A company leaked your data. Now what?
A calm order of operations, and the thing most people waste their time on.
Updated 2026-09-26
You get the email, or you see it in the news. A company you used has been breached. Here is what actually matters, in order.
1. Find out what was taken
"A breach" covers everything from email addresses to full payment details. The answer changes what you should do:
- Email address only — expect more phishing aimed at you. Nothing urgent.
- Password — change it there and, critically, anywhere you reused it.
- Payment details — contact your bank and get the card replaced.
- Identity documents — the most serious, and worth a conversation with your bank about fraud
markers on your file.
2. Change reused passwords first, not the breached one
This is the step people get backwards. The account that leaked is already known. The danger is every *other* account where you used that same password, because that is what automated attacks try next. Start there.
Our password checker tells you whether a specific password is already circulating in breach data. It runs in your browser and never sends the password anywhere.
3. Turn on a second factor where you have not
A breach is the prompt most people need. Email account first.
4. Expect targeted phishing, and recognise it
The most reliable consequence of a breach is not fraud — it is a wave of convincing messages that know your name, the company you used, and sometimes what you bought. Treat anything referencing the breach as suspicious, especially if it offers compensation or asks you to "secure your account".
Companies do not email you a link to reset your password after a breach and expect you to use it. Go to the site yourself.
What is usually not worth your time
Credit monitoring you have to pay for. The free version your bank offers is generally enough, and paid monitoring detects fraud after the fact rather than preventing it.
Panic about your email address being public. It already was. That is what email addresses do.
The uncomfortable part
You cannot undo a breach, and you have almost no control over which companies hold your data or how carefully. What you *can* control is that one leak does not become five compromised accounts — and that is entirely down to whether you reused the password.
Check a password Free, and it needs no account.