"Your password appeared in a data breach": what to do right now

Updated: August 2026

That alert from Google, your iPhone or your password manager is not alarmism: it means the password sits in real breach databases that attackers use daily. The right response takes 15 minutes and follows a specific order.

Step 1: change your email password first

Your email is the master key to everything else: it is where password resets for all other services arrive. If the leaked password (or anything similar) is your email's, change it now to a random 16+ character one and enable two-factor authentication.

Step 2: change the leaked password… everywhere you used it

Here is the real danger: attackers take credentials leaked from one site and try them automatically on hundreds of services (banking, Amazon, social networks). It is called credential stuffing and it is the most common attack in the world. Recall where you reused that password or its variants ("the same but with a 2" counts as reused) and replace them all with unique ones.

Step 3: assess the damage

  • In each important account, check "recent activity" or "connected devices" and sign out any session you do not recognize.
  • Check your email's forwarding rules: attackers sometimes create silent redirects to read your mail.
  • For banking and cards, review recent transactions.

Step 4: check what else is out there

At haveibeenpwned.com you can enter your email and see which known breaches include it and which data was exposed (passwords, phone numbers, addresses). Many password managers run this audit continuously and flag compromised or repeated passwords in your vault.

Step 5: bulletproof yourself for next time (there will be a next time)

  1. Password manager + a unique random password per service: one breach stops affecting the rest of your digital life.
  2. Two-factor authentication on email, banking and socials — preferably an authenticator app or hardware key, not SMS.
  3. Passkeys: when a service offers to create one (fingerprint/face sign-in with no password), accept: passkeys are immune to password leaks and to phishing.

Beware the follow-up scam: after big breaches come fake "change your password here" emails. Never change passwords from an email link — go to the official site yourself.

💡 Try it yourself: use our Strong password generator — free, no sign-up, no watermarks.

Frequently asked questions

How do I know the breach alert is real and not phishing?

Legitimate alerts from Google/Apple/your manager appear inside the app or settings, and never ask for data via email. When in doubt, do not click the email link: open the service manually and check its security notifications.

The leaked password was for a site I no longer use — does it matter?

Yes, if you reused it elsewhere or still have an account there (exposed personal data, possible impersonation). Change the password or delete the account, and verify no active account shares that password.

Should I pay for "dark web monitoring" services?

Usually not: haveibeenpwned is free, and password managers and many browsers already include breach alerts. Paid services add little for an individual user.

What exactly is a passkey and why is it better?

A passkey is a cryptographic key stored on your device that signs you in with your fingerprint or face. There is no password to steal or leak, and it will not work on fake sites, which kills phishing. Major services (Google, Apple, Amazon, PayPal…) already support them.