Finding out a company you use has been breached is unsettling, but what you do next matters more than the headline. In most breaches, the damage is not automatic — it comes from accounts left unchanged and warnings left unread. The steps below walk you through what to do, from password changes to longer-term habits.
What a data breach actually means for you
A data breach means someone gained access to information a company stored about you. The exposed data can include your email address, username, phone number, password, or payment card details. If the company stored passwords, they may have been scrambled, but assume yours is out there and act accordingly.
Exposure is not the same as a takeover. The goal is simply to close the obvious doors before anyone walks through them.
First steps: find out what was exposed and change passwords
- Check the breach notification. If the company contacted you, read the message carefully. It usually lists which categories of data were involved.
- Change that password right away. Log into the affected service and set a new, strong password that you have not used anywhere else.
- Change it everywhere you reused it. This is the step people skip, and it is the most important one. If the breached password was used on other sites, someone who has it can try it there. Visit every site where you used the same password and change it.
To find out which older breaches include your email, use a free breach-check service like Have I Been Pwned (haveibeenpwned.com). It lets you search your email address against known breach collections. If it comes back positive, change that password immediately.
Check for suspicious activity
After you change passwords, look around the affected account and your email for signs someone else has been active:
- Review recent logins. Most email and social services have a security or activity page that lists recent sessions and locations.
- Look at connected devices and apps. Revoke anything you do not recognize.
- Search your inbox for reset emails. Password reset messages you never requested can mean someone tried to take over the account.
If payment details were exposed
If the breach involved payment card information, watch your statements for charges you do not recognize — even small ones — and keep checking for a few weeks. Many card issuers let you freeze a card instantly from their app. If you see anything suspicious, contact your bank or card issuer and ask about a replacement card.
Turn on two-factor authentication
Two-factor authentication adds a second check beyond your password, usually a code generated on your phone or a key you tap. Even if a stolen password is floating around, an attacker without that second factor cannot get in. Turn it on for the affected account and for your email, since your email is the recovery key for almost everything else. Our guide to two-factor authentication walks you through the setup.
Watch for follow-up phishing
Breached companies are a favorite costume for scammers. In the days after a breach becomes public, expect emails that pretend to be the company, offering free credit monitoring or asking you to verify your account by clicking a link. These are often attempts to steal your password or personal details all over again.
Do not click links in unexpected messages. Instead, open your browser and go to the company's site yourself. If you want to learn how to spot online scams, start with the sender's address and any pressure to act immediately.
A clear checklist is better than a panicked rush.
Make the next breach hurt less
The best way to survive a breach is to be a harder target. Use a password manager to generate a unique, strong password for every account, and never reuse one. When a breach happens, you change a single password and you are done, instead of hunting through every site you have ever joined.
Run a breach check from time to time using Have I Been Pwned. It helps you catch old leaks and know which accounts still need a fresh password.
Quick answers
Should I change my password even if I did not reuse it? Yes — change it on the breached service regardless. Then focus on any other accounts that shared the same password.
How do I know a breach notification is real? Scammers send fake breach alerts too. Do not click links in the message. Visit the company's official site to confirm.
Is it safe to use a breach-check service? A reputable one only needs your email address. If a site asks for your password or payment details to run a check, it is not one you should trust.
What should I do if I see suspicious activity? Change the password, sign out of all sessions, and enable two-factor authentication. For payment fraud, contact your bank or card issuer immediately.
Sources and further reading
- FTC: IdentityTheft.gov
- FTC: Recognize and avoid phishing scams
- CISA: Secure our world
- Have I Been Pwned
Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026.