You typed your email into haveibeenpwned.com out of curiosity, and now you're staring at a list of four breaches you'd never heard of. Here's exactly what to do next, in order.
Start with anything financial, then email, then everything else. If you've reused that password anywhere else, change those too — this is the single most common way one small breach becomes a much bigger problem.
Wherever it's available, especially email and banking. A leaked password is far less dangerous if it alone isn't enough to get in.
Look at recent login history, sent emails you didn't send, and any account recovery emails you didn't request. These are the early signs someone already tried to use what leaked.
The real fix isn't reacting to this one breach — it's making sure the next one only affects a single, unique password instead of every account you own.
This is one part of staying safe online. The full guide covers this and much more, in plain English.
Get the guide →