EXONARA TECHNOLOGIES
5-MINUTE READ

What to Do If Your Email Is in a Data Breach — A 24-Hour Plan

You typed your email into haveibeenpwned.com out of curiosity, and now you're staring at a list of four breaches you'd never heard of. Here's exactly what to do next, in order.

Hour 1: change the password on the breached accounts

Start with anything financial, then email, then everything else. If you've reused that password anywhere else, change those too — this is the single most common way one small breach becomes a much bigger problem.

Hour 2: turn on two-factor authentication

Wherever it's available, especially email and banking. A leaked password is far less dangerous if it alone isn't enough to get in.

Hour 6: check for suspicious activity

Look at recent login history, sent emails you didn't send, and any account recovery emails you didn't request. These are the early signs someone already tried to use what leaked.

Within 24 hours: get a password manager

The real fix isn't reacting to this one breach — it's making sure the next one only affects a single, unique password instead of every account you own.

This is one part of staying safe online. The full guide covers this and much more, in plain English.

Get the guide →