What to do if…
you get notified of a data breach and you reuse that password on other accounts
Short answer
Treat the reused password as compromised. Change it everywhere you used it, starting with your email account, then turn on two-factor authentication on your most important accounts.
Do not do these things
- Don’t click links or call numbers in the breach notice until you verify them independently. Use the company’s official website, official app, or a phone number you already trust, such as one on your card, statement, or account settings.
- Don’t share one-time verification codes or sensitive identifiers in response to an inbound email, text, phone call, or chat message.
- Don’t reuse the old password with small edits, such as changing one number or symbol.
- Don’t start with low-priority accounts first; lock down email, financial accounts, phone-provider accounts, and major Apple, Google, or Microsoft accounts before less important accounts.
- Don’t save new passwords in a plain note, screenshot, email draft, or unprotected file.
- Don’t assume nothing is wrong just because the account looks normal right now.
What to do now
-
Confirm the notice is real without engaging with the message.
Go directly to the company’s official website or app. Type the address yourself, use a bookmark you already trust, or use the existing app. Look for a security notice in your account. -
Secure your email account first.
Your email often controls password resets for other accounts. Change your email password to a strong, unique password, turn on two-factor authentication, and check for unfamiliar forwarding rules, filters, recovery emails, or recovery phone numbers. -
Change the breached account password next.
Use a brand-new unique password. If the service has a security, devices, or sessions page, sign out of other sessions and review recent login activity. -
Change the reused password everywhere else you used it.
Start with accounts that could cause the most damage:- banks, credit cards, payment apps, and tax accounts
- Apple, Google, Microsoft, and other major identity accounts
- your mobile carrier account
- work accounts, cloud storage, and your password manager
- shopping, social media, subscriptions, and older accounts
-
Turn on two-factor authentication where it matters most.
Start with email, financial accounts, your mobile carrier, and major identity accounts. Use an authenticator app or security key when available, and store backup codes somewhere protected. -
Add alerts so you notice new attempts quickly.
Turn on login alerts, new-device alerts, transaction alerts, and password-change alerts where the account offers them. Check that recovery email addresses and phone numbers are yours. -
If personal information was exposed, consider credit protections.
A credit freeze can make it harder for someone to open new credit in your name; to place one, contact each of the three nationwide credit bureaus. An initial fraud alert tells businesses to take extra steps before opening new credit; you can usually place one by contacting any one of the three bureaus. -
If you see signs of identity theft, use the official recovery process.
Signs can include new accounts you did not open, bills you do not recognise, debt-collection notices, tax notices, or credit-report activity that is not yours. Use IdentityTheft.gov for a recovery plan and documentation. -
Watch closely for the next few weeks.
Look for password-reset emails you did not request, new logins, new payees, unusual purchases, or mail about new accounts. If money is involved, contact the bank, card issuer, or payment provider through a verified route.
What can wait
- You don’t need to close every account today.
- You don’t need to rebuild your whole digital life right now.
- You don’t need to reply to the breach notice once you have handled account changes through verified channels.
- You don’t need to decide today whether to keep using every affected service.
Important reassurance
This is a common situation, and it does not mean every account has been taken over. Changing reused passwords, starting with email, and adding two-factor authentication reduces a major route attackers rely on.
Scope note
These are first steps only. Later decisions, such as identity-theft recovery, account disputes, credit-report corrections, or business cybersecurity help, may need specialist support.
Important note
This guide provides general information for immediate stabilisation and harm reduction. It is not legal, financial, cybersecurity, therapeutic, or other professional advice.
Additional Resources
- Consumer Advice — Have you been affected by a data breach? Read on
- Consumer Advice — Use Two-Factor Authentication To Protect Your Accounts
- Consumer Advice — Credit Freezes and Fraud Alerts
- Consumer Advice — Is a credit freeze or fraud alert right for you?
- IdentityTheft.gov — Databreach
- IdentityTheft.gov — Steps
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.