TL;DR: Check which of your accounts use the same email and password combination that appeared in the breach — password reuse is the main way a single breach turns into multiple compromised accounts.
How to Lock Down Your Accounts After a Data Breach — a clear, step-by-step guide to what to do and how long it takes.
Step 1: Identify which accounts used the breached credentials
Check which of your accounts use the same email and password combination that appeared in the breach — password reuse is the main way a single breach turns into multiple compromised accounts.
Step 2: Change passwords on affected accounts first
Start with your most sensitive accounts — email, banking, and any account tied to payment methods — and give each a unique, strong password rather than reusing one across sites.
Step 3: Enable two-factor authentication everywhere you can
Turn on 2FA, ideally via an authenticator app, on your email, financial accounts, and any other account offering it — this blocks most account takeover attempts even if a password leaks again.
Step 4: Check for unfamiliar activity
Review login history, connected devices, and recent activity on affected accounts for anything you don't recognize, and log out any unfamiliar sessions.
Step 5: Use a password manager going forward
A password manager makes it practical to give every account a unique password, so a future breach at one site can't cascade into others.
If this looks similar to something else you've seen, it's worth reading How to Opt Out of Prescreened Credit Offers.
This pattern shows up elsewhere too — see How to Place a Fraud Alert on Your Credit Report.
Frequently Asked Questions
Step 1: Identify which accounts used the breached credentials
Check which of your accounts use the same email and password combination that appeared in the breach — password reuse is the main way a single breach turns into multiple compromised accounts.
Step 2: Change passwords on affected accounts first
Start with your most sensitive accounts — email, banking, and any account tied to payment methods — and give each a unique, strong password rather than reusing one across sites.
Step 3: Enable two-factor authentication everywhere you can
Turn on 2FA, ideally via an authenticator app, on your email, financial accounts, and any other account offering it — this blocks most account takeover attempts even if a password leaks again.
Step 4: Check for unfamiliar activity
Review login history, connected devices, and recent activity on affected accounts for anything you don't recognize, and log out any unfamiliar sessions.
Step 5: Use a password manager going forward
A password manager makes it practical to give every account a unique password, so a future breach at one site can't cascade into others.