate locations
  • Suspicious messages
  • Transaction records
  • Changes to recovery settings
  • Communication with providers

Do not keep sensitive evidence only inside the compromised account. Store a copy somewhere secure.

Evidence may be useful when contacting the email provider, bank, employer, law enforcement, or an identity-theft reporting service.

Contact the Email Provider

Use the provider’s official support or recovery system when:

  • You cannot remove the attacker
  • The password keeps changing
  • Recovery information was replaced
  • Suspicious sessions return
  • Messages or contacts were deleted
  • The account has been suspended
  • You cannot complete account recovery

Provide clear dates, screenshots, and descriptions of unauthorized activity where possible.

Continue Monitoring

An account takeover may affect more than the service where you first noticed it.

For the next several weeks, watch for:

  • New login attempts
  • Unexpected MFA prompts
  • Password-reset messages
  • Financial activity
  • Mobile carrier changes
  • New credit or service accounts
  • Targeted phishing messages
  • Contacts reporting unusual communication

Once criminals obtain personal information, they may use it later or share it with others. Continued monitoring helps you catch follow-up attempts before they become more serious.


What If Your Email Appears in a Breach but the Password Does Not?

Seeing your email address in a breach report can be unsettling, even when the incident does not list passwords among the exposed information. The good news is that an exposed email address does not automatically mean that criminals can sign in to your inbox.

However, the result should not be ignored.

An email address can still help attackers identify active accounts, create convincing phishing messages, and connect information collected from different breaches. The risk becomes greater when the incident also exposed personal details such as your name, phone number, home address, date of birth, or purchase history.

Review Exactly What Was Exposed

Start by reading the breach description carefully. Look for the categories of information included in the incident.

The breach may have exposed:

  • Email addresses
  • Names and usernames
  • Phone numbers
  • Physical addresses
  • Dates of birth
  • Account activity
  • Purchase or subscription history
  • Security questions
  • Payment details
  • Password hashes

Even if the service says that passwords were not included, check whether recovery information or other sensitive data was affected.

For example, exposed security-question answers could make it easier for someone to attempt account recovery. A leaked phone number could also support targeted text-message scams or attempts to take control of a mobile account.

Consider Whether You Reused a Password on the Affected Service

A breach report may not always provide a complete picture of the exposed data. The affected company may also update its findings as the investigation continues.

Change the account password when:

  • You reused it elsewhere
  • It is weak or easy to guess
  • It has not been changed in years
  • The affected service recommends a reset
  • You used the account around the time of the breach
  • You are unsure whether password data was involved

Create a unique replacement rather than moving the same password to another account.

Expect More Targeted Phishing

After a breach, attackers may send messages that appear to come from the affected company.

Because they may already know your name, email address, account type, or recent purchase history, the message can look more believable than an ordinary scam.

Be cautious of emails or texts that ask you to:

  • Confirm your password
  • Verify payment details
  • Download a security update
  • Open a breach report
  • Call an urgent support number
  • Pay to prevent account closure
  • Provide a multifactor authentication code

Open the company’s official website or app directly instead of using the link in the message.

A criminal does not need your email password to cause harm. Exposed personal details can be enough to make a phishing attempt feel legitimate.

Strengthen the Account Anyway

Even when the breach involved only an email address, it is still a good time to improve the account’s security.

Consider taking the following steps:

  • Enable multifactor authentication
  • Review recent account activity
  • Remove unused connected applications
  • Update weak or reused passwords
  • Turn on login notifications
  • Confirm recovery information
  • Watch for unexpected password-reset requests

You usually do not need to abandon the email address simply because it appeared in a breach. Focus first on securing the account and becoming more cautious about targeted messages.


What If the Breach Happened Years Ago?

Old breach data should not be dismissed simply because the incident happened several years ago. Stolen information can remain valuable for a long time, especially when passwords, personal details, or recovery information are still in use.

Criminals may combine older breach records with newer data to build a more complete profile of a person. They can also continue testing old passwords and predictable variations across current websites.

Check Whether the Password Is Still in Use

The most important question is whether you still use the exposed password anywhere.

Change it immediately when:

  • It remains active on the breached account
  • You reused it on another website
  • You still use a similar variation
  • It forms the pattern behind several current passwords
  • It protects an old account that remains open

Do not assume that a password is safe because attackers have not used it yet. Stolen credentials may be stored, resold, combined with other data, or tested long after the original breach.

Avoid Predictable Password Updates

Many people respond to a breach by changing only one part of the password.

Examples include:

  • Changing Summer2021! to Summer2026!
  • Adding another number to the end
  • Replacing one letter with a symbol
  • Capitalizing a different word
  • Adding the website name

These updates remain closely connected to the exposed password. Automated tools can test common substitutions and year changes quickly.

A safer replacement should use a completely different structure.

Review Old Accounts That Still Exist

An old account may still contain useful information or remain connected to current services.

Check whether the breached account includes:

  • Saved payment methods
  • Personal messages
  • Home addresses
  • Phone numbers
  • Cloud files
  • Linked social accounts
  • Recovery access to another service

Secure the account if you still need it. Delete it through the provider’s official account settings when it is no longer useful and the provider offers a reliable deletion option.

Deleting an account does not remove copies of data already taken during a breach, but it can reduce future exposure and prevent someone from misusing an abandoned profile.

Update Old Security Questions

Security-question answers can remain risky for years because the facts behind them may never change.

A breach could expose answers related to:

  • A childhood address
  • A family member’s name
  • A school
  • A pet
  • A favourite place
  • A date or personal event

Replace these answers where possible. You do not necessarily need to provide a factually accurate response. A password manager can store a unique, random answer for each account.

The goal is to prevent someone from finding or guessing the answer through public records, social media, or previous breach data.

Stay Alert for Scams Using Old Information

A message may reference an old password, address, phone number, or account to make a threat seem current.

For example, a scammer may include a password from an old breach and claim to have recently hacked your device. The presence of a real old password can make the message frightening, but it does not prove that the rest of the claim is true.

Do not reply, pay, or follow instructions in the message. Secure any account that still uses the exposed password and report the communication as spam or phishing.

An old breach may no longer represent an active emergency, but it is still a useful warning. It can reveal password habits and forgotten accounts that need to be corrected.


How to Create a Safer Replacement Password

A replacement password should not be a slightly modified version of the exposed one. It should be unique, long, and unrelated to personal information.

The main goal is to make sure that a password stolen from one company cannot unlock any other account.

Use a Unique Password for Every Account

Never use the same password for email, banking, shopping, social media, and entertainment accounts.

When each account has a unique password, a breach at one service remains more contained. Attackers cannot simply take the stolen credential and use it everywhere else.

Unique passwords are particularly important for:

  • Your primary email
  • Password manager
  • Financial accounts
  • Mobile carrier
  • Cloud storage
  • Google, Apple, or Microsoft account
  • Work and school services

These accounts can provide access to sensitive information or help an attacker reset other passwords.

Make the Password Long

Length is one of the most important characteristics of a strong password.

A longer password creates many more possible combinations and is generally harder to guess than a short password that contains a few symbols.

When the service allows it, aim for a password or passphrase that is at least 14 to 16 characters long, with more length for highly sensitive accounts.

Do not shorten a password simply because it contains uppercase letters, numbers, and symbols. A short, complicated password may still be weaker than a much longer random one.

Avoid Personal and Predictable Information

Do not build passwords around details that someone could discover or guess.

Avoid using:

  • Your name or initials
  • Birthdays
  • Family names
  • Pet names
  • Phone numbers
  • Addresses
  • School or team names
  • Favourite bands or movies
  • Common quotations
  • Simple keyboard patterns
  • The name of the website

Attackers may collect these details from social media, public records, old breaches, or information already present in the email account.

Use a Password Manager-Generated Password

A password manager can create a long, random password for each account.

A generated password may look difficult to remember, but you usually do not need to memorize it. The password manager stores and fills it when needed.

This approach works especially well for:

  • Shopping accounts
  • Streaming services
  • Social media
  • Online forums
  • Utility accounts
  • Services you access mainly through an app

Make sure that the password manager itself is protected with a strong, unique master password and multifactor authentication.

Use a Long Passphrase When You Need to Remember It

A passphrase combines several words into a longer password.

It may be useful for a password you need to enter manually, such as the master password for a password manager.

Choose words that are unrelated and difficult to predict. Avoid:

  • Famous quotations
  • Song lyrics
  • Common sayings
  • Movie lines
  • Personal stories
  • Predictable phrases

A random sequence of unrelated words is generally safer than a meaningful sentence that someone may guess.

You can also include separators or additional characters when the service requires them, but the strength should come mainly from the passphrase’s length and unpredictability.

Do Not Share or Send Passwords

Avoid sending passwords through:

  • Email
  • Text messages
  • Social media
  • Workplace chat
  • Unencrypted notes
  • Shared documents

When an account must be shared, use the password-sharing feature in a reputable password manager or create separate user access where the service supports it.

Never give a password or MFA code to someone claiming to be customer support. A legitimate support representative should not need your current password.

Change Passwords When There Is Evidence of Risk

You do not need to replace every strong, unique password on a fixed monthly schedule.

Change a password when:

  • It appears in a breach
  • The account reports suspicious activity
  • Someone else may know it
  • You entered it into a phishing site
  • It was stored on an infected device
  • You reused it
  • A provider instructs you to reset it after an incident

Unnecessary password changes can encourage predictable patterns. Focus on creating strong, unique credentials and replacing them when there is a real reason.


Use a Password Manager to Find and Eliminate Password Reuse

Remembering a different long password for every account is unrealistic for most people. A password manager solves this problem by creating, storing, and filling unique credentials.

It can also help you find weak, reused, and compromised passwords that would otherwise be easy to overlook.

How a Password Manager Helps

Depending on the product, a password manager may help you:

  • Generate long, random passwords
  • Store credentials in an encrypted vault
  • Fill passwords automatically
  • Identify reused passwords
  • Flag weak credentials
  • Warn about known compromised passwords
  • Organize recovery codes
  • Sync passwords across trusted devices
  • Share selected credentials more safely

These features make it easier to stop using one password pattern across many websites.

Start With the Most Important Accounts

You do not need to update every login in one sitting.

Begin with the accounts that could cause the greatest damage if compromised:

  1. Primary email
  2. Password manager
  3. Bank and payment services
  4. Mobile carrier
  5. Google, Apple, or Microsoft account
  6. Cloud storage
  7. Work or school accounts
  8. Social media

Once these are protected, continue with shopping, entertainment, forums, and less frequently used services.

Use the Security or Password-Health Report

Many password managers include a dashboard that identifies:

  • Reused passwords
  • Compromised passwords
  • Weak passwords
  • Old credentials
  • Accounts without MFA
  • Duplicate or outdated entries

Begin with passwords marked as both compromised and reused. These create the clearest opportunity for credential-stuffing attacks.

Open each service through its official website or app, change the password, and then update the saved entry in the password manager.

Protect the Master Password

The master password protects the entire vault, so it must be especially strong.

It should be:

  • Unique to the password manager
  • Long and difficult to guess
  • Never reused elsewhere
  • Not stored in ordinary notes or email
  • Supported by MFA where available

A long random passphrase can work well because you may need to remember and type it manually.

Do not use the password manager’s master password for your email, computer login, or any other service.

Turn On Multifactor Authentication

Enable MFA for the password-manager account when the provider supports it.

An authenticator app, passkey, or hardware security key can add protection if someone learns the master password.

Save recovery codes in a secure place outside the vault when appropriate. This can help you recover access if you lose the device used for authentication.

Remove Outdated and Duplicate Entries

Password vaults can become cluttered with old logins, duplicate records, and accounts that no longer exist.

Review the vault periodically and:

  • Update old website addresses
  • Delete duplicate entries
  • Mark inactive accounts
  • Close accounts you no longer need
  • Remove obsolete passwords
  • Confirm that saved usernames are correct

Cleaning the vault makes security warnings easier to understand and reduces the chance of using an outdated credential by mistake.

Remember That a Password Manager Is Not Complete Protection

A password manager greatly reduces password reuse, but it does not protect against every threat.

You still need to:

  • Keep devices updated
  • Avoid phishing pages
  • Review login alerts
  • Reject unexpected MFA prompts
  • Remove suspicious browser extensions
  • Scan for malware
  • Protect recovery codes
  • Secure your email account

A password manager works best as part of a broader security routine. Its greatest benefit is simple but important: one breached website no longer needs to put every other account at risk.


Turn On MFA, Passkeys, and Account Alerts

A strong, unique password is essential, but it should not be your account’s only line of defence. Multifactor authentication, passkeys, and security alerts can make it much harder for someone to take over an account—even when they already know the password.

These protections are especially important for your primary email, password manager, financial services, cloud storage, mobile carrier account, and main Google, Apple, or Microsoft account.

Enable Multifactor Authentication

Multifactor authentication, often shortened to MFA, requires another form of verification in addition to the password.

Depending on the service, the second step may involve:

  • An authenticator app
  • A hardware security key
  • A passkey
  • A push notification
  • A code sent by text message
  • A code sent to another trusted device
  • A biometric check, such as a fingerprint or face scan

This extra step can block many account-takeover attempts. An attacker may enter the correct password but still be unable to complete the login.

Whenever possible, avoid relying on a password alone.

Choose the Strongest Available Method

Not all MFA methods provide the same level of protection.

A practical preference order is:

  1. Passkey or hardware security key
  2. Authenticator app
  3. Push approval with number matching
  4. Text-message or email code
  5. Password alone

The exact options will depend on the service.

Hardware security keys and passkeys provide strong protection against many phishing attacks because they are designed to work only with the legitimate website or app. Authenticator apps are also a strong option because the generated codes are not delivered through the mobile network.

Text-message codes still provide useful protection, but they may be more vulnerable to phone-number theft, message interception, or social engineering. Even so, SMS-based MFA is generally safer than leaving the account protected by only a password.

Understand How Passkeys Work

A passkey lets you sign in using a trusted device, fingerprint, face scan, device PIN, or security key instead of a traditional reusable password.

The website stores a public credential, while the private part remains on your device or in your protected account ecosystem. This design means there is no ordinary password for a criminal to steal from the website and reuse elsewhere.

Passkeys can also reduce phishing risk because they normally work only with the correct service. A fake login page cannot simply collect and reuse them in the same way it can steal a password.

When a trusted account offers passkeys, consider adding one after confirming that your recovery options are current.

Never Approve an Unexpected Prompt

An unexpected MFA request often means that someone is trying to sign in.

Do not approve a request simply because it appears repeatedly. Attackers sometimes send many notifications in the hope that the account owner will tap Approve out of confusion or annoyance.

When you receive an unexpected request:

  • Deny it
  • Do not share any displayed code
  • Change the account password
  • Review recent login activity
  • Sign out unfamiliar sessions
  • Confirm that recovery information has not changed

Some push-based systems display a number on the login screen that must be matched in the authentication app. This feature can reduce accidental approvals, but you should still reject any request you did not initiate.

Store Recovery Codes Securely

MFA-protected accounts often provide one-time recovery or backup codes.

These codes can help you regain access when you lose your phone, replace a device, or cannot use the normal authentication method.

Keep recovery codes:

  • Somewhere private and secure
  • Separate from the protected account
  • Out of your ordinary email inbox
  • Away from shared notes or documents
  • Accessible during a genuine lockout

A password manager, encrypted file, or securely stored printed copy may be appropriate.

Do not send recovery codes to anyone. A person who obtains one may be able to bypass the normal authentication step.

Enable Login and Security Alerts

Turn on notifications for important account events, including:

  • New-device sign-ins
  • Password changes
  • Recovery-information updates
  • MFA changes
  • New connected applications
  • Suspicious login attempts
  • Financial transactions
  • Account-recovery requests

Security alerts help you react before an attacker has time to make additional changes.

Make sure these notifications go to an address or device that you still control. If all alerts are sent only to the potentially compromised inbox, an attacker may delete them before you see them.

Review Trusted Devices Periodically

Accounts may remember devices and allow them to sign in with fewer verification steps.

Review the trusted-device list occasionally and remove:

  • Old phones
  • Previous computers
  • Shared devices
  • Devices you sold or gave away
  • Browsers you no longer use
  • Anything you do not recognize

Keeping this list current reduces the number of places from which someone could potentially regain access.


Watch for Phishing After a Publicized Data Breach

A major breach often creates a second wave of danger: phishing messages that pretend to help affected customers.

Criminals know that people are worried after hearing about a leak. They may send fake security alerts, password-reset notices, refund offers, or account-verification requests that appear to come from the affected company.

Because some personal information may already be exposed, these messages can look unusually convincing.

Common Breach-Related Phishing Messages

A fraudulent email, text, or pop-up may claim:

  • Your account will be closed unless you act
  • Your password was found on the dark web
  • You need to confirm whether your information leaked
  • You qualify for a refund or compensation payment
  • Your mailbox has exceeded its storage limit
  • Your account has been suspended
  • You must install an urgent security update
  • A support representative needs to verify your identity
  • Your payment method must be updated immediately

The message may use the correct company name, your real email address, or other details taken from the breach.

Personal information makes a scam more believable, but it does not make the message legitimate.

Do Not Use Unexpected Login Links

When a message tells you to secure an account, avoid clicking its login button.

Instead:

  1. Open the provider’s official app.
  2. Enter the known website address into the browser.
  3. Use a trusted bookmark.
  4. Navigate to the account’s security settings.
  5. Check whether the same warning appears there.

A phishing page may look nearly identical to the real website. Its purpose is to collect your password, MFA code, payment information, or recovery details.

Also check the website address carefully. Criminals may use misspellings, extra words, unusual domains, or lookalike characters.

Never Share Passwords or Verification Codes

A legitimate company should not ask you to reply with your password or read an MFA code to an unexpected caller.

Do not share:

  • Current passwords
  • One-time login codes
  • Recovery codes
  • Security-question answers
  • Password-reset links
  • Full payment-card details
  • Remote access to your device

A code sent to your phone or email is usually intended only for the login you started. Anyone requesting that code may be trying to complete a login as you.

Be Careful With Phone Support Scams

Some phishing messages instruct victims to call a fake support number.

The person answering may claim that:

  • Your device contains malware
  • Your bank account is being attacked
  • A refund must be processed
  • Your identity has been stolen
  • They need remote access to fix the problem
  • You must move money to a secure account

Never install remote-access software or provide control of your device to someone who contacted you unexpectedly.

Use only the support number listed in the provider’s official app, website, account statement, or payment card.

Avoid Fake Breach-Checking Tools

A scammer may offer to reveal exactly which password was exposed.

Be suspicious when a website or message asks you to:

  • Enter your email and password together
  • Download a special breach scanner
  • Pay to remove your information from a leak
  • Provide payment details before viewing results
  • Install an unknown browser extension
  • Sign in with your email account to continue

Use established breach-checking services, trusted password managers, and official account-security tools instead.

No legitimate breach checker needs your current email password simply to search for an exposed address.

Verify Claims Through Independent Sources

When a message refers to a real company breach, verify the incident separately.

Check:

  • The company’s official website
  • Its official security or news page
  • Your account notifications
  • Reputable news coverage
  • A trusted breach-monitoring service

Do not rely on contact information or links included in the suspicious message itself.

Expect Phishing to Continue

Breach-related scams may continue long after the original event.

Criminals can reuse exposed information to target you with messages about:

  • Account renewals
  • Package deliveries
  • Tax refunds
  • Subscription payments
  • Financial warnings
  • Password resets
  • Customer-support requests

Remain cautious even when a message contains real information. The strongest clue is not whether the sender knows something about you, but whether the message pressures you to reveal more information or take an unusual action.


Not every urgent-looking security email is legitimate. Our guide on how to identify phishing emails in seconds explains the warning signs to check before clicking a link, downloading an attachment, or entering your login information.


Should You Change Your Email Address After a Breach?

An email address does not usually need to be abandoned simply because it appeared in a data breach.

Email addresses are often exposed through shopping sites, forums, subscription services, and social networks. In many cases, the inbox itself remains secure and can continue to be used safely after you strengthen the account.

Changing your address may also create practical problems because it can be connected to years of accounts, contacts, documents, and recovery settings.

When You Can Usually Keep the Address

Keeping the existing address may be reasonable when:

  • You still control the account
  • The password has been changed
  • MFA or a passkey is enabled
  • Recovery information is correct
  • Unfamiliar sessions have been removed
  • There are no malicious forwarding rules
  • The main problem is ordinary spam or phishing
  • You can still reliably receive security alerts

An exposed address may receive more unwanted messages, but spam alone does not mean that the inbox is actively compromised.

Use filters and reporting tools to manage unwanted mail, and remain careful with unexpected links and attachments.

When a New Address May Be Worth Considering

Creating a new address may make sense when:

  • You cannot reliably recover the old account
  • Unauthorized access keeps returning
  • The account has become overwhelmed with targeted scams
  • The address reveals personal information you no longer want public
  • You are experiencing ongoing harassment
  • The address was used publicly for many years
  • You want to separate sensitive accounts from newsletters and registrations
  • The provider cannot offer the security features you need

A new address can reduce some exposure, but it will not erase information that has already leaked. Criminals may continue using the old address in phishing attempts.

Secure the Old Account Before Abandoning It

Do not immediately delete or ignore the old email address.

It may still be connected to:

  • Banking accounts
  • Social media
  • Cloud storage
  • Shopping services
  • Government services
  • Mobile accounts
  • Work or school platforms
  • Password recovery

Before moving away from it:

  1. Secure the old account.
  2. Review its forwarding and recovery settings.
  3. Update important services with the new address.
  4. Change recovery email addresses.
  5. Notify trusted contacts.
  6. Monitor the old inbox for missed account notifications.
  7. Remove sensitive messages and files when appropriate.

Keep access long enough to catch important services you may have forgotten.

Use Different Addresses or Aliases for Different Purposes

You do not always need an entirely separate inbox for every activity. Some providers support aliases that deliver messages to the same account while giving you different addresses to use.

A practical arrangement could include:

  • A private address for banking and account recovery
  • A personal address for friends and family
  • A work or professional address
  • A separate address or alias for shopping and newsletters
  • A temporary alias for low-priority registrations

This separation can reduce clutter and make suspicious messages easier to identify. For example, a banking warning sent to an address used only for newsletters would immediately look suspicious.

Keep the Most Important Address Private

Avoid publishing the email address used for financial accounts, password recovery, and your password manager.

Use a less sensitive address for public profiles, forums, giveaways, newsletters, and unfamiliar services.

No address can remain completely hidden forever, but limiting where your primary address appears can reduce targeted phishing and unwanted account-recovery attempts.


When Exposed Information Creates an Identity-Theft Risk

Not every data breach creates the same level of danger.

An exposed email address may mainly increase spam and phishing. A breach involving government identification, financial records, or detailed personal information can create a much more serious identity-theft risk.

Identity theft occurs when someone uses another person’s information to open accounts, make purchases, obtain services, or impersonate them.

Information That Requires Greater Caution

Take stronger precautions when a breach includes:

  • Government identification numbers
  • Passport or driver’s licence information
  • Tax records
  • Banking details
  • Payment-card numbers
  • Full dates of birth
  • Medical or insurance records
  • Account-recovery information
  • Scans of identification documents
  • Digital signatures
  • Detailed employment records

A name and email address alone usually cannot support every form of identity theft. However, criminals can combine information from several sources to create a more complete profile.

Monitor Financial Accounts

Review bank, credit-card, and payment-service activity for transactions you do not recognize.

Turn on alerts for:

  • Purchases
  • Cash withdrawals
  • Transfers
  • New payees
  • Password changes
  • Contact-information updates
  • Login attempts

Report suspicious activity through the provider’s official contact channels immediately.

A small unfamiliar transaction can sometimes be a test before a larger attempt, so do not ignore it simply because the amount is low.

Replace Exposed Payment Cards

When a breach includes full payment-card details or the provider recommends replacement, contact the card issuer.

Ask whether the card should be:

  • Locked
  • Replaced
  • Monitored
  • Removed from digital wallets
  • Disconnected from recurring services

Update legitimate subscriptions after receiving the replacement card, but verify each request carefully. Criminals may send fake card-replacement messages after a breach.

Consider Fraud Alerts or Credit Freezes

Depending on your country and the information exposed, you may be able to place a fraud alert or credit freeze with credit-reporting agencies.

A fraud alert asks lenders to take additional steps to verify your identity. A credit freeze restricts access to your credit report, which can make it harder for someone to open a new account in your name.

A freeze is more likely to be appropriate when highly sensitive identity information has been exposed—not after every basic email-address leak.

Check the official guidance and credit-reporting options available in your country before taking action.

Protect Your Mobile Account

An exposed phone number can be used in targeted scams or attempts to transfer your number to another SIM card.

Contact your mobile carrier and add a strong account PIN or port-protection feature when available.

Review the account for:

  • Unfamiliar devices
  • SIM changes
  • New lines
  • Contact-information updates
  • Call-forwarding settings
  • Number-transfer requests

A criminal who takes control of a phone number may receive text-message verification codes for other accounts.

Replace Exposed Identity Documents

When a passport, driver’s licence, health card, or other official document was exposed, contact the issuing authority for guidance.

The correct response will depend on:

  • The document type
  • Your country or province
  • Whether the original document was stolen
  • Whether only a number or a full image was exposed
  • Whether there is evidence of misuse

Keep copies of the breach notice and any communication with the affected organization.

Watch for New Accounts and Services

Identity theft may not appear as a charge on an existing account.

Look for signs such as:

  • Bills from unfamiliar companies
  • Credit applications you did not make
  • New mobile or utility accounts
  • Unexpected government correspondence
  • Changes to tax or benefit accounts
  • Debt-collection notices
  • Verification messages from unfamiliar services

Review available credit reports and official account records when sensitive identity information has been exposed.

Preserve Evidence and Report Misuse

Keep records of:

  • Breach notifications
  • Fraudulent transactions
  • Suspicious emails or texts
  • Credit-report changes
  • Account-opening notices
  • Calls with financial institutions
  • Official report numbers
  • Copies of identification used in a claim

Report identity theft through the appropriate government, financial, law-enforcement, or consumer-protection channels in your country.

Do not send additional identity documents to someone who contacts you unexpectedly and claims to be investigating the breach. Verify the organization independently first.

An email-address leak does not always require drastic action. However, when the exposed data can be used to prove identity, access money, or recover other accounts, early monitoring and official reporting can significantly reduce the damage.


What a Breach Checker Can and Cannot Tell You

A breach-checking service can be a useful starting point, but it does not provide a complete security diagnosis.

These tools usually compare an email address or password against information collected from known data breaches. They can help you identify exposed accounts and decide which passwords or services require attention.

However, a clean result does not prove that your accounts are completely safe.

What a Breach Checker Can Tell You

Depending on the service, a breach checker may show:

  • Whether your email address appeared in a known breach
  • Which company or online service was affected
  • The approximate date of the incident
  • The types of information that may have been exposed
  • Whether a password appeared in known stolen-password data
  • Whether new breach information has been added since a previous check

This information can help you identify where a password may have leaked and whether other personal data was involved.

For example, a result may show that an old shopping account exposed email addresses, names, phone numbers, and password hashes. You can then change the affected password, check whether it was reused, and prepare for more targeted phishing.

What a Breach Checker Cannot Confirm

A breach checker usually cannot tell you:

  • Whether someone has logged in to your account
  • Whether criminals have used the exposed information
  • Whether your device contains malware
  • Whether an attacker stole an active browser session
  • Who obtained your information
  • Whether every known or private breach has been included
  • Whether a recent incident has already been discovered
  • Whether identity theft has occurred
  • Whether an account is currently safe

A positive breach result confirms exposure connected to a known incident, but it does not necessarily confirm account takeover.

Similarly, a negative result does not rule out phishing, malware, password guessing, or exposure in a breach that has not yet become public.

Breach Databases May Be Incomplete

Not every stolen database becomes available to security researchers or breach-checking services.

Some breaches may be:

  • Discovered only by the affected company
  • Kept private during an investigation
  • Sold in closed criminal groups
  • Too recent to have been processed
  • Incorrectly labelled
  • Missing important categories of exposed data
  • Connected to malware logs rather than a company breach

The service may also have only part of a larger dataset.

For this reason, you should not ignore suspicious account activity simply because your address does not appear in a breach search.

Password Results Require Context

A password-checking service may tell you that a particular password has appeared in known stolen data. That does not necessarily reveal which account originally used it or whose password it was.

Common passwords can appear many times because thousands of people independently chose the same value.

Regardless of where the password came from, you should avoid using it. A password that appears in known breach data is likely to be included in automated guessing lists.

Combine Breach Checks With Account Reviews

For a more reliable assessment, combine breach checking with other security steps:

  • Review recent login activity
  • Inspect active sessions and trusted devices
  • Check forwarding rules and inbox filters
  • Review connected applications
  • Look for password-manager warnings
  • Scan devices for malware
  • Enable login alerts
  • Monitor financial and account activity

A breach checker is best understood as an early-warning tool, not proof that an account is either hacked or completely secure.


A 15-Minute Compromised-Account Response Checklist

When you discover an exposed password or suspicious login, it can be difficult to know where to begin. The following checklist focuses on the most important actions you can take quickly.

You may need more than 15 minutes to investigate the full incident, but these first steps can help stop ongoing access and reduce further damage.

First Five Minutes: Secure the Main Account

Start with the affected account—or your primary email account if several services may be involved.

  1. Open the official website or app directly.
    Do not use a link from an unexpected email, text, or pop-up.
  2. Change the password.
    Create a completely new and unique password.
  3. Sign out other sessions.
    Use the option to sign out everywhere or remove unfamiliar devices.
  4. Enable multifactor authentication.
    Choose a passkey, security key, or authenticator app where available.
  5. Confirm recovery information.
    Check that the recovery email address and phone number still belong to you.

If you cannot sign in, begin the provider’s official account-recovery process from a familiar device.

Next Five Minutes: Remove Hidden Access

Once the password and recovery settings are secure, check for other ways an attacker may remain connected.

Review and remove unfamiliar:

  • Forwarding addresses
  • Inbox rules
  • Filters
  • Connected applications
  • App-specific passwords
  • Trusted devices
  • Browser sessions
  • Delegated users
  • Account aliases

Also check the Sent, Trash, Spam, Drafts, and Archive folders for activity you do not recognize.

Take quick screenshots of suspicious logins or settings before removing them when evidence may be useful.

Final Five Minutes: Protect Related Accounts

Next, focus on the damage that could spread beyond the original account.

  • Change the password anywhere it was reused.
  • Secure your password manager.
  • Review banking and payment activity.
  • Check recent password-reset emails.
  • Scan your device with updated security software.
  • Warn contacts if suspicious messages were sent.
  • Turn on login and transaction alerts.
  • Check your mobile carrier account if your phone number was exposed.

Prioritize email, financial accounts, cloud storage, mobile service, and your main Google, Apple, or Microsoft account.

When to Skip the Checklist and Contact Support Immediately

Do not delay contacting the appropriate provider when:

  • Money has been stolen
  • You are locked out of the account
  • Recovery information has been replaced
  • Unauthorized sessions keep returning
  • A work or school account is involved
  • Identity documents were exposed
  • Someone transferred or attempted to transfer your phone number
  • The account is being used to scam other people

Contact banks, email providers, employers, schools, mobile carriers, or government services through their official channels.

The checklist is designed to help you act quickly, but serious financial fraud or ongoing unauthorized access may require immediate professional support.


How to Reduce the Damage From Future Data Breaches

You cannot control how every company stores or protects its customer data. Even a service with strong security practices may eventually face an attack.

You can, however, control how much damage one breach causes.

The goal is to prevent a leaked password or email address from becoming the key to your entire digital life.

Use a Unique Password for Every Account

Password reuse turns one company’s breach into a risk for every service where the same password appears.

Use a password manager to create and store unique credentials. Begin with your most sensitive accounts, including:

  • Primary email
  • Password manager
  • Banking and payment services
  • Mobile carrier
  • Cloud storage
  • Work or school accounts
  • Main Google, Apple, or Microsoft account

When every account has a different password, attackers cannot use a credential stolen from one website to unlock another.

Protect Your Primary Email More Carefully

Your email account is one of your most important digital assets because it receives password resets, security alerts, documents, and verification messages.

Protect it with:

  • A long, unique password
  • MFA or a passkey
  • Updated recovery information
  • Login alerts
  • Regular session reviews
  • Secure recovery codes

Avoid using your primary recovery email address for newsletters, competitions, forums, and low-priority registrations when practical.

Use Separate Addresses or Aliases

Separating online activities can make breaches and phishing easier to manage.

You might use:

  • A private address for banking and account recovery
  • A personal address for friends and family
  • A professional address
  • An alias for shopping and subscriptions
  • Another alias for newsletters and public registrations

This approach does not prevent breaches, but it can reduce spam and help you recognize suspicious messages.

A banking alert sent to an address used only for newsletters, for example, would immediately deserve extra scrutiny.

Turn On Security Alerts

Enable notifications for:

  • New logins
  • Password changes
  • Recovery-setting updates
  • New connected applications
  • Financial transactions
  • Mobile-account changes
  • MFA modifications

Security alerts can help you respond before an attacker changes additional settings or moves to other accounts.

Make sure the alert destination is current and protected.

Keep Devices and Software Updated

Install updates for:

  • Operating systems
  • Browsers
  • Email applications
  • Security software
  • Mobile apps
  • Password managers
  • Frequently used programs

Updates often repair vulnerabilities that attackers could exploit.

Remove applications and browser extensions you no longer use. Every unnecessary program or extension creates another possible source of risk.

Be Selective About Connected Applications

Review which apps and websites have access to your email, cloud files, contacts, or social accounts.

Remove access when:

  • You no longer use the service
  • The developer is unfamiliar
  • The permissions seem excessive
  • The application has been abandoned
  • You cannot remember approving it

Signing in with a major account can be convenient, but you should still understand what information the connected service can access.

Delete Accounts You No Longer Need

Old accounts can continue storing personal information even when you have not used them for years.

Where practical:

  1. Sign in through the official website.
  2. Remove saved payment information.
  3. Download anything you need.
  4. Disconnect other accounts.
  5. Use the provider’s account-deletion process.
  6. Remove the login from your password manager after confirming deletion.

Deleting an account cannot recover data already stolen in a previous breach, but it can reduce future exposure.

Store Less Sensitive Information in Email

Email inboxes often become long-term storage for identification documents, bank statements, tax files, medical records, and password-reset messages.

Delete information you no longer need and move important files to more appropriate secure storage.

Also clear old password-reset emails and messages containing temporary login links after they are no longer useful.

The less sensitive information available in the inbox, the less an attacker can collect if they gain access.

Avoid Unexpected MFA Approvals

Never approve an authentication prompt you did not initiate.

Unexpected prompts may mean that someone has already entered the correct password. Deny the request, change the password, and review the account’s login activity.

Treat verification codes and recovery codes like passwords. Do not send them to callers, support agents, or people contacting you through messages.

Check Important Accounts Periodically

You do not need to constantly monitor every login, but occasional reviews can uncover problems early.

Periodically check:

  • Saved-password security warnings
  • Active sessions
  • Trusted devices
  • Connected applications
  • Recovery information
  • Forwarding rules
  • Financial statements
  • Login alerts

You should also repeat breach checks after a major incident involving a service you use.

The goal is not to eliminate every online risk. It is to make sure that one exposed piece of information cannot easily lead to several compromised accounts.


Finding a Breach Is a Signal to Act, Not a Reason to Panic

Discovering that your email address or password appeared in a data breach can feel frightening, but the result does not always mean that someone has entered your inbox or stolen your identity.

A breach result tells you that information was exposed. Your next task is to determine what was included, whether the information is still in use, and whether there are signs of unauthorized access.

Begin by checking known breach records and your password manager’s security warnings. Then review recent logins, active sessions, forwarding rules, recovery information, and connected applications.

If a password was exposed, replace it everywhere it was reused. Secure your primary email account first, enable multifactor authentication, sign out unfamiliar sessions, and scan your device when malware may be involved.

When someone has already accessed the account, act quickly. Remove unauthorized access, review related services, warn affected contacts, preserve evidence, and contact banks, providers, employers, or official reporting services where necessary.

Most importantly, use the incident to improve your long-term security. Unique passwords, a trusted password manager, MFA, passkeys, security alerts, and updated devices can prevent one breach from spreading across your other accounts.

You may not be able to stop every company from experiencing a data breach. You can still make sure that exposed information has limited value and that suspicious activity is discovered before it causes greater harm.


Frequently Asked Questions About Compromised Emails and Passwords

Does a Breached Email Mean My Email Account Was Hacked?

Not necessarily. Your email address may appear in a breach because a shopping site, forum, app, or other service exposed customer data. That does not automatically mean someone accessed your inbox.

However, you should still review what information was exposed, check recent login activity, update reused passwords, and enable multifactor authentication.

Is It Safe to Enter My Email Into a Breach-Checking Website?

It can be safe when you use a well-established breach-checking service and open the site directly through your browser.

A legitimate service should only need the email address you want to check. It should not ask for your current email password, MFA code, recovery code, or payment information.

Avoid links from unexpected emails, texts, pop-ups, or social media messages claiming that your account was compromised.

Is It Safe to Check Whether a Password Has Been Leaked?

Use only trusted password managers, browser security tools, operating-system password checks, or established password-checking services.

Do not type an active password into an unfamiliar website. A malicious site could record it and use it to access your accounts.

Whenever a trusted tool identifies a password as compromised, replace it everywhere it was used.

Should I Change My Password If the Breach Happened Years Ago?

Yes, if the password is still active anywhere.

You should also change it when you continue using a similar version, such as the same base word with a different number, year, or symbol. Old breach data can remain useful to attackers for years, especially when people reuse predictable password patterns.

Do I Need to Change Every Password After a Breach?

Not always. Focus first on the exposed password and every account where you reused it or a closely related variation.

Prioritize your primary email, password manager, financial accounts, mobile carrier, cloud storage, and main Google, Apple, or Microsoft account.

Passwords that are already strong, unique, and unrelated to the exposed credential may not need to be changed.

Can Hackers Access Other Accounts With One Leaked Password?

Yes. Attackers may use credential stuffing to test a leaked email-and-password combination on many popular websites.

This is why password reuse is so dangerous. A password exposed through an old shopping account could also unlock email, social media, streaming, cloud, or payment accounts when the same credential was reused.

Why Am I Still Seeing Suspicious Logins After Changing My Password?

Several explanations are possible. An attacker may still have an active session, a connected application, an app-specific password, or access through malicious forwarding rules.

Your device may also contain malware or a stolen browser session may remain active.

Sign out all sessions, remove unfamiliar devices and apps, inspect forwarding settings, enable MFA, and scan the device with updated security software.

Should I Delete a Compromised Email Account?

Usually, you should secure the account before considering deletion.

The address may still be connected to banking, social media, cloud storage, shopping accounts, and password-recovery settings. Deleting it too soon could make other accounts harder to recover.

A new address may be worth considering when you cannot regain reliable control, targeted abuse continues, or the account no longer provides adequate security features.

Does Multifactor Authentication Protect Me If My Password Leaks?

MFA can block many unauthorized login attempts because the password alone is not enough to complete the sign-in.

However, you should still change the exposed password, end active sessions, review account settings, and check for malware. MFA reduces risk, but it does not make a compromised password safe to keep using.

What Should I Do If I Receive an Unexpected MFA Prompt?

Deny the request and do not share any code.

An unexpected prompt may mean someone has already entered the correct password. Change the password from a trusted device, review recent login activity, remove unfamiliar sessions, and confirm that recovery information has not changed.

Never approve repeated requests simply to make them stop.

Can a Clean Breach Check Prove That My Account Is Safe?

No. A clean result only means that the address or password was not found in the breach data available to that service.

The account could still be affected by a recent private breach, phishing, malware, password guessing, or session theft.

Continue investigating when you see unfamiliar logins, password changes, missing messages, unexpected MFA prompts, or unknown forwarding rules.

Should I Change My Email Address If It Appears in a Data Breach?

Usually not. An exposed address can often continue to be used safely after you change weak or reused passwords, enable MFA, review sessions, and confirm recovery settings.

Consider using a new address when the old account cannot be secured, harassment continues, or you want to separate sensitive accounts from public registrations and newsletters.


References

Leave a Reply

Your email address will not be published. Required fields are marked *

Table of Contents

Index