{"id":5452,"date":"2026-07-20T10:06:44","date_gmt":"2026-07-20T18:06:44","guid":{"rendered":"https:\/\/www.antivirusaz.com\/faq\/?p=5452"},"modified":"2026-07-20T10:33:52","modified_gmt":"2026-07-20T18:33:52","slug":"how-to-check-if-email-or-password-has-been-compromised","status":"publish","type":"post","link":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/","title":{"rendered":"How to Check If Your Email or Password Has Been Compromised and What to Do Next"},"content":{"rendered":"<p>Finding out that your email address or password may have appeared in a data breach can be alarming. You might receive a security notification, notice an unfamiliar login, or discover that one of your accounts was included in a recently reported cyberattack. However, an exposed email address does not always mean that someone has successfully entered your inbox.<\/p>\n<p>There are several possible situations. Your email address may have appeared in a breached customer database, an old password may have been leaked, or criminals may have obtained a current combination of your email address and password. In more serious cases, someone may already be accessing your account, reading your messages, changing settings, or using your inbox to reset passwords elsewhere.<\/p>\n<p>The most important thing is to <strong>stay calm and act in the correct order<\/strong>. Changing one password may help, but it may not completely solve the problem if that password was reused, an attacker still has an active session, or <a href=\"\/security-center\/malware.html\">malware<\/a> is collecting information from your device.<\/p>\n<p>This guide explains how to check whether your email address or password has been compromised, identify signs of unauthorized access, secure affected accounts, and reduce the risk of further damage.<\/p>\n<hr \/>\n\n<hr \/>\n<p><a href=\"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-5463\" src=\"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised-1024x683.webp\" alt=\"How to Check If Your Email or Password Has Been Compromised and What to Do Next\" width=\"1024\" height=\"683\" srcset=\"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised-1024x683.webp 1024w, https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised-300x200.webp 300w, https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised-768x512.webp 768w, https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised-50x33.webp 50w, https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<hr \/>\n<h2><span class=\"ez-toc-section\" id=\"How-to-Find-Out-What-Was-Exposed-and-Secure-Your-Accounts\"><\/span>How to Find Out What Was Exposed and Secure Your Accounts<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Before changing every password you own, you should first determine <em>what happened<\/em> and <em>which accounts may be affected<\/em>. A breach involving only an email address requires a different response from one that exposed a current password, financial information, or access to the email account itself.<\/p>\n<p>Start by checking whether your email address appears in a known data breach. You should then review any warnings from your browser, password manager, email provider, or security software. These tools may identify passwords that have been exposed, reused across several accounts, or considered too weak to provide reliable protection.<\/p>\n<p>Next, inspect your email account\u2019s recent security activity. Look for unfamiliar devices, login locations, password changes, recovery-information updates, connected applications, and active sessions. You should also review your inbox rules and forwarding settings because attackers sometimes use them to quietly copy messages or hide security alerts.<\/p>\n<p>If you confirm that a password was exposed, replace it with a <strong>new and unique password<\/strong>. Do not simply add a number or symbol to the old one. You should also change that password anywhere else it was reused, beginning with your primary email account, password manager, financial accounts, and other services that contain sensitive information.<\/p>\n<p>Finally, enable <strong>multifactor authentication<\/strong>, sign out unfamiliar sessions, remove unauthorized applications, and scan your device for malware. Following these steps in the correct order can help you regain control of your accounts and prevent one exposed password from creating a much larger security problem.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"What-Does-It-Mean-When-an-Email-or-Password-Is-Compromised\"><\/span>What Does It Mean When an Email or Password Is Compromised?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The word <em>compromised<\/em> can describe several different security problems. It does not always mean that a criminal has entered your email account or taken control of it. In some cases, it simply means that information connected to your email address appeared in a leaked database.<\/p>\n<p>Understanding what was exposed can help you respond without overlooking a serious risk or taking unnecessary steps.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Your-Email-Address-Appeared-in-a-Data-Breach\"><\/span>Your Email Address Appeared in a Data Breach<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An <strong>email address exposure<\/strong> usually happens when a company, website, or online service experiences a data breach. The compromised database may contain customer email addresses along with other personal or account information.<\/p>\n<p>Depending on the incident, the exposed information could include:<\/p>\n<ul>\n<li>Your name and email address<\/li>\n<li>A username or account number<\/li>\n<li>Your phone number or physical address<\/li>\n<li>Your date of birth<\/li>\n<li>An encrypted or hashed password<\/li>\n<li>Answers to security questions<\/li>\n<li>Purchase or subscription history<\/li>\n<li>Financial or payment information<\/li>\n<\/ul>\n<p>This does not necessarily mean that someone accessed your inbox. For example, your email address could appear in a breach involving an online store, social network, forum, or streaming service. The email provider itself may not have been affected.<\/p>\n<p>However, exposed personal details can still help criminals create convincing phishing messages. They may contact you while pretending to represent the breached company, refer to real account details, and pressure you into clicking a malicious link or revealing more information.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Your-Password-Was-Exposed\"><\/span>Your Password Was Exposed<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A password is considered <strong>exposed or compromised<\/strong> when it appears in known breach data, credential collections, malware logs, or other stolen records.<\/p>\n<p>Even if the password is several years old, you should not assume it is harmless. Criminals can keep stolen credentials and test them long after the original breach occurred. They may also try common variations of the password, such as changing a year or adding a symbol.<\/p>\n<p>An exposed password should no longer be used for any account. This is especially important when you have reused the same password\u2014or a similar version of it\u2014across multiple websites.<\/p>\n<p>Attackers frequently use a technique called <strong>credential stuffing<\/strong>, in which automated tools test leaked email-and-password combinations on many different services. A password stolen from an old shopping account could therefore put your email, social media, cloud storage, or financial accounts at risk.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Your-Email-Account-Was-Accessed\"><\/span>Your Email Account Was Accessed<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An <strong>account compromise<\/strong> means that someone has successfully gained unauthorized access to the account.<\/p>\n<p>The intruder may be able to:<\/p>\n<ul>\n<li>Read, send, delete, or forward messages<\/li>\n<li>View personal documents and attachments<\/li>\n<li>Change the account password<\/li>\n<li>Replace recovery information<\/li>\n<li>Create inbox rules or forwarding settings<\/li>\n<li>Reset passwords for other online services<\/li>\n<li>Impersonate you when contacting friends, relatives, or coworkers<\/li>\n<li>Search your inbox for financial or personal information<\/li>\n<\/ul>\n<p>Your email account is particularly valuable because it often serves as the recovery method for many other accounts. If someone controls your inbox, they may be able to request password resets and gradually take over additional services.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Your-Device-May-Be-Compromised\"><\/span>Your Device May Be Compromised<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Sometimes, the problem does not begin with a company data breach. <strong>Malware on your computer or phone may steal credentials directly from the device.<\/strong><\/p>\n<p><a href=\"\/faq\/art\/what-is-infostealer-malware\/\">Infostealer malware<\/a> can collect saved browser passwords, login cookies, autofill information, cryptocurrency wallet data, and other sensitive details. A malicious browser extension may also read information entered into websites or redirect you to fake login pages.<\/p>\n<p>This possibility is important because changing a password may not solve the problem if the device remains infected. The malware could simply capture the replacement password the next time you enter it.<\/p>\n<p>In simple terms, a breach indicates that your information was <em>exposed<\/em>, while unfamiliar account activity suggests that someone may have <em>used<\/em> that information. Both situations deserve attention, but an actively accessed account requires immediate action.<\/p>\n<hr \/>\n<p style=\"text-align: center;\">A data breach can also make phishing attempts more convincing because scammers may already know your email address, name, or other personal details. Learn more about <strong><a href=\"https:\/\/www.antivirusaz.com\/security-center\/phishing.html\">phishing and how these attacks work<\/a><\/strong> before responding to unexpected security warnings, payment requests, or account-verification messages.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Warning-Signs-That-Your-Email-Account-May-Have-Been-Hacked\"><\/span>Warning Signs That Your Email Account May Have Been Hacked<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Some account compromises are obvious. You may suddenly lose access to your inbox, see messages that you did not send, or receive a warning about a password change. Other attackers try to remain unnoticed so they can quietly monitor your email or wait for an opportunity to misuse it.<\/p>\n<p>Review your account carefully when you notice any of the following warning signs.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Unfamiliar-Login-or-Device-Alerts\"><\/span>Unfamiliar Login or Device Alerts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Most major email services send a notification when someone signs in from a new device, browser, or location. An unfamiliar alert could mean that another person knows your password or has gained access through a stolen session.<\/p>\n<p>Do not assume that every unusual location indicates an attack. Mobile networks, VPNs, and internet providers can sometimes make a legitimate login appear to come from another city or region. Compare the location with the device type, browser, time, and recent activity before deciding whether it belongs to you.<\/p>\n<p>If you do not recognize the activity, use the email provider\u2019s official website or app to secure the account. <strong>Do not use a link inside an unexpected security message<\/strong>, since the warning itself could be a <a href=\"\/security-center\/phishing.html\">phishing attempt<\/a>.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Password-Reset-Messages-You-Did-Not-Request\"><\/span>Password-Reset Messages You Did Not Request<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An unexpected password-reset email may indicate that someone is trying to enter one of your accounts.<\/p>\n<p>A single message does not necessarily mean the attacker succeeded. Anyone who knows your email address may be able to request a reset. However, repeated requests\u2014especially for several different services\u2014could suggest that your address is being actively targeted.<\/p>\n<p>Never approve a reset or enter your credentials unless you initiated the request. Open the affected service directly and review its security activity.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Emails-You-Did-Not-Send\"><\/span>Emails You Did Not Send<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Check the <strong>Sent<\/strong>, <strong>Drafts<\/strong>, <strong>Trash<\/strong>, <strong>Spam<\/strong>, and <strong>Archived<\/strong> folders for messages you do not recognize.<\/p>\n<p>Attackers may use a compromised account to:<\/p>\n<ul>\n<li>Send phishing links to your contacts<\/li>\n<li>Request money or gift cards<\/li>\n<li>Distribute malicious attachments<\/li>\n<li>Reset passwords for other accounts<\/li>\n<li>Continue an existing business or financial conversation<\/li>\n<li>Impersonate you during a scam<\/li>\n<\/ul>\n<p>Some attackers delete sent messages afterward, so an empty Sent folder does not prove that the account is safe. Friends, relatives, or coworkers may be the first people to notice that unusual messages are coming from your address.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Messages-Are-Missing-or-Marked-as-Read\"><\/span>Messages Are Missing or Marked as Read<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Emails that disappear, move into unexpected folders, or become marked as read without your involvement can be another warning sign.<\/p>\n<p>An attacker may search for messages containing:<\/p>\n<ul>\n<li>Password-reset links<\/li>\n<li>Bank or payment information<\/li>\n<li>Tax documents<\/li>\n<li>Identification records<\/li>\n<li>Business invoices<\/li>\n<li>Travel plans<\/li>\n<li>Personal conversations<\/li>\n<\/ul>\n<p>They may delete security warnings or move them into a hidden folder to prevent you from noticing suspicious activity.<\/p>\n<p>Before assuming the account was hacked, confirm that another legitimate device or email application did not open or organize the messages. Synchronization between a phone, computer, tablet, and desktop email client can sometimes create confusing changes.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Unknown-Forwarding-Rules-or-Inbox-Filters\"><\/span>Unknown Forwarding Rules or Inbox Filters<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Email forwarding and automatic rules are useful features, but they can also provide attackers with a quiet way to monitor an account.<\/p>\n<p>A malicious rule might:<\/p>\n<ul>\n<li>Forward all messages to an unknown address<\/li>\n<li>Copy messages containing words such as <em>invoice<\/em>, <em>payment<\/em>, or <em>password<\/em><\/li>\n<li>Delete security notifications<\/li>\n<li>Move replies into an obscure folder<\/li>\n<li>Mark certain messages as read<\/li>\n<li>Hide emails from a bank or account provider<\/li>\n<\/ul>\n<p>These changes may remain active even after you replace the password. That is why you should inspect forwarding settings, inbox rules, filters, delegated access, and connected applications whenever you suspect an account compromise.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Changes-to-Your-Password-or-Recovery-Information\"><\/span>Changes to Your Password or Recovery Information<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Treat any unrecognized change to your password, recovery email address, phone number, security questions, or trusted devices as a serious warning.<\/p>\n<p>Attackers often modify recovery settings so they can regain access after the account owner changes the password. They may also add their own phone number or email address as a backup method.<\/p>\n<p>Check that every recovery option belongs to you and that the information is still current. Remove unknown details and review any recent security events connected to the changes.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Unexpected-Multifactor-Authentication-Requests\"><\/span>Unexpected Multifactor Authentication Requests<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An unexpected authentication prompt may mean that someone has already entered the correct password and is attempting to complete the login.<\/p>\n<p>Never approve a prompt simply to make it disappear. Attackers sometimes send repeated requests in the hope that the account owner will eventually tap <strong>Approve<\/strong> out of frustration or confusion. This technique is sometimes called <em>MFA fatigue<\/em> or <em>push bombing<\/em>.<\/p>\n<p>Deny the request, change the account password from a trusted device, sign out other sessions, and review recent activity.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Unrecognized-Purchases-or-Password-Changes-on-Other-Accounts\"><\/span>Unrecognized Purchases or Password Changes on Other Accounts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A compromised email account can become a gateway to other services. Watch for unexpected purchase receipts, subscription confirmations, password changes, account-recovery messages, or new-account notifications.<\/p>\n<p>These events may indicate that someone is using your inbox to access:<\/p>\n<ul>\n<li>Online banking or payment accounts<\/li>\n<li>Shopping websites<\/li>\n<li>Social media<\/li>\n<li>Cloud storage<\/li>\n<li>Mobile carrier accounts<\/li>\n<li>Gaming platforms<\/li>\n<li>Workplace or school services<\/li>\n<\/ul>\n<p>The absence of obvious warning signs does not guarantee that an account is secure. A careful attacker may quietly read messages or collect information without changing the password or sending anything. <strong>Reviewing recent login activity, active sessions, forwarding rules, and connected applications provides a more reliable picture than checking the inbox alone.<\/strong><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Step-1-Check-Whether-Your-Email-Appeared-in-a-Known-Data-Breach\"><\/span>Step 1: Check Whether Your Email Appeared in a Known Data Breach<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The first step is to determine whether your email address has appeared in a publicly documented data breach. A breach-checking service can compare your address with collections of account information exposed during known security incidents.<\/p>\n<p>One of the best-known options is <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Have I Been Pwned<\/strong><\/a>, which allows you to search for an email address and see whether it appeared in supported breach records. The results may show the affected company, the approximate date of the incident, and the types of information that were exposed.<\/p>\n<p>To perform the check safely:<\/p>\n<ol>\n<li>Open a trusted breach-checking service directly in your browser.<\/li>\n<li>Enter the email address you want to investigate.<\/li>\n<li>Review each listed breach carefully.<\/li>\n<li>Note which company or service was affected.<\/li>\n<li>Check what types of information were exposed.<\/li>\n<li>Repeat the process for any older or secondary email addresses you still use.<\/li>\n<\/ol>\n<p>It is safer to enter the website address yourself or access it through a trusted bookmark. Avoid clicking a breach-checking link in an unexpected email, text message, pop-up, or social media post. Criminals sometimes create fake security tools designed to collect email addresses, passwords, or payment information.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"What-a-Positive-Breach-Result-Means\"><\/span>What a Positive Breach Result Means<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>If your email address appears in a breach result, it means the address was included in data connected to a known security incident. It does <strong>not automatically mean that someone entered your email account<\/strong>.<\/p>\n<p>For example, an online retailer may have exposed a customer database containing names, email addresses, shipping information, and encrypted passwords. Your inbox may not have been affected directly, but the leaked information could still be used for phishing, password guessing, or account takeover attempts.<\/p>\n<p>Pay close attention to the categories of exposed data. A breach involving only an email address creates a different level of risk from one involving:<\/p>\n<ul>\n<li>Passwords or password hashes<\/li>\n<li>Security questions and answers<\/li>\n<li>Phone numbers<\/li>\n<li>Home addresses<\/li>\n<li>Payment information<\/li>\n<li>Identification records<\/li>\n<li>Dates of birth<\/li>\n<\/ul>\n<p>The presence of a password or recovery information means you should take faster and more extensive action.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"What-a-Clean-Result-Means\"><\/span>What a Clean Result Means<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A result showing no known breaches is reassuring, but it is not a guarantee that your information has never been exposed.<\/p>\n<p>A breach may be:<\/p>\n<ul>\n<li>Too recent to appear in the database<\/li>\n<li>Known only to the affected company<\/li>\n<li>Privately traded among criminals<\/li>\n<li>Connected to malware rather than a company breach<\/li>\n<li>Missing from the breach-checking service<\/li>\n<li>Associated with a different email address or username<\/li>\n<\/ul>\n<p>You should still investigate unfamiliar logins, unexpected authentication prompts, password changes, or suspicious account activity even when a breach search returns no results.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Check-Every-Email-Address-You-Use\"><\/span>Check Every Email Address You Use<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Many people focus only on their current primary address. However, an older address can still create security risks when it remains connected to active accounts.<\/p>\n<p>Check addresses used for:<\/p>\n<ul>\n<li>Shopping and subscriptions<\/li>\n<li>Social media<\/li>\n<li>School or work<\/li>\n<li>Gaming<\/li>\n<li>Banking and payments<\/li>\n<li>Old forums and online communities<\/li>\n<li>Account recovery<\/li>\n<li>Newsletter registrations<\/li>\n<\/ul>\n<p>An old email address may also reveal passwords or personal information that you continue to use elsewhere. Treat each breach result as a clue that helps you identify which accounts need attention.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Step-2-Check-Your-Saved-Passwords-for-Breach-Warnings\"><\/span>Step 2: Check Your Saved Passwords for Breach Warnings<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>After checking your email addresses, review the passwords saved in your browser, operating system, or password manager. Many modern password tools can warn you when a saved password appears in known breach data.<\/p>\n<p>Depending on the service you use, the warning may describe a password as:<\/p>\n<ul>\n<li><strong>Compromised<\/strong><\/li>\n<li><strong>Exposed<\/strong><\/li>\n<li><strong>Leaked<\/strong><\/li>\n<li><strong>Reused<\/strong><\/li>\n<li><strong>Weak<\/strong><\/li>\n<li><strong>At risk<\/strong><\/li>\n<\/ul>\n<p>These labels describe different problems. A compromised password has appeared in known stolen data, while a reused password is saved for more than one account. A weak password may be easy to guess even when it has not appeared in a documented breach.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Where-to-Look-for-Password-Warnings\"><\/span>Where to Look for Password Warnings<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Password-security checks may be available through:<\/p>\n<ul>\n<li>Your browser\u2019s password manager<\/li>\n<li>A dedicated password-management application<\/li>\n<li>Your phone or computer\u2019s built-in password tools<\/li>\n<li>Your main Google, Apple, or Microsoft account<\/li>\n<li>Security software with identity-monitoring features<\/li>\n<\/ul>\n<p>Look for an area called <em>Password Checkup<\/em>, <em>Security Recommendations<\/em>, <em>Password Health<\/em>, <em>Security Dashboard<\/em>, or something similar. The exact name and location may differ depending on your device and software version.<\/p>\n<p>The tool may show a list of affected accounts and direct you to their websites. However, it is often safer to open the official website or app yourself rather than following a link you were not expecting.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Prioritize-Compromised-and-Reused-Passwords\"><\/span>Prioritize Compromised and Reused Passwords<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>You do not necessarily need to change every saved password at once. Start with the accounts that create the greatest risk.<\/p>\n<p>A useful order is:<\/p>\n<ol>\n<li>Primary email account<\/li>\n<li>Password manager<\/li>\n<li>Banking and payment accounts<\/li>\n<li>Google, Apple, or Microsoft account<\/li>\n<li>Mobile carrier<\/li>\n<li>Cloud storage<\/li>\n<li>Work or school accounts<\/li>\n<li>Social media<\/li>\n<li>Shopping and subscription services<\/li>\n<li>Less important accounts<\/li>\n<\/ol>\n<p>A password that is both <strong>compromised and reused<\/strong> should receive immediate attention. If attackers have the password, they may test it automatically across many popular services.<\/p>\n<p>Replace it with a completely different password for each account. Do not make small adjustments such as changing <code>Password2025!<\/code> to <code>Password2026!<\/code>. Predictable variations may still be easy to guess.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Do-Not-Enter-Your-Password-Into-Random-Leak-Checkers\"><\/span>Do Not Enter Your Password Into Random Leak Checkers<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Some websites claim that they can tell you whether a password has been leaked. Be extremely careful with these tools.<\/p>\n<p>You should never type a current password into an unfamiliar website, online quiz, pop-up, or form. A malicious site could simply record the password and use it against you.<\/p>\n<p>Use password checks provided by:<\/p>\n<ul>\n<li>A trusted password manager<\/li>\n<li>Your browser or operating system<\/li>\n<li>An established breach-checking service<\/li>\n<li>The official account provider<\/li>\n<\/ul>\n<p>A legitimate tool should not ask you to submit your email address and current password together as proof that the account belongs to you.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Step-3-Review-Your-Email-Accounts-Recent-Security-Activity\"><\/span>Step 3: Review Your Email Account\u2019s Recent Security Activity<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A breach result tells you that information was exposed, but it does not tell you whether someone actually used it. To look for signs of unauthorized access, review your email provider\u2019s recent security and login activity.<\/p>\n<p>Most major providers maintain a record of recently used devices, browsers, sessions, and security changes. Open the provider\u2019s official website or app and look for an area labeled <em>Security<\/em>, <em>Recent Activity<\/em>, <em>Devices<\/em>, <em>Sessions<\/em>, or <em>Sign-In Activity<\/em>.<\/p>\n<p>Review information such as:<\/p>\n<ul>\n<li>Recently used devices<\/li>\n<li>Login dates and times<\/li>\n<li>Browser types<\/li>\n<li>Operating systems<\/li>\n<li>Approximate locations<\/li>\n<li>IP addresses, when available<\/li>\n<li>Successful and unsuccessful login attempts<\/li>\n<li>Password changes<\/li>\n<li>Recovery-information updates<\/li>\n<li>New application permissions<\/li>\n<li>Multifactor authentication changes<\/li>\n<\/ul>\n<h4><span class=\"ez-toc-section\" id=\"Compare-More-Than-the-Location\"><\/span>Compare More Than the Location<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An unfamiliar city or country can be concerning, but location data is not always exact.<\/p>\n<p>A legitimate login may appear in a different place because of:<\/p>\n<ul>\n<li>A mobile network<\/li>\n<li>A VPN<\/li>\n<li>Your internet provider\u2019s routing<\/li>\n<li>Travel<\/li>\n<li>A workplace or school network<\/li>\n<li>Cloud-based security services<\/li>\n<\/ul>\n<p>Instead of relying only on location, compare several details:<\/p>\n<ul>\n<li>Do you recognize the device?<\/li>\n<li>Does the browser match one you use?<\/li>\n<li>Did the activity occur while you were online?<\/li>\n<li>Were you travelling at the time?<\/li>\n<li>Did the session change any account settings?<\/li>\n<li>Did it happen before an unexpected MFA prompt?<\/li>\n<li>Are there repeated attempts from several locations?<\/li>\n<\/ul>\n<p>A login from a nearby city on your usual phone may be legitimate. A login from an unknown computer followed by a recovery-email change is much more suspicious.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Active-Sessions-and-Trusted-Devices\"><\/span>Review Active Sessions and Trusted Devices<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An attacker may remain signed in even after you notice the problem. Check the list of active sessions and trusted devices for anything you do not recognize.<\/p>\n<p>Remove unfamiliar devices and use the option to <strong>sign out of all other sessions<\/strong> when available. You may need to sign back in on your own phone, tablet, computer, or email application afterward.<\/p>\n<p>Signing out sessions is important because changing the password may not always end every existing connection immediately. It can also help remove access obtained through a stolen browser session or login cookie.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Record-Suspicious-Activity-Before-Removing-It\"><\/span>Record Suspicious Activity Before Removing It<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When possible, save basic evidence before signing out an unfamiliar session.<\/p>\n<p>You may want to record:<\/p>\n<ul>\n<li>The device name<\/li>\n<li>Approximate location<\/li>\n<li>Date and time<\/li>\n<li>IP address<\/li>\n<li>Browser type<\/li>\n<li>Security changes<\/li>\n<li>Related notification emails<\/li>\n<\/ul>\n<p>Screenshots can be useful if you later need to contact the provider, report fraud, notify an employer, or explain unauthorized activity to a bank.<\/p>\n<p>Do not delay securing the account simply to collect extensive evidence. Capture what you can quickly, then remove the session and protect the account.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Step-4-Check-Forwarding-Rules-Filters-and-Connected-Apps\"><\/span>Step 4: Check Forwarding Rules, Filters, and Connected Apps<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Changing the password is not enough if an attacker has created another way to access your messages. They may add a forwarding address, create hidden inbox rules, approve a third-party application, or generate an app-specific password.<\/p>\n<p>These changes can allow information to continue leaving the account even after the main password has been replaced.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Automatic-Email-Forwarding\"><\/span>Review Automatic Email Forwarding<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Open your email settings and check whether incoming messages are being forwarded to another address.<\/p>\n<p>A forwarding address may be legitimate if you set it up for work, school, or another inbox. Remove it immediately when you do not recognize it.<\/p>\n<p>Attackers may forward:<\/p>\n<ul>\n<li>All incoming messages<\/li>\n<li>Password-reset emails<\/li>\n<li>Bank notifications<\/li>\n<li>Invoices and payment messages<\/li>\n<li>Travel confirmations<\/li>\n<li>Messages from specific contacts<\/li>\n<li>Emails containing sensitive keywords<\/li>\n<\/ul>\n<p>Some providers send a warning when forwarding is enabled, but an attacker may delete or hide that notification.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Inspect-Inbox-Rules-and-Filters\"><\/span>Inspect Inbox Rules and Filters<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Inbox rules automatically move, label, archive, forward, or delete messages. Attackers can misuse them to hide evidence of account activity.<\/p>\n<p>Look for rules that:<\/p>\n<ul>\n<li>Delete security alerts<\/li>\n<li>Mark messages as read<\/li>\n<li>Move emails into unusual folders<\/li>\n<li>Hide replies from banks or online services<\/li>\n<li>Forward messages to another account<\/li>\n<li>Target words such as <em>password<\/em>, <em>payment<\/em>, <em>invoice<\/em>, or <em>verification<\/em><\/li>\n<li>Apply to messages from the email provider itself<\/li>\n<\/ul>\n<p>Delete any rule you did not create or cannot explain.<\/p>\n<p>Also check the <strong>Trash<\/strong>, <strong>Spam<\/strong>, <strong>Archive<\/strong>, and custom folders for missing security alerts or password-reset emails. A malicious filter may have been routing them away from the main inbox.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Connected-Applications\"><\/span>Review Connected Applications<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Many websites and applications allow users to sign in with an email, Google, Microsoft, or Apple account. Others request permission to read messages, access contacts, or manage files.<\/p>\n<p>Review the list of third-party applications connected to your account and remove anything that:<\/p>\n<ul>\n<li>You do not recognize<\/li>\n<li>You no longer use<\/li>\n<li>Requests more access than it needs<\/li>\n<li>Was added around the time suspicious activity began<\/li>\n<li>Has an unclear name or publisher<\/li>\n<li>Came from an unknown browser extension or mobile app<\/li>\n<\/ul>\n<p>Removing a connection may sign you out of the related service or stop it from working. That inconvenience is preferable to leaving an unknown application with access to your inbox.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Check-App-Specific-Passwords-and-Email-Clients\"><\/span>Check App-Specific Passwords and Email Clients<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Some accounts support <strong>app-specific passwords<\/strong> for older email programs or devices that cannot use standard multifactor authentication. These passwords may continue working separately from your normal login.<\/p>\n<p>Delete unfamiliar app passwords and recreate only the ones you genuinely need.<\/p>\n<p>You should also review access through:<\/p>\n<ul>\n<li>Desktop email programs<\/li>\n<li>Mobile mail applications<\/li>\n<li>IMAP and POP connections<\/li>\n<li>Calendar and contact applications<\/li>\n<li>Browser extensions<\/li>\n<li>Automated business tools<\/li>\n<li>Backup and archiving services<\/li>\n<\/ul>\n<p>An email client you no longer use may still have an active connection to the account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Confirm-Recovery-and-Delegated-Access-Settings\"><\/span>Confirm Recovery and Delegated Access Settings<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Before leaving the security settings, check:<\/p>\n<ul>\n<li>Recovery email addresses<\/li>\n<li>Recovery phone numbers<\/li>\n<li>Trusted devices<\/li>\n<li>Emergency contacts<\/li>\n<li>Delegated mailbox access<\/li>\n<li>Shared-account permissions<\/li>\n<li>Account aliases<\/li>\n<\/ul>\n<p>Remove any address, phone number, person, or device you do not recognize. Attackers sometimes add their own recovery method so they can regain control after the owner changes the password.<\/p>\n<p>Once you have reviewed forwarding, filters, connected apps, and recovery options, sign out other sessions and change the password if you have not already done so. These checks help close the less obvious access points that can remain after an account compromise.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"What-to-Do-Immediately-If-Your-Password-Was-Exposed\"><\/span>What to Do Immediately If Your Password Was Exposed<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If a password appears in a breach warning or password-security check, you should treat it as unsafe. Even when the related account looks normal, criminals may already possess the password and could try using it now or in the future.<\/p>\n<p>The response should go beyond changing a single login. You also need to consider where else the password was used, whether someone is still signed in, and whether the account contains access to more sensitive services.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Change-the-Exposed-Password\"><\/span>Change the Exposed Password<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Open the affected service through its official website or app and replace the password as soon as possible.<\/p>\n<p>Create a password that is:<\/p>\n<ul>\n<li><strong>Completely different<\/strong> from the old one<\/li>\n<li>Unique to that specific account<\/li>\n<li>Long enough to resist guessing<\/li>\n<li>Unrelated to your name, birthday, address, or other personal details<\/li>\n<li>Not based on a common phrase or keyboard pattern<\/li>\n<\/ul>\n<p>Avoid making a small change to the exposed password. Adding a number, replacing one letter with a symbol, or updating the year does not create a strong replacement.<\/p>\n<p>For example, changing <code>Mountain2025!<\/code> to <code>Mountain2026!<\/code> leaves the main pattern intact. Attackers frequently test these predictable variations.<\/p>\n<p>A password manager can generate and store a random password so you do not need to remember it yourself.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Change-It-Everywhere-You-Reused-It\"><\/span>Change It Everywhere You Reused It<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Password reuse is one of the main reasons a single breach can lead to several account takeovers.<\/p>\n<p>Attackers often use automated tools to test stolen email-and-password combinations on many popular websites. This technique is called <strong>credential stuffing<\/strong>. It relies on the fact that many people use the same login details for email, shopping, social media, streaming, and financial services.<\/p>\n<p>Search your saved passwords and think carefully about where you may have reused the exposed credential. Change every account that uses the same password or a closely related version.<\/p>\n<p>Prioritize accounts in this order:<\/p>\n<ol>\n<li>Your primary email account<\/li>\n<li>Your password manager<\/li>\n<li>Banking and payment services<\/li>\n<li>Your main Google, Apple, or Microsoft account<\/li>\n<li>Mobile carrier accounts<\/li>\n<li>Cloud storage<\/li>\n<li>Work or school services<\/li>\n<li>Social media<\/li>\n<li>Shopping accounts<\/li>\n<li>Entertainment and subscription services<\/li>\n<\/ol>\n<p>Do not reuse the new password on any of these accounts. Each one should receive its own unique credential.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Sign-Out-Other-Devices-and-Sessions\"><\/span>Sign Out Other Devices and Sessions<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Changing the password may not immediately remove every active connection to the account.<\/p>\n<p>Look for an option such as:<\/p>\n<ul>\n<li><strong>Sign out everywhere<\/strong><\/li>\n<li><strong>Log out all devices<\/strong><\/li>\n<li><strong>End other sessions<\/strong><\/li>\n<li><strong>Remove trusted devices<\/strong><\/li>\n<li><strong>Revoke active sessions<\/strong><\/li>\n<\/ul>\n<p>Use this option when you suspect that someone else may already be signed in. You may need to log back in on your own phone, computer, tablet, browser, or email application afterward.<\/p>\n<p>Ending active sessions is particularly important when an attacker may have stolen a browser cookie or session token. In some situations, this type of access can remain active without requiring the password again.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Remove-Unrecognized-Access\"><\/span>Remove Unrecognized Access<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Review the account\u2019s security settings for changes made by someone else.<\/p>\n<p>Remove any unfamiliar:<\/p>\n<ul>\n<li>Devices<\/li>\n<li>Recovery email addresses<\/li>\n<li>Phone numbers<\/li>\n<li>Connected applications<\/li>\n<li>Browser extensions<\/li>\n<li>App-specific passwords<\/li>\n<li>Trusted sessions<\/li>\n<li>Forwarding addresses<\/li>\n<li>Inbox rules<\/li>\n<li>Delegated users<\/li>\n<\/ul>\n<p>Do not assume the problem is solved simply because the main password has changed. An attacker may have created another way to regain access later.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Enable-Multifactor-Authentication\"><\/span>Enable Multifactor Authentication<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Turn on <strong>multifactor authentication<\/strong>, also known as <a href=\"\/faq\/art\/what-is-multifactor-authentication\/\">MFA or two-factor authentication<\/a>, wherever it is available.<\/p>\n<p>MFA adds another verification step beyond the password. Depending on the account, this could involve:<\/p>\n<ul>\n<li>An authenticator app<\/li>\n<li>A passkey<\/li>\n<li>A hardware security key<\/li>\n<li>A push notification<\/li>\n<li>A text-message code<\/li>\n<li>A code sent to another trusted device<\/li>\n<\/ul>\n<p>An authenticator app, passkey, or hardware security key generally provides stronger protection than relying only on text messages. However, any supported MFA method is usually safer than using a password alone.<\/p>\n<p>Store backup or recovery codes in a secure location. Do not leave the only copy inside the email account they are meant to protect.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Watch-the-Account-After-Securing-It\"><\/span>Watch the Account After Securing It<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Continue monitoring the account after making these changes.<\/p>\n<p>Look for:<\/p>\n<ul>\n<li>New login alerts<\/li>\n<li>Unexpected MFA prompts<\/li>\n<li>Password-reset messages<\/li>\n<li>Changes to account settings<\/li>\n<li>Purchases you do not recognize<\/li>\n<li>Messages sent without your knowledge<\/li>\n<li>New connected applications<\/li>\n<li>Attempts to recover the account<\/li>\n<\/ul>\n<p>An exposed password may have been copied or traded among several groups. Blocking one attempt does not guarantee that no one else will try using it later.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Secure-Your-Email-Account-Before-Fixing-Other-Accounts\"><\/span>Secure Your Email Account Before Fixing Other Accounts<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>When several accounts may be at risk, start with your <strong>primary email account<\/strong>.<\/p>\n<p>Your inbox often acts as the recovery centre for nearly everything else you use online. Banks, shopping sites, social networks, cloud services, and other platforms may send password-reset links or security codes to that address.<\/p>\n<p>If an attacker still controls your email, they may be able to undo password changes made elsewhere.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Why-Your-Email-Account-Comes-First\"><\/span>Why Your Email Account Comes First<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A compromised inbox may allow someone to:<\/p>\n<ul>\n<li>Reset passwords for other services<\/li>\n<li>Approve account-recovery requests<\/li>\n<li>Read security notifications<\/li>\n<li>Find usernames and account numbers<\/li>\n<li>Access personal documents and attachments<\/li>\n<li>Impersonate you to friends or businesses<\/li>\n<li>Search for financial or identity information<\/li>\n<li>Intercept verification links<\/li>\n<\/ul>\n<p>For this reason, changing a social media or shopping password first may not help for long. An attacker with access to the email account could simply request another reset.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-a-Trusted-Device\"><\/span>Use a Trusted Device<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Secure the email account from a device you believe is safe.<\/p>\n<p>Ideally, use:<\/p>\n<ul>\n<li>A computer or phone you regularly control<\/li>\n<li>An updated operating system and browser<\/li>\n<li>A device without suspicious software or extensions<\/li>\n<li>A familiar home or mobile connection<\/li>\n<\/ul>\n<p>When you suspect that your usual device contains malware, use another trusted device for urgent account changes. You can return to the potentially infected device after the most important accounts are protected.<\/p>\n<p>Avoid changing passwords from public or shared computers.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Follow-the-Correct-Order\"><\/span>Follow the Correct Order<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A practical recovery order is:<\/p>\n<ol>\n<li>Check the device for obvious malware or suspicious software.<\/li>\n<li>Change the email password.<\/li>\n<li>Confirm the recovery email address and phone number.<\/li>\n<li>Enable MFA or add a passkey.<\/li>\n<li>Save fresh recovery codes.<\/li>\n<li>Sign out all other sessions.<\/li>\n<li>Remove unfamiliar devices.<\/li>\n<li>Inspect forwarding rules and filters.<\/li>\n<li>Revoke unknown connected applications.<\/li>\n<li>Begin securing other affected accounts.<\/li>\n<\/ol>\n<p>This order helps prevent an attacker from using the email account to regain access elsewhere.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Verify-Recovery-Information\"><\/span>Verify Recovery Information<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Check every recovery option connected to the email account.<\/p>\n<p>Make sure that:<\/p>\n<ul>\n<li>The recovery email belongs to you<\/li>\n<li>The listed phone number is correct<\/li>\n<li>Trusted devices are familiar<\/li>\n<li>Backup contacts are legitimate<\/li>\n<li>No unknown alias has been added<\/li>\n<li>Security questions have not been changed<\/li>\n<\/ul>\n<p>Attackers may replace recovery information before changing anything obvious. Their goal may be to return later, even after you notice the original intrusion.<\/p>\n<p>Update outdated recovery details as well. An old phone number or inaccessible email address can make it harder for you to recover the account during an emergency.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Save-Recovery-Codes-Safely\"><\/span>Save Recovery Codes Safely<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Many email providers offer one-time recovery or backup codes when MFA is enabled.<\/p>\n<p>Store these codes somewhere that is:<\/p>\n<ul>\n<li>Secure<\/li>\n<li>Accessible during an account lockout<\/li>\n<li>Separate from the protected inbox<\/li>\n<li>Not visible to other people<\/li>\n<\/ul>\n<p>A password manager, encrypted file, or securely stored printed copy may be appropriate. Avoid saving the only copy in the email account itself.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-the-Official-Recovery-Process-If-You-Are-Locked-Out\"><\/span>Use the Official Recovery Process If You Are Locked Out<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>If someone changed the password or recovery information, begin the provider\u2019s official account-recovery process.<\/p>\n<p>Use a familiar device and network when possible. Providers may use your previous login habits, location, device, recovery information, and account history to verify ownership.<\/p>\n<p>Be prepared to provide details such as:<\/p>\n<ul>\n<li>A previous password<\/li>\n<li>The approximate account-creation date<\/li>\n<li>A recovery address or phone number<\/li>\n<li>Frequently contacted addresses<\/li>\n<li>Recent account activity<\/li>\n<\/ul>\n<p>Do not trust strangers who claim they can recover the account for a fee. So-called account-recovery hackers commonly target people who are already worried and vulnerable. Only the provider can legitimately restore access to its account.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Check-the-Device-for-Malware-Before-Entering-New-Passwords\"><\/span>Check the Device for Malware Before Entering New Passwords<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Not every stolen password comes from a company data breach. Malware may collect credentials directly from your computer, phone, or browser.<\/p>\n<p>If the device remains infected, changing your passwords may offer only temporary protection. The malicious software could capture each replacement password as soon as you enter it.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"How-Malware-Can-Steal-Login-Information\"><\/span>How Malware Can Steal Login Information<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Credential-stealing malware may collect:<\/p>\n<ul>\n<li>Saved browser passwords<\/li>\n<li>Information entered into login forms<\/li>\n<li>Browser cookies<\/li>\n<li>Active session tokens<\/li>\n<li>Autofill information<\/li>\n<li>Cryptocurrency wallet data<\/li>\n<li>Screenshots<\/li>\n<li>Clipboard contents<\/li>\n<li>Files and documents<\/li>\n<li>Email and messaging credentials<\/li>\n<\/ul>\n<p>Some threats focus specifically on stealing information and sending it to criminals. These programs are often called <strong>infostealers<\/strong>.<\/p>\n<p>Attackers may also use malicious browser extensions, fake login pages, remote-access tools, or software designed to record keyboard input.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Consider-What-Happened-Before-the-Warning-Signs-Began\"><\/span>Consider What Happened Before the Warning Signs Began<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Think about any recent activity that could have exposed the device.<\/p>\n<p>Risk may be higher if you recently:<\/p>\n<ul>\n<li>Installed cracked or pirated software<\/li>\n<li>Opened an unexpected attachment<\/li>\n<li>Downloaded a fake browser or software update<\/li>\n<li>Installed an unknown browser extension<\/li>\n<li>Ran a file from an advertisement or pop-up<\/li>\n<li>Disabled antivirus protection to install something<\/li>\n<li>Allowed an unfamiliar person to access the computer remotely<\/li>\n<li>Downloaded software from an unofficial website<\/li>\n<li>Opened a suspicious archive or executable file<\/li>\n<\/ul>\n<p>A password leak warning does not prove that malware is present, but suspicious activity around the same time deserves investigation.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Update-the-Device-First\"><\/span>Update the Device First<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Install available updates for:<\/p>\n<ul>\n<li>The operating system<\/li>\n<li>Web browsers<\/li>\n<li>Security software<\/li>\n<li>Email applications<\/li>\n<li>Frequently used programs<\/li>\n<\/ul>\n<p>Updates may fix security weaknesses that malware or attackers could exploit.<\/p>\n<p>Restart the device after completing important updates when prompted.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Remove-Suspicious-Programs-and-Extensions\"><\/span>Remove Suspicious Programs and Extensions<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Review installed applications and browser extensions.<\/p>\n<p>Remove anything that:<\/p>\n<ul>\n<li>You do not remember installing<\/li>\n<li>Appeared around the time the problem began<\/li>\n<li>Has an unclear name or publisher<\/li>\n<li>Claims to provide unnecessary browser features<\/li>\n<li>Changes search results or the home page<\/li>\n<li>Displays excessive pop-ups<\/li>\n<li>Requests access to every website you visit<\/li>\n<li>Was downloaded from an unofficial source<\/li>\n<\/ul>\n<p>Be cautious when deleting software from a work or school device. Contact the organization\u2019s IT team if you are unsure whether a program is legitimate.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Run-a-Full-Security-Scan\"><\/span>Run a Full Security Scan<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Use trusted, updated security software to perform a <strong>full system scan<\/strong> rather than only a quick scan.<\/p>\n<p>A full scan may take longer, but it examines more files and locations. Follow the security program\u2019s recommendations for quarantining or removing detected threats.<\/p>\n<p>You may also use the operating system\u2019s built-in offline or restart-based scanning option when available. This can help detect malware that tries to hide while the normal system is running.<\/p>\n<p>Avoid installing several real-time antivirus products at the same time, since they may conflict with one another.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Startup-Programs-and-Browser-Settings\"><\/span>Review Startup Programs and Browser Settings<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Check whether unfamiliar applications automatically start when the device turns on.<\/p>\n<p>Also review the browser for:<\/p>\n<ul>\n<li>A changed home page<\/li>\n<li>An unfamiliar search engine<\/li>\n<li>New extensions<\/li>\n<li>Modified notification permissions<\/li>\n<li>Unwanted proxy settings<\/li>\n<li>Saved passwords you do not recognize<\/li>\n<li>Unexpected site permissions<\/li>\n<\/ul>\n<p>Resetting the browser may help when its settings have been heavily modified, but make sure important bookmarks or data are backed up first.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-Another-Device-for-Urgent-Password-Changes\"><\/span>Use Another Device for Urgent Password Changes<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When you strongly suspect malware, use a different trusted device to secure your primary email, password manager, and financial accounts.<\/p>\n<p>After the affected device has been cleaned, change critical passwords again if you entered them while the malware may have been active.<\/p>\n<p>This extra step is important because you cannot know with certainty which credentials the malware captured.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Revoke-Active-Sessions\"><\/span>Revoke Active Sessions<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Some malware steals browser sessions rather than only passwords. A stolen session token may allow an attacker to access an account without entering the password or completing MFA again.<\/p>\n<p>Sign out all active sessions and remove unfamiliar trusted devices after changing your credentials. This helps invalidate access that may have been copied from the infected device.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"What-to-Do-If-Someone-Has-Already-Accessed-the-Account\"><\/span>What to Do If Someone Has Already Accessed the Account<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>When recent activity confirms that another person entered the account, treat the situation as an active security incident.<\/p>\n<p>Your goal is to remove the intruder, prevent them from returning, identify what they may have accessed, and limit damage to other accounts.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Secure-the-Account-Immediately\"><\/span>Secure the Account Immediately<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>From a trusted device:<\/p>\n<ol>\n<li>Change the password.<\/li>\n<li>Sign out all active sessions.<\/li>\n<li>Enable MFA.<\/li>\n<li>Remove unfamiliar devices.<\/li>\n<li>Restore the correct recovery information.<\/li>\n<li>Delete unauthorized app passwords.<\/li>\n<li>Revoke suspicious connected applications.<\/li>\n<li>Remove unknown forwarding rules and filters.<\/li>\n<\/ol>\n<p>Do not reuse a password from another account.<\/p>\n<p>When the provider gives you the option, review recent security changes and mark unfamiliar activity as unauthorized.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Examine-the-Entire-Mailbox\"><\/span>Examine the Entire Mailbox<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Do not check only the main inbox.<\/p>\n<p>Review:<\/p>\n<ul>\n<li>Sent messages<\/li>\n<li>Drafts<\/li>\n<li>Deleted items<\/li>\n<li>Trash<\/li>\n<li>Spam<\/li>\n<li>Archived messages<\/li>\n<li>Custom folders<\/li>\n<li>Forwarding settings<\/li>\n<li>Inbox filters<\/li>\n<\/ul>\n<p>Look for messages you did not create, password resets you did not request, and replies from contacts who received suspicious messages.<\/p>\n<p>Attackers may delete evidence after using the account, so missing messages or unusually empty folders may also be significant.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Check-Other-Accounts-for-Damage\"><\/span>Check Other Accounts for Damage<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Search the inbox for recent account notifications, including:<\/p>\n<ul>\n<li>Password changes<\/li>\n<li>New-device alerts<\/li>\n<li>Purchases<\/li>\n<li>Money transfers<\/li>\n<li>Subscription changes<\/li>\n<li>Recovery requests<\/li>\n<li>New accounts<\/li>\n<li>Verification codes<\/li>\n<li>Shipping confirmations<\/li>\n<\/ul>\n<p>Open the relevant service directly rather than clicking links inside suspicious emails.<\/p>\n<p>Change passwords and review activity for any account that shows unexplained changes.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Warn-Your-Contacts\"><\/span>Warn Your Contacts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>If the attacker sent messages from your account, notify the people who may have received them.<\/p>\n<p>Tell them not to:<\/p>\n<ul>\n<li>Click recent unexpected links<\/li>\n<li>Open unusual attachments<\/li>\n<li>Send money<\/li>\n<li>Purchase gift cards<\/li>\n<li>Share passwords or verification codes<\/li>\n<li>Continue suspicious conversations<\/li>\n<\/ul>\n<p>Keep the warning simple and factual. Criminals may imitate your usual tone, continue an existing conversation, or refer to real details found in your inbox.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Contact-Financial-Providers-Quickly\"><\/span>Contact Financial Providers Quickly<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When you find an unrecognized purchase, transfer, or payment-account change, contact the bank, card issuer, or payment service immediately.<\/p>\n<p>Use the phone number on the official website, app, bank card, or statement. Do not call a number supplied in a suspicious email or text.<\/p>\n<p>Ask the provider to:<\/p>\n<ul>\n<li>Block or reverse unauthorized transactions when possible<\/li>\n<li>Secure the account<\/li>\n<li>Replace affected cards<\/li>\n<li>Review recent activity<\/li>\n<li>Add stronger verification<\/li>\n<li>Document the fraud report<\/li>\n<\/ul>\n<p>The faster you report financial fraud, the more options the provider may have to limit the damage.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Notify-Your-Workplace-or-School\"><\/span>Notify Your Workplace or School<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>If the affected account belongs to an employer, school, or organization, report the incident to its IT or security team immediately.<\/p>\n<p>Do not attempt to investigate or clean a managed device on your own unless instructed. The organization may need to:<\/p>\n<ul>\n<li>Preserve evidence<\/li>\n<li>Reset credentials<\/li>\n<li>Review network activity<\/li>\n<li>Check whether other accounts were affected<\/li>\n<li>Notify customers or staff<\/li>\n<li>Meet legal or regulatory obligations<\/li>\n<\/ul>\n<p>Even a personal email compromise should be reported when it exposed workplace documents, customer information, internal messages, or company passwords.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Preserve-Basic-Evidence\"><\/span>Preserve Basic Evidence<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Save relevant information such as:<\/p>\n<ul>\n<li>Security-alert emails<\/li>\n<li>Screenshots of login activity<\/li>\n<li>Dates and times<\/li>\n<li>Device names<\/li>\n<li>Approximate locations<\/li>\n<li>Suspicious messages<\/li>\n<li>Transaction records<\/li>\n<li>Changes to recovery settings<\/li>\n<li>Communication with providers<\/li>\n<\/ul>\n<p>Do not keep sensitive evidence only inside the compromised account. Store a copy somewhere secure.<\/p>\n<p>Evidence may be useful when contacting the email provider, bank, employer, law enforcement, or an identity-theft reporting service.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Contact-the-Email-Provider\"><\/span>Contact the Email Provider<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Use the provider\u2019s official support or recovery system when:<\/p>\n<ul>\n<li>You cannot remove the attacker<\/li>\n<li>The password keeps changing<\/li>\n<li>Recovery information was replaced<\/li>\n<li>Suspicious sessions return<\/li>\n<li>Messages or contacts were deleted<\/li>\n<li>The account has been suspended<\/li>\n<li>You cannot complete account recovery<\/li>\n<\/ul>\n<p>Provide clear dates, screenshots, and descriptions of unauthorized activity where possible.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Continue-Monitoring\"><\/span>Continue Monitoring<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An account takeover may affect more than the service where you first noticed it.<\/p>\n<p>For the next several weeks, watch for:<\/p>\n<ul>\n<li>New login attempts<\/li>\n<li>Unexpected MFA prompts<\/li>\n<li>Password-reset messages<\/li>\n<li>Financial activity<\/li>\n<li>Mobile carrier changes<\/li>\n<li>New credit or service accounts<\/li>\n<li>Targeted phishing messages<\/li>\n<li>Contacts reporting unusual communication<\/li>\n<\/ul>\n<p>Once criminals obtain personal information, they may use it later or share it with others. Continued monitoring helps you catch follow-up attempts before they become more serious.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"What-If-Your-Email-Appears-in-a-Breach-but-the-Password-Does-Not\"><\/span>What If Your Email Appears in a Breach but the Password Does Not?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Seeing your email address in a breach report can be unsettling, even when the incident does not list passwords among the exposed information. The good news is that an exposed email address does <strong>not automatically mean that criminals can sign in to your inbox<\/strong>.<\/p>\n<p>However, the result should not be ignored.<\/p>\n<p>An email address can still help attackers identify active accounts, create convincing phishing messages, and connect information collected from different breaches. The risk becomes greater when the incident also exposed personal details such as your name, phone number, home address, date of birth, or purchase history.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Exactly-What-Was-Exposed\"><\/span>Review Exactly What Was Exposed<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Start by reading the breach description carefully. Look for the categories of information included in the incident.<\/p>\n<p>The breach may have exposed:<\/p>\n<ul>\n<li>Email addresses<\/li>\n<li>Names and usernames<\/li>\n<li>Phone numbers<\/li>\n<li>Physical addresses<\/li>\n<li>Dates of birth<\/li>\n<li>Account activity<\/li>\n<li>Purchase or subscription history<\/li>\n<li>Security questions<\/li>\n<li>Payment details<\/li>\n<li>Password hashes<\/li>\n<\/ul>\n<p>Even if the service says that passwords were not included, check whether recovery information or other sensitive data was affected.<\/p>\n<p>For example, exposed security-question answers could make it easier for someone to attempt account recovery. A leaked phone number could also support targeted text-message scams or attempts to take control of a mobile account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Consider-Whether-You-Reused-a-Password-on-the-Affected-Service\"><\/span>Consider Whether You Reused a Password on the Affected Service<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A breach report may not always provide a complete picture of the exposed data. The affected company may also update its findings as the investigation continues.<\/p>\n<p>Change the account password when:<\/p>\n<ul>\n<li>You reused it elsewhere<\/li>\n<li>It is weak or easy to guess<\/li>\n<li>It has not been changed in years<\/li>\n<li>The affected service recommends a reset<\/li>\n<li>You used the account around the time of the breach<\/li>\n<li>You are unsure whether password data was involved<\/li>\n<\/ul>\n<p>Create a unique replacement rather than moving the same password to another account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Expect-More-Targeted-Phishing\"><\/span>Expect More Targeted Phishing<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>After a breach, attackers may send messages that appear to come from the affected company.<\/p>\n<p>Because they may already know your name, email address, account type, or recent purchase history, the message can look more believable than an ordinary scam.<\/p>\n<p>Be cautious of emails or texts that ask you to:<\/p>\n<ul>\n<li>Confirm your password<\/li>\n<li>Verify payment details<\/li>\n<li>Download a security update<\/li>\n<li>Open a breach report<\/li>\n<li>Call an urgent support number<\/li>\n<li>Pay to prevent account closure<\/li>\n<li>Provide a multifactor authentication code<\/li>\n<\/ul>\n<p>Open the company\u2019s official website or app directly instead of using the link in the message.<\/p>\n<p>A criminal does not need your email password to cause harm. Exposed personal details can be enough to make a phishing attempt feel legitimate.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Strengthen-the-Account-Anyway\"><\/span>Strengthen the Account Anyway<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Even when the breach involved only an email address, it is still a good time to improve the account\u2019s security.<\/p>\n<p>Consider taking the following steps:<\/p>\n<ul>\n<li>Enable multifactor authentication<\/li>\n<li>Review recent account activity<\/li>\n<li>Remove unused connected applications<\/li>\n<li>Update weak or reused passwords<\/li>\n<li>Turn on login notifications<\/li>\n<li>Confirm recovery information<\/li>\n<li>Watch for unexpected password-reset requests<\/li>\n<\/ul>\n<p>You usually do not need to abandon the email address simply because it appeared in a breach. Focus first on securing the account and becoming more cautious about targeted messages.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"What-If-the-Breach-Happened-Years-Ago\"><\/span>What If the Breach Happened Years Ago?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Old breach data should not be dismissed simply because the incident happened several years ago. Stolen information can remain valuable for a long time, especially when passwords, personal details, or recovery information are still in use.<\/p>\n<p>Criminals may combine older breach records with newer data to build a more complete profile of a person. They can also continue testing old passwords and predictable variations across current websites.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Check-Whether-the-Password-Is-Still-in-Use\"><\/span>Check Whether the Password Is Still in Use<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>The most important question is whether you still use the exposed password anywhere.<\/p>\n<p>Change it immediately when:<\/p>\n<ul>\n<li>It remains active on the breached account<\/li>\n<li>You reused it on another website<\/li>\n<li>You still use a similar variation<\/li>\n<li>It forms the pattern behind several current passwords<\/li>\n<li>It protects an old account that remains open<\/li>\n<\/ul>\n<p>Do not assume that a password is safe because attackers have not used it yet. Stolen credentials may be stored, resold, combined with other data, or tested long after the original breach.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Avoid-Predictable-Password-Updates\"><\/span>Avoid Predictable Password Updates<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Many people respond to a breach by changing only one part of the password.<\/p>\n<p>Examples include:<\/p>\n<ul>\n<li>Changing <code>Summer2021!<\/code> to <code>Summer2026!<\/code><\/li>\n<li>Adding another number to the end<\/li>\n<li>Replacing one letter with a symbol<\/li>\n<li>Capitalizing a different word<\/li>\n<li>Adding the website name<\/li>\n<\/ul>\n<p>These updates remain closely connected to the exposed password. Automated tools can test common substitutions and year changes quickly.<\/p>\n<p>A safer replacement should use a <strong>completely different structure<\/strong>.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Old-Accounts-That-Still-Exist\"><\/span>Review Old Accounts That Still Exist<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An old account may still contain useful information or remain connected to current services.<\/p>\n<p>Check whether the breached account includes:<\/p>\n<ul>\n<li>Saved payment methods<\/li>\n<li>Personal messages<\/li>\n<li>Home addresses<\/li>\n<li>Phone numbers<\/li>\n<li>Cloud files<\/li>\n<li>Linked social accounts<\/li>\n<li>Recovery access to another service<\/li>\n<\/ul>\n<p>Secure the account if you still need it. Delete it through the provider\u2019s official account settings when it is no longer useful and the provider offers a reliable deletion option.<\/p>\n<p>Deleting an account does not remove copies of data already taken during a breach, but it can reduce future exposure and prevent someone from misusing an abandoned profile.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Update-Old-Security-Questions\"><\/span>Update Old Security Questions<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Security-question answers can remain risky for years because the facts behind them may never change.<\/p>\n<p>A breach could expose answers related to:<\/p>\n<ul>\n<li>A childhood address<\/li>\n<li>A family member\u2019s name<\/li>\n<li>A school<\/li>\n<li>A pet<\/li>\n<li>A favourite place<\/li>\n<li>A date or personal event<\/li>\n<\/ul>\n<p>Replace these answers where possible. You do not necessarily need to provide a factually accurate response. A password manager can store a unique, random answer for each account.<\/p>\n<p>The goal is to prevent someone from finding or guessing the answer through public records, social media, or previous breach data.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Stay-Alert-for-Scams-Using-Old-Information\"><\/span>Stay Alert for Scams Using Old Information<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A message may reference an old password, address, phone number, or account to make a threat seem current.<\/p>\n<p>For example, a scammer may include a password from an old breach and claim to have recently hacked your device. The presence of a real old password can make the message frightening, but it does not prove that the rest of the claim is true.<\/p>\n<p>Do not reply, pay, or follow instructions in the message. Secure any account that still uses the exposed password and report the communication as spam or phishing.<\/p>\n<p>An old breach may no longer represent an active emergency, but it is still a useful warning. It can reveal password habits and forgotten accounts that need to be corrected.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"How-to-Create-a-Safer-Replacement-Password\"><\/span>How to Create a Safer Replacement Password<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A replacement password should not be a slightly modified version of the exposed one. It should be <strong>unique, long, and unrelated to personal information<\/strong>.<\/p>\n<p>The main goal is to make sure that a password stolen from one company cannot unlock any other account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-a-Unique-Password-for-Every-Account\"><\/span>Use a Unique Password for Every Account<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Never use the same password for email, banking, shopping, social media, and entertainment accounts.<\/p>\n<p>When each account has a unique password, a breach at one service remains more contained. Attackers cannot simply take the stolen credential and use it everywhere else.<\/p>\n<p>Unique passwords are particularly important for:<\/p>\n<ul>\n<li>Your primary email<\/li>\n<li>Password manager<\/li>\n<li>Financial accounts<\/li>\n<li>Mobile carrier<\/li>\n<li>Cloud storage<\/li>\n<li>Google, Apple, or Microsoft account<\/li>\n<li>Work and school services<\/li>\n<\/ul>\n<p>These accounts can provide access to sensitive information or help an attacker reset other passwords.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Make-the-Password-Long\"><\/span>Make the Password Long<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Length is one of the most important characteristics of a <a href=\"\/security-center\/strong-password.html\">strong password<\/a>.<\/p>\n<p>A longer password creates many more possible combinations and is generally harder to guess than a short password that contains a few symbols.<\/p>\n<p>When the service allows it, aim for a password or passphrase that is at least <strong>14 to 16 characters long<\/strong>, with more length for highly sensitive accounts.<\/p>\n<p>Do not shorten a password simply because it contains uppercase letters, numbers, and symbols. A short, complicated password may still be weaker than a much longer random one.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Avoid-Personal-and-Predictable-Information\"><\/span>Avoid Personal and Predictable Information<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Do not build passwords around details that someone could discover or guess.<\/p>\n<p>Avoid using:<\/p>\n<ul>\n<li>Your name or initials<\/li>\n<li>Birthdays<\/li>\n<li>Family names<\/li>\n<li>Pet names<\/li>\n<li>Phone numbers<\/li>\n<li>Addresses<\/li>\n<li>School or team names<\/li>\n<li>Favourite bands or movies<\/li>\n<li>Common quotations<\/li>\n<li>Simple keyboard patterns<\/li>\n<li>The name of the website<\/li>\n<\/ul>\n<p>Attackers may collect these details from social media, public records, old breaches, or information already present in the email account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-a-Password-Manager-Generated-Password\"><\/span>Use a Password Manager-Generated Password<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A <a href=\"\/faq\/art\/what-are-password-managers\/\">password manager<\/a> can create a long, random password for each account.<\/p>\n<p>A generated password may look difficult to remember, but you usually do not need to memorize it. The password manager stores and fills it when needed.<\/p>\n<p>This approach works especially well for:<\/p>\n<ul>\n<li>Shopping accounts<\/li>\n<li>Streaming services<\/li>\n<li>Social media<\/li>\n<li>Online forums<\/li>\n<li>Utility accounts<\/li>\n<li>Services you access mainly through an app<\/li>\n<\/ul>\n<p>Make sure that the password manager itself is protected with a strong, unique master password and multifactor authentication.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-a-Long-Passphrase-When-You-Need-to-Remember-It\"><\/span>Use a Long Passphrase When You Need to Remember It<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A passphrase combines several words into a longer password.<\/p>\n<p>It may be useful for a password you need to enter manually, such as the master password for a password manager.<\/p>\n<p>Choose words that are unrelated and difficult to predict. Avoid:<\/p>\n<ul>\n<li>Famous quotations<\/li>\n<li>Song lyrics<\/li>\n<li>Common sayings<\/li>\n<li>Movie lines<\/li>\n<li>Personal stories<\/li>\n<li>Predictable phrases<\/li>\n<\/ul>\n<p>A random sequence of unrelated words is generally safer than a meaningful sentence that someone may guess.<\/p>\n<p>You can also include separators or additional characters when the service requires them, but the strength should come mainly from the passphrase\u2019s <strong>length and unpredictability<\/strong>.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Do-Not-Share-or-Send-Passwords\"><\/span>Do Not Share or Send Passwords<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Avoid sending passwords through:<\/p>\n<ul>\n<li>Email<\/li>\n<li>Text messages<\/li>\n<li>Social media<\/li>\n<li>Workplace chat<\/li>\n<li>Unencrypted notes<\/li>\n<li>Shared documents<\/li>\n<\/ul>\n<p>When an account must be shared, use the password-sharing feature in a reputable password manager or create separate user access where the service supports it.<\/p>\n<p>Never give a password or MFA code to someone claiming to be customer support. A legitimate support representative should not need your current password.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Change-Passwords-When-There-Is-Evidence-of-Risk\"><\/span>Change Passwords When There Is Evidence of Risk<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>You do not need to replace every strong, unique password on a fixed monthly schedule.<\/p>\n<p>Change a password when:<\/p>\n<ul>\n<li>It appears in a breach<\/li>\n<li>The account reports suspicious activity<\/li>\n<li>Someone else may know it<\/li>\n<li>You entered it into a phishing site<\/li>\n<li>It was stored on an infected device<\/li>\n<li>You reused it<\/li>\n<li>A provider instructs you to reset it after an incident<\/li>\n<\/ul>\n<p>Unnecessary password changes can encourage predictable patterns. Focus on creating strong, unique credentials and replacing them when there is a real reason.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Use-a-Password-Manager-to-Find-and-Eliminate-Password-Reuse\"><\/span>Use a Password Manager to Find and Eliminate Password Reuse<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Remembering a different long password for every account is unrealistic for most people. A <a href=\"\/faq\/art\/what-are-password-managers\/\">password manager<\/a> solves this problem by creating, storing, and filling unique credentials.<\/p>\n<p>It can also help you find weak, reused, and compromised passwords that would otherwise be easy to overlook.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"How-a-Password-Manager-Helps\"><\/span>How a Password Manager Helps<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Depending on the product, a password manager may help you:<\/p>\n<ul>\n<li>Generate long, random passwords<\/li>\n<li>Store credentials in an encrypted vault<\/li>\n<li>Fill passwords automatically<\/li>\n<li>Identify reused passwords<\/li>\n<li>Flag weak credentials<\/li>\n<li>Warn about known compromised passwords<\/li>\n<li>Organize recovery codes<\/li>\n<li>Sync passwords across trusted devices<\/li>\n<li>Share selected credentials more safely<\/li>\n<\/ul>\n<p>These features make it easier to stop using one password pattern across many websites.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Start-With-the-Most-Important-Accounts\"><\/span>Start With the Most Important Accounts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>You do not need to update every login in one sitting.<\/p>\n<p>Begin with the accounts that could cause the greatest damage if compromised:<\/p>\n<ol>\n<li>Primary email<\/li>\n<li>Password manager<\/li>\n<li>Bank and payment services<\/li>\n<li>Mobile carrier<\/li>\n<li>Google, Apple, or Microsoft account<\/li>\n<li>Cloud storage<\/li>\n<li>Work or school accounts<\/li>\n<li>Social media<\/li>\n<\/ol>\n<p>Once these are protected, continue with shopping, entertainment, forums, and less frequently used services.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-the-Security-or-Password-Health-Report\"><\/span>Use the Security or Password-Health Report<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Many password managers include a dashboard that identifies:<\/p>\n<ul>\n<li>Reused passwords<\/li>\n<li>Compromised passwords<\/li>\n<li>Weak passwords<\/li>\n<li>Old credentials<\/li>\n<li>Accounts without MFA<\/li>\n<li>Duplicate or outdated entries<\/li>\n<\/ul>\n<p>Begin with passwords marked as both <strong>compromised and reused<\/strong>. These create the clearest opportunity for credential-stuffing attacks.<\/p>\n<p>Open each service through its official website or app, change the password, and then update the saved entry in the password manager.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Protect-the-Master-Password\"><\/span>Protect the Master Password<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>The master password protects the entire vault, so it must be especially strong.<\/p>\n<p>It should be:<\/p>\n<ul>\n<li>Unique to the password manager<\/li>\n<li>Long and difficult to guess<\/li>\n<li>Never reused elsewhere<\/li>\n<li>Not stored in ordinary notes or email<\/li>\n<li>Supported by MFA where available<\/li>\n<\/ul>\n<p>A long random passphrase can work well because you may need to remember and type it manually.<\/p>\n<p>Do not use the password manager\u2019s master password for your email, computer login, or any other service.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Turn-On-Multifactor-Authentication\"><\/span>Turn On Multifactor Authentication<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Enable MFA for the password-manager account when the provider supports it.<\/p>\n<p>An authenticator app, passkey, or hardware security key can add protection if someone learns the master password.<\/p>\n<p>Save recovery codes in a secure place outside the vault when appropriate. This can help you recover access if you lose the device used for authentication.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Remove-Outdated-and-Duplicate-Entries\"><\/span>Remove Outdated and Duplicate Entries<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Password vaults can become cluttered with old logins, duplicate records, and accounts that no longer exist.<\/p>\n<p>Review the vault periodically and:<\/p>\n<ul>\n<li>Update old website addresses<\/li>\n<li>Delete duplicate entries<\/li>\n<li>Mark inactive accounts<\/li>\n<li>Close accounts you no longer need<\/li>\n<li>Remove obsolete passwords<\/li>\n<li>Confirm that saved usernames are correct<\/li>\n<\/ul>\n<p>Cleaning the vault makes security warnings easier to understand and reduces the chance of using an outdated credential by mistake.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Remember-That-a-Password-Manager-Is-Not-Complete-Protection\"><\/span>Remember That a Password Manager Is Not Complete Protection<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A password manager greatly reduces password reuse, but it does not protect against every threat.<\/p>\n<p>You still need to:<\/p>\n<ul>\n<li>Keep devices updated<\/li>\n<li>Avoid phishing pages<\/li>\n<li>Review login alerts<\/li>\n<li>Reject unexpected MFA prompts<\/li>\n<li>Remove suspicious browser extensions<\/li>\n<li>Scan for malware<\/li>\n<li>Protect recovery codes<\/li>\n<li>Secure your email account<\/li>\n<\/ul>\n<p>A password manager works best as part of a broader security routine. Its greatest benefit is simple but important: <strong>one breached website no longer needs to put every other account at risk.<\/strong><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Turn-On-MFA-Passkeys-and-Account-Alerts\"><\/span>Turn On MFA, Passkeys, and Account Alerts<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A strong, unique password is essential, but it should not be your account\u2019s only line of defence. <strong>Multifactor authentication<\/strong>, passkeys, and security alerts can make it much harder for someone to take over an account\u2014even when they already know the password.<\/p>\n<p>These protections are especially important for your primary email, password manager, financial services, cloud storage, mobile carrier account, and main Google, Apple, or Microsoft account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Enable-Multifactor-Authentication-2\"><\/span>Enable Multifactor Authentication<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Multifactor authentication, often shortened to <strong>MFA<\/strong>, requires another form of verification in addition to the password.<\/p>\n<p>Depending on the service, the second step may involve:<\/p>\n<ul>\n<li>An authenticator app<\/li>\n<li>A hardware security key<\/li>\n<li>A passkey<\/li>\n<li>A push notification<\/li>\n<li>A code sent by text message<\/li>\n<li>A code sent to another trusted device<\/li>\n<li>A biometric check, such as a fingerprint or face scan<\/li>\n<\/ul>\n<p>This extra step can block many account-takeover attempts. An attacker may enter the correct password but still be unable to complete the login.<\/p>\n<p>Whenever possible, avoid relying on a password alone.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Choose-the-Strongest-Available-Method\"><\/span>Choose the Strongest Available Method<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Not all MFA methods provide the same level of protection.<\/p>\n<p>A practical preference order is:<\/p>\n<ol>\n<li><strong>Passkey or hardware security key<\/strong><\/li>\n<li><strong>Authenticator app<\/strong><\/li>\n<li><strong>Push approval with number matching<\/strong><\/li>\n<li><strong>Text-message or email code<\/strong><\/li>\n<li><strong>Password alone<\/strong><\/li>\n<\/ol>\n<p>The exact options will depend on the service.<\/p>\n<p>Hardware security keys and passkeys provide strong protection against many phishing attacks because they are designed to work only with the legitimate website or app. Authenticator apps are also a strong option because the generated codes are not delivered through the mobile network.<\/p>\n<p>Text-message codes still provide useful protection, but they may be more vulnerable to phone-number theft, message interception, or social engineering. Even so, SMS-based MFA is generally safer than leaving the account protected by only a password.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Understand-How-Passkeys-Work\"><\/span>Understand How Passkeys Work<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A <strong>passkey<\/strong> lets you sign in using a trusted device, fingerprint, face scan, device PIN, or security key instead of a traditional reusable password.<\/p>\n<p>The website stores a public credential, while the private part remains on your device or in your protected account ecosystem. This design means there is no ordinary password for a criminal to steal from the website and reuse elsewhere.<\/p>\n<p>Passkeys can also reduce phishing risk because they normally work only with the correct service. A fake login page cannot simply collect and reuse them in the same way it can steal a password.<\/p>\n<p>When a trusted account offers passkeys, consider adding one after confirming that your recovery options are current.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Never-Approve-an-Unexpected-Prompt\"><\/span>Never Approve an Unexpected Prompt<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An unexpected MFA request often means that someone is trying to sign in.<\/p>\n<p>Do not approve a request simply because it appears repeatedly. Attackers sometimes send many notifications in the hope that the account owner will tap <strong>Approve<\/strong> out of confusion or annoyance.<\/p>\n<p>When you receive an unexpected request:<\/p>\n<ul>\n<li>Deny it<\/li>\n<li>Do not share any displayed code<\/li>\n<li>Change the account password<\/li>\n<li>Review recent login activity<\/li>\n<li>Sign out unfamiliar sessions<\/li>\n<li>Confirm that recovery information has not changed<\/li>\n<\/ul>\n<p>Some push-based systems display a number on the login screen that must be matched in the authentication app. This feature can reduce accidental approvals, but you should still reject any request you did not initiate.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Store-Recovery-Codes-Securely\"><\/span>Store Recovery Codes Securely<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>MFA-protected accounts often provide one-time recovery or backup codes.<\/p>\n<p>These codes can help you regain access when you lose your phone, replace a device, or cannot use the normal authentication method.<\/p>\n<p>Keep recovery codes:<\/p>\n<ul>\n<li>Somewhere private and secure<\/li>\n<li>Separate from the protected account<\/li>\n<li>Out of your ordinary email inbox<\/li>\n<li>Away from shared notes or documents<\/li>\n<li>Accessible during a genuine lockout<\/li>\n<\/ul>\n<p>A password manager, encrypted file, or securely stored printed copy may be appropriate.<\/p>\n<p>Do not send recovery codes to anyone. A person who obtains one may be able to bypass the normal authentication step.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Enable-Login-and-Security-Alerts\"><\/span>Enable Login and Security Alerts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Turn on notifications for important account events, including:<\/p>\n<ul>\n<li>New-device sign-ins<\/li>\n<li>Password changes<\/li>\n<li>Recovery-information updates<\/li>\n<li>MFA changes<\/li>\n<li>New connected applications<\/li>\n<li>Suspicious login attempts<\/li>\n<li>Financial transactions<\/li>\n<li>Account-recovery requests<\/li>\n<\/ul>\n<p>Security alerts help you react before an attacker has time to make additional changes.<\/p>\n<p>Make sure these notifications go to an address or device that you still control. If all alerts are sent only to the potentially compromised inbox, an attacker may delete them before you see them.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Review-Trusted-Devices-Periodically\"><\/span>Review Trusted Devices Periodically<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Accounts may remember devices and allow them to sign in with fewer verification steps.<\/p>\n<p>Review the trusted-device list occasionally and remove:<\/p>\n<ul>\n<li>Old phones<\/li>\n<li>Previous computers<\/li>\n<li>Shared devices<\/li>\n<li>Devices you sold or gave away<\/li>\n<li>Browsers you no longer use<\/li>\n<li>Anything you do not recognize<\/li>\n<\/ul>\n<p>Keeping this list current reduces the number of places from which someone could potentially regain access.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Watch-for-Phishing-After-a-Publicized-Data-Breach\"><\/span>Watch for Phishing After a Publicized Data Breach<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A major breach often creates a second wave of danger: <strong>phishing messages that pretend to help affected customers<\/strong>.<\/p>\n<p>Criminals know that people are worried after hearing about a leak. They may send fake security alerts, password-reset notices, refund offers, or account-verification requests that appear to come from the affected company.<\/p>\n<p>Because some personal information may already be exposed, these messages can look unusually convincing.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Common-Breach-Related-Phishing-Messages\"><\/span>Common Breach-Related Phishing Messages<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A fraudulent email, text, or pop-up may claim:<\/p>\n<ul>\n<li>Your account will be closed unless you act<\/li>\n<li>Your password was found on the dark web<\/li>\n<li>You need to confirm whether your information leaked<\/li>\n<li>You qualify for a refund or compensation payment<\/li>\n<li>Your mailbox has exceeded its storage limit<\/li>\n<li>Your account has been suspended<\/li>\n<li>You must install an urgent security update<\/li>\n<li>A support representative needs to verify your identity<\/li>\n<li>Your payment method must be updated immediately<\/li>\n<\/ul>\n<p>The message may use the correct company name, your real email address, or other details taken from the breach.<\/p>\n<p>Personal information makes a scam more believable, but it does not make the message legitimate.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Do-Not-Use-Unexpected-Login-Links\"><\/span>Do Not Use Unexpected Login Links<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When a message tells you to secure an account, avoid clicking its login button.<\/p>\n<p>Instead:<\/p>\n<ol>\n<li>Open the provider\u2019s official app.<\/li>\n<li>Enter the known website address into the browser.<\/li>\n<li>Use a trusted bookmark.<\/li>\n<li>Navigate to the account\u2019s security settings.<\/li>\n<li>Check whether the same warning appears there.<\/li>\n<\/ol>\n<p>A phishing page may look nearly identical to the real website. Its purpose is to collect your password, MFA code, payment information, or recovery details.<\/p>\n<p>Also check the website address carefully. Criminals may use misspellings, extra words, unusual domains, or lookalike characters.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Never-Share-Passwords-or-Verification-Codes\"><\/span>Never Share Passwords or Verification Codes<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A legitimate company should not ask you to reply with your password or read an MFA code to an unexpected caller.<\/p>\n<p>Do not share:<\/p>\n<ul>\n<li>Current passwords<\/li>\n<li>One-time login codes<\/li>\n<li>Recovery codes<\/li>\n<li>Security-question answers<\/li>\n<li>Password-reset links<\/li>\n<li>Full payment-card details<\/li>\n<li>Remote access to your device<\/li>\n<\/ul>\n<p>A code sent to your phone or email is usually intended only for the login you started. Anyone requesting that code may be trying to complete a login as you.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Be-Careful-With-Phone-Support-Scams\"><\/span>Be Careful With Phone Support Scams<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Some phishing messages instruct victims to call a fake support number.<\/p>\n<p>The person answering may claim that:<\/p>\n<ul>\n<li>Your device contains malware<\/li>\n<li>Your bank account is being attacked<\/li>\n<li>A refund must be processed<\/li>\n<li>Your identity has been stolen<\/li>\n<li>They need remote access to fix the problem<\/li>\n<li>You must move money to a secure account<\/li>\n<\/ul>\n<p>Never install remote-access software or provide control of your device to someone who contacted you unexpectedly.<\/p>\n<p>Use only the support number listed in the provider\u2019s official app, website, account statement, or payment card.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Avoid-Fake-Breach-Checking-Tools\"><\/span>Avoid Fake Breach-Checking Tools<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A scammer may offer to reveal exactly which password was exposed.<\/p>\n<p>Be suspicious when a website or message asks you to:<\/p>\n<ul>\n<li>Enter your email and password together<\/li>\n<li>Download a special breach scanner<\/li>\n<li>Pay to remove your information from a leak<\/li>\n<li>Provide payment details before viewing results<\/li>\n<li>Install an unknown browser extension<\/li>\n<li>Sign in with your email account to continue<\/li>\n<\/ul>\n<p>Use established breach-checking services, trusted password managers, and official account-security tools instead.<\/p>\n<p>No legitimate breach checker needs your current email password simply to search for an exposed address.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Verify-Claims-Through-Independent-Sources\"><\/span>Verify Claims Through Independent Sources<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When a message refers to a real company breach, verify the incident separately.<\/p>\n<p>Check:<\/p>\n<ul>\n<li>The company\u2019s official website<\/li>\n<li>Its official security or news page<\/li>\n<li>Your account notifications<\/li>\n<li>Reputable news coverage<\/li>\n<li>A trusted breach-monitoring service<\/li>\n<\/ul>\n<p>Do not rely on contact information or links included in the suspicious message itself.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Expect-Phishing-to-Continue\"><\/span>Expect Phishing to Continue<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Breach-related scams may continue long after the original event.<\/p>\n<p>Criminals can reuse exposed information to target you with messages about:<\/p>\n<ul>\n<li>Account renewals<\/li>\n<li>Package deliveries<\/li>\n<li>Tax refunds<\/li>\n<li>Subscription payments<\/li>\n<li>Financial warnings<\/li>\n<li>Password resets<\/li>\n<li>Customer-support requests<\/li>\n<\/ul>\n<p>Remain cautious even when a message contains real information. The strongest clue is not whether the sender knows something about you, but whether the message pressures you to reveal more information or take an unusual action.<\/p>\n<hr \/>\n<p style=\"text-align: center;\">Not every urgent-looking security email is legitimate. Our guide on <strong><a href=\"https:\/\/www.antivirusaz.com\/faq\/how-to-identify-phishing-emails-in-seconds\/\">how to identify phishing emails in seconds<\/a><\/strong> explains the warning signs to check before clicking a link, downloading an attachment, or entering your login information.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Should-You-Change-Your-Email-Address-After-a-Breach\"><\/span>Should You Change Your Email Address After a Breach?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>An email address does not usually need to be abandoned simply because it appeared in a data breach.<\/p>\n<p>Email addresses are often exposed through shopping sites, forums, subscription services, and social networks. In many cases, the inbox itself remains secure and can continue to be used safely after you strengthen the account.<\/p>\n<p>Changing your address may also create practical problems because it can be connected to years of accounts, contacts, documents, and recovery settings.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"When-You-Can-Usually-Keep-the-Address\"><\/span>When You Can Usually Keep the Address<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Keeping the existing address may be reasonable when:<\/p>\n<ul>\n<li>You still control the account<\/li>\n<li>The password has been changed<\/li>\n<li>MFA or a passkey is enabled<\/li>\n<li>Recovery information is correct<\/li>\n<li>Unfamiliar sessions have been removed<\/li>\n<li>There are no malicious forwarding rules<\/li>\n<li>The main problem is ordinary spam or phishing<\/li>\n<li>You can still reliably receive security alerts<\/li>\n<\/ul>\n<p>An exposed address may receive more unwanted messages, but spam alone does not mean that the inbox is actively compromised.<\/p>\n<p>Use filters and reporting tools to manage unwanted mail, and remain careful with unexpected links and attachments.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"When-a-New-Address-May-Be-Worth-Considering\"><\/span>When a New Address May Be Worth Considering<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Creating a new address may make sense when:<\/p>\n<ul>\n<li>You cannot reliably recover the old account<\/li>\n<li>Unauthorized access keeps returning<\/li>\n<li>The account has become overwhelmed with targeted scams<\/li>\n<li>The address reveals personal information you no longer want public<\/li>\n<li>You are experiencing ongoing harassment<\/li>\n<li>The address was used publicly for many years<\/li>\n<li>You want to separate sensitive accounts from newsletters and registrations<\/li>\n<li>The provider cannot offer the security features you need<\/li>\n<\/ul>\n<p>A new address can reduce some exposure, but it will not erase information that has already leaked. Criminals may continue using the old address in phishing attempts.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Secure-the-Old-Account-Before-Abandoning-It\"><\/span>Secure the Old Account Before Abandoning It<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Do not immediately delete or ignore the old email address.<\/p>\n<p>It may still be connected to:<\/p>\n<ul>\n<li>Banking accounts<\/li>\n<li>Social media<\/li>\n<li>Cloud storage<\/li>\n<li>Shopping services<\/li>\n<li>Government services<\/li>\n<li>Mobile accounts<\/li>\n<li>Work or school platforms<\/li>\n<li>Password recovery<\/li>\n<\/ul>\n<p>Before moving away from it:<\/p>\n<ol>\n<li>Secure the old account.<\/li>\n<li>Review its forwarding and recovery settings.<\/li>\n<li>Update important services with the new address.<\/li>\n<li>Change recovery email addresses.<\/li>\n<li>Notify trusted contacts.<\/li>\n<li>Monitor the old inbox for missed account notifications.<\/li>\n<li>Remove sensitive messages and files when appropriate.<\/li>\n<\/ol>\n<p>Keep access long enough to catch important services you may have forgotten.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-Different-Addresses-or-Aliases-for-Different-Purposes\"><\/span>Use Different Addresses or Aliases for Different Purposes<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>You do not always need an entirely separate inbox for every activity. Some providers support aliases that deliver messages to the same account while giving you different addresses to use.<\/p>\n<p>A practical arrangement could include:<\/p>\n<ul>\n<li>A private address for banking and account recovery<\/li>\n<li>A personal address for friends and family<\/li>\n<li>A work or professional address<\/li>\n<li>A separate address or alias for shopping and newsletters<\/li>\n<li>A temporary alias for low-priority registrations<\/li>\n<\/ul>\n<p>This separation can reduce clutter and make suspicious messages easier to identify. For example, a banking warning sent to an address used only for newsletters would immediately look suspicious.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Keep-the-Most-Important-Address-Private\"><\/span>Keep the Most Important Address Private<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Avoid publishing the email address used for financial accounts, password recovery, and your password manager.<\/p>\n<p>Use a less sensitive address for public profiles, forums, giveaways, newsletters, and unfamiliar services.<\/p>\n<p>No address can remain completely hidden forever, but limiting where your primary address appears can reduce targeted phishing and unwanted account-recovery attempts.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"When-Exposed-Information-Creates-an-Identity-Theft-Risk\"><\/span>When Exposed Information Creates an Identity-Theft Risk<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Not every data breach creates the same level of danger.<\/p>\n<p>An exposed email address may mainly increase spam and phishing. A breach involving government identification, financial records, or detailed personal information can create a much more serious <strong>identity-theft risk<\/strong>.<\/p>\n<p>Identity theft occurs when someone uses another person\u2019s information to open accounts, make purchases, obtain services, or impersonate them.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Information-That-Requires-Greater-Caution\"><\/span>Information That Requires Greater Caution<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Take stronger precautions when a breach includes:<\/p>\n<ul>\n<li>Government identification numbers<\/li>\n<li>Passport or driver\u2019s licence information<\/li>\n<li>Tax records<\/li>\n<li>Banking details<\/li>\n<li>Payment-card numbers<\/li>\n<li>Full dates of birth<\/li>\n<li>Medical or insurance records<\/li>\n<li>Account-recovery information<\/li>\n<li>Scans of identification documents<\/li>\n<li>Digital signatures<\/li>\n<li>Detailed employment records<\/li>\n<\/ul>\n<p>A name and email address alone usually cannot support every form of identity theft. However, criminals can combine information from several sources to create a more complete profile.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Monitor-Financial-Accounts\"><\/span>Monitor Financial Accounts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Review bank, credit-card, and payment-service activity for transactions you do not recognize.<\/p>\n<p>Turn on alerts for:<\/p>\n<ul>\n<li>Purchases<\/li>\n<li>Cash withdrawals<\/li>\n<li>Transfers<\/li>\n<li>New payees<\/li>\n<li>Password changes<\/li>\n<li>Contact-information updates<\/li>\n<li>Login attempts<\/li>\n<\/ul>\n<p>Report suspicious activity through the provider\u2019s official contact channels immediately.<\/p>\n<p>A small unfamiliar transaction can sometimes be a test before a larger attempt, so do not ignore it simply because the amount is low.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Replace-Exposed-Payment-Cards\"><\/span>Replace Exposed Payment Cards<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When a breach includes full payment-card details or the provider recommends replacement, contact the card issuer.<\/p>\n<p>Ask whether the card should be:<\/p>\n<ul>\n<li>Locked<\/li>\n<li>Replaced<\/li>\n<li>Monitored<\/li>\n<li>Removed from digital wallets<\/li>\n<li>Disconnected from recurring services<\/li>\n<\/ul>\n<p>Update legitimate subscriptions after receiving the replacement card, but verify each request carefully. Criminals may send fake card-replacement messages after a breach.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Consider-Fraud-Alerts-or-Credit-Freezes\"><\/span>Consider Fraud Alerts or Credit Freezes<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Depending on your country and the information exposed, you may be able to place a <strong>fraud alert<\/strong> or <strong>credit freeze<\/strong> with credit-reporting agencies.<\/p>\n<p>A fraud alert asks lenders to take additional steps to verify your identity. A credit freeze restricts access to your credit report, which can make it harder for someone to open a new account in your name.<\/p>\n<p>A freeze is more likely to be appropriate when highly sensitive identity information has been exposed\u2014not after every basic email-address leak.<\/p>\n<p>Check the official guidance and credit-reporting options available in your country before taking action.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Protect-Your-Mobile-Account\"><\/span>Protect Your Mobile Account<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>An exposed phone number can be used in targeted scams or attempts to transfer your number to another SIM card.<\/p>\n<p>Contact your mobile carrier and add a strong account PIN or port-protection feature when available.<\/p>\n<p>Review the account for:<\/p>\n<ul>\n<li>Unfamiliar devices<\/li>\n<li>SIM changes<\/li>\n<li>New lines<\/li>\n<li>Contact-information updates<\/li>\n<li>Call-forwarding settings<\/li>\n<li>Number-transfer requests<\/li>\n<\/ul>\n<p>A criminal who takes control of a phone number may receive text-message verification codes for other accounts.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Replace-Exposed-Identity-Documents\"><\/span>Replace Exposed Identity Documents<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>When a passport, driver\u2019s licence, health card, or other official document was exposed, contact the issuing authority for guidance.<\/p>\n<p>The correct response will depend on:<\/p>\n<ul>\n<li>The document type<\/li>\n<li>Your country or province<\/li>\n<li>Whether the original document was stolen<\/li>\n<li>Whether only a number or a full image was exposed<\/li>\n<li>Whether there is evidence of misuse<\/li>\n<\/ul>\n<p>Keep copies of the breach notice and any communication with the affected organization.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Watch-for-New-Accounts-and-Services\"><\/span>Watch for New Accounts and Services<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Identity theft may not appear as a charge on an existing account.<\/p>\n<p>Look for signs such as:<\/p>\n<ul>\n<li>Bills from unfamiliar companies<\/li>\n<li>Credit applications you did not make<\/li>\n<li>New mobile or utility accounts<\/li>\n<li>Unexpected government correspondence<\/li>\n<li>Changes to tax or benefit accounts<\/li>\n<li>Debt-collection notices<\/li>\n<li>Verification messages from unfamiliar services<\/li>\n<\/ul>\n<p>Review available credit reports and official account records when sensitive identity information has been exposed.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Preserve-Evidence-and-Report-Misuse\"><\/span>Preserve Evidence and Report Misuse<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Keep records of:<\/p>\n<ul>\n<li>Breach notifications<\/li>\n<li>Fraudulent transactions<\/li>\n<li>Suspicious emails or texts<\/li>\n<li>Credit-report changes<\/li>\n<li>Account-opening notices<\/li>\n<li>Calls with financial institutions<\/li>\n<li>Official report numbers<\/li>\n<li>Copies of identification used in a claim<\/li>\n<\/ul>\n<p>Report identity theft through the appropriate government, financial, law-enforcement, or consumer-protection channels in your country.<\/p>\n<p>Do not send additional identity documents to someone who contacts you unexpectedly and claims to be investigating the breach. Verify the organization independently first.<\/p>\n<p>An email-address leak does not always require drastic action. However, when the exposed data can be used to prove identity, access money, or recover other accounts, <strong>early monitoring and official reporting can significantly reduce the damage<\/strong>.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"What-a-Breach-Checker-Can-and-Cannot-Tell-You\"><\/span>What a Breach Checker Can and Cannot Tell You<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A breach-checking service can be a useful starting point, but it does not provide a complete security diagnosis.<\/p>\n<p>These tools usually compare an email address or password against information collected from known data breaches. They can help you identify exposed accounts and decide which passwords or services require attention.<\/p>\n<p>However, a clean result does not prove that your accounts are completely safe.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"What-a-Breach-Checker-Can-Tell-You\"><\/span>What a Breach Checker Can Tell You<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Depending on the service, a breach checker may show:<\/p>\n<ul>\n<li>Whether your email address appeared in a known breach<\/li>\n<li>Which company or online service was affected<\/li>\n<li>The approximate date of the incident<\/li>\n<li>The types of information that may have been exposed<\/li>\n<li>Whether a password appeared in known stolen-password data<\/li>\n<li>Whether new breach information has been added since a previous check<\/li>\n<\/ul>\n<p>This information can help you identify where a password may have leaked and whether other personal data was involved.<\/p>\n<p>For example, a result may show that an old shopping account exposed email addresses, names, phone numbers, and password hashes. You can then change the affected password, check whether it was reused, and prepare for more targeted phishing.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"What-a-Breach-Checker-Cannot-Confirm\"><\/span>What a Breach Checker Cannot Confirm<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A breach checker usually cannot tell you:<\/p>\n<ul>\n<li>Whether someone has logged in to your account<\/li>\n<li>Whether criminals have used the exposed information<\/li>\n<li>Whether your device contains malware<\/li>\n<li>Whether an attacker stole an active browser session<\/li>\n<li>Who obtained your information<\/li>\n<li>Whether every known or private breach has been included<\/li>\n<li>Whether a recent incident has already been discovered<\/li>\n<li>Whether identity theft has occurred<\/li>\n<li>Whether an account is currently safe<\/li>\n<\/ul>\n<p>A positive breach result confirms exposure connected to a known incident, but it does not necessarily confirm account takeover.<\/p>\n<p>Similarly, a negative result does not rule out phishing, malware, password guessing, or exposure in a breach that has not yet become public.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Breach-Databases-May-Be-Incomplete\"><\/span>Breach Databases May Be Incomplete<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Not every stolen database becomes available to security researchers or breach-checking services.<\/p>\n<p>Some breaches may be:<\/p>\n<ul>\n<li>Discovered only by the affected company<\/li>\n<li>Kept private during an investigation<\/li>\n<li>Sold in closed criminal groups<\/li>\n<li>Too recent to have been processed<\/li>\n<li>Incorrectly labelled<\/li>\n<li>Missing important categories of exposed data<\/li>\n<li>Connected to malware logs rather than a company breach<\/li>\n<\/ul>\n<p>The service may also have only part of a larger dataset.<\/p>\n<p>For this reason, you should not ignore suspicious account activity simply because your address does not appear in a breach search.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Password-Results-Require-Context\"><\/span>Password Results Require Context<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>A password-checking service may tell you that a particular password has appeared in known stolen data. That does not necessarily reveal which account originally used it or whose password it was.<\/p>\n<p>Common passwords can appear many times because thousands of people independently chose the same value.<\/p>\n<p>Regardless of where the password came from, you should avoid using it. A password that appears in known breach data is likely to be included in automated guessing lists.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Combine-Breach-Checks-With-Account-Reviews\"><\/span>Combine Breach Checks With Account Reviews<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>For a more reliable assessment, combine breach checking with other security steps:<\/p>\n<ul>\n<li>Review recent login activity<\/li>\n<li>Inspect active sessions and trusted devices<\/li>\n<li>Check forwarding rules and inbox filters<\/li>\n<li>Review connected applications<\/li>\n<li>Look for password-manager warnings<\/li>\n<li>Scan devices for malware<\/li>\n<li>Enable login alerts<\/li>\n<li>Monitor financial and account activity<\/li>\n<\/ul>\n<p>A breach checker is best understood as an <strong>early-warning tool<\/strong>, not proof that an account is either hacked or completely secure.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"A-15-Minute-Compromised-Account-Response-Checklist\"><\/span>A 15-Minute Compromised-Account Response Checklist<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>When you discover an exposed password or suspicious login, it can be difficult to know where to begin. The following checklist focuses on the most important actions you can take quickly.<\/p>\n<p>You may need more than 15 minutes to investigate the full incident, but these first steps can help stop ongoing access and reduce further damage.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"First-Five-Minutes-Secure-the-Main-Account\"><\/span>First Five Minutes: Secure the Main Account<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Start with the affected account\u2014or your primary email account if several services may be involved.<\/p>\n<ol>\n<li><strong>Open the official website or app directly.<\/strong><br \/>\nDo not use a link from an unexpected email, text, or pop-up.<\/li>\n<li><strong>Change the password.<\/strong><br \/>\nCreate a completely new and unique password.<\/li>\n<li><strong>Sign out other sessions.<\/strong><br \/>\nUse the option to sign out everywhere or remove unfamiliar devices.<\/li>\n<li><strong>Enable multifactor authentication.<\/strong><br \/>\nChoose a passkey, security key, or authenticator app where available.<\/li>\n<li><strong>Confirm recovery information.<\/strong><br \/>\nCheck that the recovery email address and phone number still belong to you.<\/li>\n<\/ol>\n<p>If you cannot sign in, begin the provider\u2019s official account-recovery process from a familiar device.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Next-Five-Minutes-Remove-Hidden-Access\"><\/span>Next Five Minutes: Remove Hidden Access<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Once the password and recovery settings are secure, check for other ways an attacker may remain connected.<\/p>\n<p>Review and remove unfamiliar:<\/p>\n<ul>\n<li>Forwarding addresses<\/li>\n<li>Inbox rules<\/li>\n<li>Filters<\/li>\n<li>Connected applications<\/li>\n<li>App-specific passwords<\/li>\n<li>Trusted devices<\/li>\n<li>Browser sessions<\/li>\n<li>Delegated users<\/li>\n<li>Account aliases<\/li>\n<\/ul>\n<p>Also check the <strong>Sent<\/strong>, <strong>Trash<\/strong>, <strong>Spam<\/strong>, <strong>Drafts<\/strong>, and <strong>Archive<\/strong> folders for activity you do not recognize.<\/p>\n<p>Take quick screenshots of suspicious logins or settings before removing them when evidence may be useful.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Final-Five-Minutes-Protect-Related-Accounts\"><\/span>Final Five Minutes: Protect Related Accounts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Next, focus on the damage that could spread beyond the original account.<\/p>\n<ul>\n<li>Change the password anywhere it was reused.<\/li>\n<li>Secure your password manager.<\/li>\n<li>Review banking and payment activity.<\/li>\n<li>Check recent password-reset emails.<\/li>\n<li>Scan your device with updated security software.<\/li>\n<li>Warn contacts if suspicious messages were sent.<\/li>\n<li>Turn on login and transaction alerts.<\/li>\n<li>Check your mobile carrier account if your phone number was exposed.<\/li>\n<\/ul>\n<p>Prioritize email, financial accounts, cloud storage, mobile service, and your main Google, Apple, or Microsoft account.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"When-to-Skip-the-Checklist-and-Contact-Support-Immediately\"><\/span>When to Skip the Checklist and Contact Support Immediately<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Do not delay contacting the appropriate provider when:<\/p>\n<ul>\n<li>Money has been stolen<\/li>\n<li>You are locked out of the account<\/li>\n<li>Recovery information has been replaced<\/li>\n<li>Unauthorized sessions keep returning<\/li>\n<li>A work or school account is involved<\/li>\n<li>Identity documents were exposed<\/li>\n<li>Someone transferred or attempted to transfer your phone number<\/li>\n<li>The account is being used to scam other people<\/li>\n<\/ul>\n<p>Contact banks, email providers, employers, schools, mobile carriers, or government services through their official channels.<\/p>\n<p>The checklist is designed to help you act quickly, but serious financial fraud or ongoing unauthorized access may require immediate professional support.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"How-to-Reduce-the-Damage-From-Future-Data-Breaches\"><\/span>How to Reduce the Damage From Future Data Breaches<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>You cannot control how every company stores or protects its customer data. Even a service with strong security practices may eventually face an attack.<\/p>\n<p>You can, however, control how much damage one breach causes.<\/p>\n<p>The goal is to prevent a leaked password or email address from becoming the key to your entire digital life.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-a-Unique-Password-for-Every-Account-2\"><\/span>Use a Unique Password for Every Account<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Password reuse turns one company\u2019s breach into a risk for every service where the same password appears.<\/p>\n<p>Use a password manager to create and store unique credentials. Begin with your most sensitive accounts, including:<\/p>\n<ul>\n<li>Primary email<\/li>\n<li>Password manager<\/li>\n<li>Banking and payment services<\/li>\n<li>Mobile carrier<\/li>\n<li>Cloud storage<\/li>\n<li>Work or school accounts<\/li>\n<li>Main Google, Apple, or Microsoft account<\/li>\n<\/ul>\n<p>When every account has a different password, attackers cannot use a credential stolen from one website to unlock another.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Protect-Your-Primary-Email-More-Carefully\"><\/span>Protect Your Primary Email More Carefully<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Your email account is one of your most important digital assets because it receives password resets, security alerts, documents, and verification messages.<\/p>\n<p>Protect it with:<\/p>\n<ul>\n<li>A long, unique password<\/li>\n<li>MFA or a passkey<\/li>\n<li>Updated recovery information<\/li>\n<li>Login alerts<\/li>\n<li>Regular session reviews<\/li>\n<li>Secure recovery codes<\/li>\n<\/ul>\n<p>Avoid using your primary recovery email address for newsletters, competitions, forums, and low-priority registrations when practical.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Use-Separate-Addresses-or-Aliases\"><\/span>Use Separate Addresses or Aliases<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Separating online activities can make breaches and phishing easier to manage.<\/p>\n<p>You might use:<\/p>\n<ul>\n<li>A private address for banking and account recovery<\/li>\n<li>A personal address for friends and family<\/li>\n<li>A professional address<\/li>\n<li>An alias for shopping and subscriptions<\/li>\n<li>Another alias for newsletters and public registrations<\/li>\n<\/ul>\n<p>This approach does not prevent breaches, but it can reduce spam and help you recognize suspicious messages.<\/p>\n<p>A banking alert sent to an address used only for newsletters, for example, would immediately deserve extra scrutiny.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Turn-On-Security-Alerts\"><\/span>Turn On Security Alerts<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Enable notifications for:<\/p>\n<ul>\n<li>New logins<\/li>\n<li>Password changes<\/li>\n<li>Recovery-setting updates<\/li>\n<li>New connected applications<\/li>\n<li>Financial transactions<\/li>\n<li>Mobile-account changes<\/li>\n<li>MFA modifications<\/li>\n<\/ul>\n<p>Security alerts can help you respond before an attacker changes additional settings or moves to other accounts.<\/p>\n<p>Make sure the alert destination is current and protected.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Keep-Devices-and-Software-Updated\"><\/span>Keep Devices and Software Updated<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Install updates for:<\/p>\n<ul>\n<li>Operating systems<\/li>\n<li>Browsers<\/li>\n<li>Email applications<\/li>\n<li>Security software<\/li>\n<li>Mobile apps<\/li>\n<li>Password managers<\/li>\n<li>Frequently used programs<\/li>\n<\/ul>\n<p>Updates often repair vulnerabilities that attackers could exploit.<\/p>\n<p>Remove applications and browser extensions you no longer use. Every unnecessary program or extension creates another possible source of risk.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Be-Selective-About-Connected-Applications\"><\/span>Be Selective About Connected Applications<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Review which apps and websites have access to your email, cloud files, contacts, or social accounts.<\/p>\n<p>Remove access when:<\/p>\n<ul>\n<li>You no longer use the service<\/li>\n<li>The developer is unfamiliar<\/li>\n<li>The permissions seem excessive<\/li>\n<li>The application has been abandoned<\/li>\n<li>You cannot remember approving it<\/li>\n<\/ul>\n<p>Signing in with a major account can be convenient, but you should still understand what information the connected service can access.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Delete-Accounts-You-No-Longer-Need\"><\/span>Delete Accounts You No Longer Need<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Old accounts can continue storing personal information even when you have not used them for years.<\/p>\n<p>Where practical:<\/p>\n<ol>\n<li>Sign in through the official website.<\/li>\n<li>Remove saved payment information.<\/li>\n<li>Download anything you need.<\/li>\n<li>Disconnect other accounts.<\/li>\n<li>Use the provider\u2019s account-deletion process.<\/li>\n<li>Remove the login from your password manager after confirming deletion.<\/li>\n<\/ol>\n<p>Deleting an account cannot recover data already stolen in a previous breach, but it can reduce future exposure.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Store-Less-Sensitive-Information-in-Email\"><\/span>Store Less Sensitive Information in Email<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Email inboxes often become long-term storage for identification documents, bank statements, tax files, medical records, and password-reset messages.<\/p>\n<p>Delete information you no longer need and move important files to more appropriate secure storage.<\/p>\n<p>Also clear old password-reset emails and messages containing temporary login links after they are no longer useful.<\/p>\n<p>The less sensitive information available in the inbox, the less an attacker can collect if they gain access.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Avoid-Unexpected-MFA-Approvals\"><\/span>Avoid Unexpected MFA Approvals<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Never approve an authentication prompt you did not initiate.<\/p>\n<p>Unexpected prompts may mean that someone has already entered the correct password. Deny the request, change the password, and review the account\u2019s login activity.<\/p>\n<p>Treat verification codes and recovery codes like passwords. Do not send them to callers, support agents, or people contacting you through messages.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Check-Important-Accounts-Periodically\"><\/span>Check Important Accounts Periodically<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>You do not need to constantly monitor every login, but occasional reviews can uncover problems early.<\/p>\n<p>Periodically check:<\/p>\n<ul>\n<li>Saved-password security warnings<\/li>\n<li>Active sessions<\/li>\n<li>Trusted devices<\/li>\n<li>Connected applications<\/li>\n<li>Recovery information<\/li>\n<li>Forwarding rules<\/li>\n<li>Financial statements<\/li>\n<li>Login alerts<\/li>\n<\/ul>\n<p>You should also repeat breach checks after a major incident involving a service you use.<\/p>\n<p>The goal is not to eliminate every online risk. It is to make sure that <strong>one exposed piece of information cannot easily lead to several compromised accounts<\/strong>.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Finding-a-Breach-Is-a-Signal-to-Act-Not-a-Reason-to-Panic\"><\/span>Finding a Breach Is a Signal to Act, Not a Reason to Panic<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Discovering that your email address or password appeared in a data breach can feel frightening, but the result does not always mean that someone has entered your inbox or stolen your identity.<\/p>\n<p>A breach result tells you that information was exposed. Your next task is to determine <em>what was included<\/em>, whether the information is still in use, and whether there are signs of unauthorized access.<\/p>\n<p>Begin by checking known breach records and your password manager\u2019s security warnings. Then review recent logins, active sessions, forwarding rules, recovery information, and connected applications.<\/p>\n<p>If a password was exposed, replace it everywhere it was reused. Secure your primary email account first, enable multifactor authentication, sign out unfamiliar sessions, and scan your device when malware may be involved.<\/p>\n<p>When someone has already accessed the account, act quickly. Remove unauthorized access, review related services, warn affected contacts, preserve evidence, and contact banks, providers, employers, or official reporting services where necessary.<\/p>\n<p>Most importantly, use the incident to improve your long-term security. <strong>Unique passwords, a trusted password manager, MFA, passkeys, security alerts, and updated devices can prevent one breach from spreading across your other accounts.<\/strong><\/p>\n<p>You may not be able to stop every company from experiencing a data breach. You can still make sure that exposed information has limited value and that suspicious activity is discovered before it causes greater harm.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Frequently-Asked-Questions-About-Compromised-Emails-and-Passwords\"><\/span>Frequently Asked Questions About Compromised Emails and Passwords<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<h4><span class=\"ez-toc-section\" id=\"Does-a-Breached-Email-Mean-My-Email-Account-Was-Hacked\"><\/span>Does a Breached Email Mean My Email Account Was Hacked?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Not necessarily. Your email address may appear in a breach because a shopping site, forum, app, or other service exposed customer data. That does not automatically mean someone accessed your inbox.<\/p>\n<p>However, you should still review what information was exposed, check recent login activity, update reused passwords, and enable multifactor authentication.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Is-It-Safe-to-Enter-My-Email-Into-a-Breach-Checking-Website\"><\/span>Is It Safe to Enter My Email Into a Breach-Checking Website?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>It can be safe when you use a <strong>well-established breach-checking service<\/strong> and open the site directly through your browser.<\/p>\n<p>A legitimate service should only need the email address you want to check. It should not ask for your current email password, MFA code, recovery code, or payment information.<\/p>\n<p>Avoid links from unexpected emails, texts, pop-ups, or social media messages claiming that your account was compromised.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Is-It-Safe-to-Check-Whether-a-Password-Has-Been-Leaked\"><\/span>Is It Safe to Check Whether a Password Has Been Leaked?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Use only trusted password managers, browser security tools, operating-system password checks, or established password-checking services.<\/p>\n<p>Do not type an active password into an unfamiliar website. A malicious site could record it and use it to access your accounts.<\/p>\n<p>Whenever a trusted tool identifies a password as compromised, replace it everywhere it was used.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Should-I-Change-My-Password-If-the-Breach-Happened-Years-Ago\"><\/span>Should I Change My Password If the Breach Happened Years Ago?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Yes, if the password is still active anywhere.<\/p>\n<p>You should also change it when you continue using a similar version, such as the same base word with a different number, year, or symbol. Old breach data can remain useful to attackers for years, especially when people reuse predictable password patterns.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Do-I-Need-to-Change-Every-Password-After-a-Breach\"><\/span>Do I Need to Change Every Password After a Breach?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Not always. Focus first on the exposed password and every account where you reused it or a closely related variation.<\/p>\n<p>Prioritize your primary email, password manager, financial accounts, mobile carrier, cloud storage, and main Google, Apple, or Microsoft account.<\/p>\n<p>Passwords that are already strong, unique, and unrelated to the exposed credential may not need to be changed.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Can-Hackers-Access-Other-Accounts-With-One-Leaked-Password\"><\/span>Can Hackers Access Other Accounts With One Leaked Password?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Yes. Attackers may use <strong>credential stuffing<\/strong> to test a leaked email-and-password combination on many popular websites.<\/p>\n<p>This is why password reuse is so dangerous. A password exposed through an old shopping account could also unlock email, social media, streaming, cloud, or payment accounts when the same credential was reused.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Why-Am-I-Still-Seeing-Suspicious-Logins-After-Changing-My-Password\"><\/span>Why Am I Still Seeing Suspicious Logins After Changing My Password?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Several explanations are possible. An attacker may still have an active session, a connected application, an app-specific password, or access through malicious forwarding rules.<\/p>\n<p>Your device may also contain malware or a stolen browser session may remain active.<\/p>\n<p>Sign out all sessions, remove unfamiliar devices and apps, inspect forwarding settings, enable MFA, and scan the device with updated security software.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Should-I-Delete-a-Compromised-Email-Account\"><\/span>Should I Delete a Compromised Email Account?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Usually, you should secure the account before considering deletion.<\/p>\n<p>The address may still be connected to banking, social media, cloud storage, shopping accounts, and password-recovery settings. Deleting it too soon could make other accounts harder to recover.<\/p>\n<p>A new address may be worth considering when you cannot regain reliable control, targeted abuse continues, or the account no longer provides adequate security features.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Does-Multifactor-Authentication-Protect-Me-If-My-Password-Leaks\"><\/span>Does Multifactor Authentication Protect Me If My Password Leaks?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>MFA can block many unauthorized login attempts because the password alone is not enough to complete the sign-in.<\/p>\n<p>However, you should still change the exposed password, end active sessions, review account settings, and check for malware. MFA reduces risk, but it does not make a compromised password safe to keep using.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"What-Should-I-Do-If-I-Receive-an-Unexpected-MFA-Prompt\"><\/span>What Should I Do If I Receive an Unexpected MFA Prompt?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Deny the request and do not share any code.<\/p>\n<p>An unexpected prompt may mean someone has already entered the correct password. Change the password from a trusted device, review recent login activity, remove unfamiliar sessions, and confirm that recovery information has not changed.<\/p>\n<p>Never approve repeated requests simply to make them stop.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Can-a-Clean-Breach-Check-Prove-That-My-Account-Is-Safe\"><\/span>Can a Clean Breach Check Prove That My Account Is Safe?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>No. A clean result only means that the address or password was not found in the breach data available to that service.<\/p>\n<p>The account could still be affected by a recent private breach, phishing, malware, password guessing, or session theft.<\/p>\n<p>Continue investigating when you see unfamiliar logins, password changes, missing messages, unexpected MFA prompts, or unknown forwarding rules.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Should-I-Change-My-Email-Address-If-It-Appears-in-a-Data-Breach\"><\/span>Should I Change My Email Address If It Appears in a Data Breach?<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Usually not. An exposed address can often continue to be used safely after you change weak or reused passwords, enable MFA, review sessions, and confirm recovery settings.<\/p>\n<p>Consider using a new address when the old account cannot be secured, harassment continues, or you want to separate sensitive accounts from public registrations and newsletters.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"References\"><\/span>References<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener\">Have I Been Pwned \u2013 Email Breach Search<\/a> \u2013 Check whether an email address has appeared in known data breaches and review which services and data types were involved.<\/li>\n<li><a href=\"https:\/\/haveibeenpwned.com\/Passwords\" target=\"_blank\" rel=\"noopener\">Have I Been Pwned \u2013 Pwned Passwords<\/a> \u2013 Check whether a password has previously appeared in known breach data. The service uses a privacy-preserving method that does not send the complete password hash.<\/li>\n<li><a href=\"https:\/\/haveibeenpwned.com\/FAQs\" target=\"_blank\" rel=\"noopener\">Have I Been Pwned \u2013 Frequently Asked Questions<\/a> \u2013 Explains how the breach-search service works, what its results mean, how passwords are handled, and why a clean result cannot guarantee that an account has never been exposed.<\/li>\n<li><a href=\"https:\/\/www.nist.gov\/cybersecurity-and-privacy\/how-do-i-create-good-password\" target=\"_blank\" rel=\"noopener\">NIST \u2013 How Do I Create a Good Password?<\/a> \u2013 Practical guidance from the National Institute of Standards and Technology on creating and managing safer passwords.<\/li>\n<li><a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63b.html\" target=\"_blank\" rel=\"noopener\">NIST Special Publication 800-63B: Authentication and Authenticator Management<\/a> \u2013 Technical digital-identity guidance covering passwords, authentication requirements, compromised-password screening, and account security.<\/li>\n<li><a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63b\/authenticators\/\" target=\"_blank\" rel=\"noopener\">NIST \u2013 Authenticator Requirements<\/a> \u2013 Detailed information about passwords, one-time codes, cryptographic authenticators, recovery methods, and other authentication technologies.<\/li>\n<li><a href=\"https:\/\/pages.nist.gov\/800-63-FAQ\/\" target=\"_blank\" rel=\"noopener\">NIST Digital Identity Guidelines FAQ<\/a> \u2013 Answers common questions about NIST\u2019s recommendations for passwords, multifactor authentication, account recovery, and digital identity.<\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/MFA\" target=\"_blank\" rel=\"noopener\">CISA \u2013 Multifactor Authentication<\/a> \u2013 An overview of how multifactor authentication helps protect accounts when passwords are stolen or guessed.<\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/topics\/cybersecurity-best-practices\/multifactor-authentication\" target=\"_blank\" rel=\"noopener\">CISA \u2013 Multifactor Authentication Best Practices<\/a> \u2013 Guidance on selecting and using stronger authentication methods to reduce the risk of account takeover.<\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2022\/10\/31\/cisa-releases-guidance-phishing-resistant-and-numbers-matching-multifactor-authentication\" target=\"_blank\" rel=\"noopener\">CISA \u2013 Phishing-Resistant MFA and Number Matching<\/a> \u2013 Explains why phishing-resistant authentication and number matching provide better protection than simple push approvals.<\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/news-events\/news\/next-level-mfa-fido-authentication\" target=\"_blank\" rel=\"noopener\">CISA \u2013 Next-Level MFA: FIDO Authentication<\/a> \u2013 An introduction to FIDO-based authentication, security keys, and stronger methods designed to reduce password and phishing risks.<\/li>\n<li><a href=\"https:\/\/consumer.ftc.gov\/consumer-alerts\/2022\/10\/have-you-been-affected-data-breach-read\" target=\"_blank\" rel=\"noopener\">FTC \u2013 Have You Been Affected by a Data Breach?<\/a> \u2013 Consumer guidance on evaluating breach notifications, determining what information was exposed, and taking appropriate protective steps.<\/li>\n<li><a href=\"https:\/\/consumer.ftc.gov\/articles\/protect-your-personal-information-hackers-and-scammers\" target=\"_blank\" rel=\"noopener\">FTC \u2013 Protect Your Personal Information From Hackers and Scammers<\/a> \u2013 Advice on protecting online accounts, recognizing scams, securing personal information, and responding to suspicious activity.<\/li>\n<li><a href=\"https:\/\/consumer.ftc.gov\/articles\/what-know-about-identity-theft\" target=\"_blank\" rel=\"noopener\">FTC \u2013 What to Know About Identity Theft<\/a> \u2013 Explains common forms of identity theft, possible warning signs, and steps to take when personal information is misused.<\/li>\n<li><a href=\"https:\/\/consumer.ftc.gov\/articles\/credit-freezes-and-fraud-alerts\" target=\"_blank\" rel=\"noopener\">FTC \u2013 Credit Freezes and Fraud Alerts<\/a> \u2013 Describes how credit freezes and fraud alerts work and when they may help after sensitive identity information has been exposed.<\/li>\n<li><a href=\"https:\/\/www.identitytheft.gov\/\" target=\"_blank\" rel=\"noopener\">IdentityTheft.gov<\/a> \u2013 The U.S. government\u2019s identity-theft reporting and recovery website, which helps affected consumers create a personalized recovery plan.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Finding out that your email address or password may have appeared in a data breach can be alarming. You might receive a security notification, notice an unfamiliar login, or discover that one of your accounts was included in a recently reported cyberattack. However, an exposed email address does not always mean that someone has successfully [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5463,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[325],"tags":[809,810],"class_list":["post-5452","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-compromised-email","tag-compromised-password"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Check If Your Email or Password Was Compromised<\/title>\n<meta name=\"description\" content=\"Learn how to check if your email or password was compromised, secure affected accounts, and prevent further unauthorized access.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Check If Your Email or Password Was Compromised\" \/>\n<meta property=\"og:description\" content=\"Learn how to check if your email or password was compromised, secure affected accounts, and prevent further unauthorized access.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/\" \/>\n<meta property=\"og:site_name\" content=\"Antivirus and Security Software FAQs &amp; Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T18:06:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-20T18:33:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"kbmain\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"kbmain\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"65 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/\"},\"author\":{\"name\":\"kbmain\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#\\\/schema\\\/person\\\/9d2a9e498b139553b88912644883ce25\"},\"headline\":\"How to Check If Your Email or Password Has Been Compromised and What to Do Next\",\"datePublished\":\"2026-07-20T18:06:44+00:00\",\"dateModified\":\"2026-07-20T18:33:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/\"},\"wordCount\":14737,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/chec-email-password-compromised.webp\",\"keywords\":[\"compromised email\",\"compromised password\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/\",\"name\":\"How to Check If Your Email or Password Was Compromised\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/chec-email-password-compromised.webp\",\"datePublished\":\"2026-07-20T18:06:44+00:00\",\"dateModified\":\"2026-07-20T18:33:52+00:00\",\"description\":\"Learn how to check if your email or password was compromised, secure affected accounts, and prevent further unauthorized access.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/chec-email-password-compromised.webp\",\"contentUrl\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/chec-email-password-compromised.webp\",\"width\":1536,\"height\":1024,\"caption\":\"How to Check If Your Email or Password Has Been Compromised and What to Do Next\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/how-to-check-if-email-or-password-has-been-compromised\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Check If Your Email or Password Has Been Compromised and What to Do Next\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#website\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/\",\"name\":\"Antivirus and Security Software FAQs & Blog\",\"description\":\"Frequently asked questions about antivirus and security software, and other computer security related issues.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#organization\"},\"alternateName\":\"AntivirusAZ.com FAQs & Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#organization\",\"name\":\"AntiVirusAZ.com\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/antivirusaz-faq-blog-logo.png\",\"contentUrl\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/antivirusaz-faq-blog-logo.png\",\"width\":1536,\"height\":512,\"caption\":\"AntiVirusAZ.com\"},\"image\":{\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.antivirusaz.com\\\/faq\\\/#\\\/schema\\\/person\\\/9d2a9e498b139553b88912644883ce25\",\"name\":\"kbmain\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e2d3286d66e8fdf75944d7b4683ca846102c2ac589ea41eba5a8d053ef5fcef5?s=96&d=robohash&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e2d3286d66e8fdf75944d7b4683ca846102c2ac589ea41eba5a8d053ef5fcef5?s=96&d=robohash&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e2d3286d66e8fdf75944d7b4683ca846102c2ac589ea41eba5a8d053ef5fcef5?s=96&d=robohash&r=g\",\"caption\":\"kbmain\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Check If Your Email or Password Was Compromised","description":"Learn how to check if your email or password was compromised, secure affected accounts, and prevent further unauthorized access.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/","og_locale":"en_US","og_type":"article","og_title":"How to Check If Your Email or Password Was Compromised","og_description":"Learn how to check if your email or password was compromised, secure affected accounts, and prevent further unauthorized access.","og_url":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/","og_site_name":"Antivirus and Security Software FAQs &amp; Blog","article_published_time":"2026-07-20T18:06:44+00:00","article_modified_time":"2026-07-20T18:33:52+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp","type":"image\/webp"}],"author":"kbmain","twitter_card":"summary_large_image","twitter_misc":{"Written by":"kbmain","Est. reading time":"65 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#article","isPartOf":{"@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/"},"author":{"name":"kbmain","@id":"https:\/\/www.antivirusaz.com\/faq\/#\/schema\/person\/9d2a9e498b139553b88912644883ce25"},"headline":"How to Check If Your Email or Password Has Been Compromised and What to Do Next","datePublished":"2026-07-20T18:06:44+00:00","dateModified":"2026-07-20T18:33:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/"},"wordCount":14737,"commentCount":0,"publisher":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#organization"},"image":{"@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#primaryimage"},"thumbnailUrl":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp","keywords":["compromised email","compromised password"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/","url":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/","name":"How to Check If Your Email or Password Was Compromised","isPartOf":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#primaryimage"},"image":{"@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#primaryimage"},"thumbnailUrl":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp","datePublished":"2026-07-20T18:06:44+00:00","dateModified":"2026-07-20T18:33:52+00:00","description":"Learn how to check if your email or password was compromised, secure affected accounts, and prevent further unauthorized access.","breadcrumb":{"@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#primaryimage","url":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp","contentUrl":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2026\/07\/chec-email-password-compromised.webp","width":1536,"height":1024,"caption":"How to Check If Your Email or Password Has Been Compromised and What to Do Next"},{"@type":"BreadcrumbList","@id":"https:\/\/www.antivirusaz.com\/faq\/how-to-check-if-email-or-password-has-been-compromised\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.antivirusaz.com\/faq\/"},{"@type":"ListItem","position":2,"name":"How to Check If Your Email or Password Has Been Compromised and What to Do Next"}]},{"@type":"WebSite","@id":"https:\/\/www.antivirusaz.com\/faq\/#website","url":"https:\/\/www.antivirusaz.com\/faq\/","name":"Antivirus and Security Software FAQs & Blog","description":"Frequently asked questions about antivirus and security software, and other computer security related issues.","publisher":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#organization"},"alternateName":"AntivirusAZ.com FAQs & Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.antivirusaz.com\/faq\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.antivirusaz.com\/faq\/#organization","name":"AntiVirusAZ.com","url":"https:\/\/www.antivirusaz.com\/faq\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.antivirusaz.com\/faq\/#\/schema\/logo\/image\/","url":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2023\/02\/antivirusaz-faq-blog-logo.png","contentUrl":"https:\/\/www.antivirusaz.com\/faq\/wp-content\/uploads\/2023\/02\/antivirusaz-faq-blog-logo.png","width":1536,"height":512,"caption":"AntiVirusAZ.com"},"image":{"@id":"https:\/\/www.antivirusaz.com\/faq\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.antivirusaz.com\/faq\/#\/schema\/person\/9d2a9e498b139553b88912644883ce25","name":"kbmain","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e2d3286d66e8fdf75944d7b4683ca846102c2ac589ea41eba5a8d053ef5fcef5?s=96&d=robohash&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e2d3286d66e8fdf75944d7b4683ca846102c2ac589ea41eba5a8d053ef5fcef5?s=96&d=robohash&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e2d3286d66e8fdf75944d7b4683ca846102c2ac589ea41eba5a8d053ef5fcef5?s=96&d=robohash&r=g","caption":"kbmain"}}]}},"_links":{"self":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/posts\/5452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/comments?post=5452"}],"version-history":[{"count":23,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/posts\/5452\/revisions"}],"predecessor-version":[{"id":5476,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/posts\/5452\/revisions\/5476"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/media\/5463"}],"wp:attachment":[{"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/media?parent=5452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/categories?post=5452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.antivirusaz.com\/faq\/wp-json\/wp\/v2\/tags?post=5452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}