EXONARA TECHNOLOGIES
5-MINUTE READ

What to Do If Your Email Is in a Data Breach A 24-Hour Plan

You typed your email into haveibeenpwned.com out of curiosity, and now you're staring at a list of four breaches you'd never heard of. Here's exactly what to do next, in order.

Hour 1: change the password on the breached accounts

Start with anything financial, then email, then everything else. If you've reused that password anywhere else, change those too this is the single most common way one small breach becomes a much bigger problem.

Hour 2: turn on two-factor authentication

Wherever it's available, especially email and banking. A leaked password is far less dangerous if it alone isn't enough to get in.

Hour 6: check for suspicious activity

Look at recent login history, sent emails you didn't send, and any account recovery emails you didn't request. These are the early signs someone already tried to use what leaked.

Within 24 hours: get a password manager

The real fix isn't reacting to this one breach it's making sure the next one only affects a single, unique password instead of every account you own.

What each breach actually exposed

Click into each listed breach on haveibeenpwned.com — they tell you exactly what data was taken (passwords, emails, phone numbers, sometimes addresses). This matters: a breach that leaked only your email is a lower priority than one that leaked your password in plain text.

The mistake most people make

This is one part of staying safe online. The full guide covers this and much more, in plain English.

Get the guide →