SecurityPasswords

Your Data Was in a Breach: What to Do Next

A breach alert lands in your inbox and your stomach drops. Take a breath. Here is a calm, ordered checklist that closes the door before one leak becomes many.

An email arrives, or a notification pops up: a service you use was breached, and your login was in it. It is an uneasy feeling, and the temptation is either to panic or to shrug and ignore it. Neither helps. A breach is not the end of the world, but the next hour matters, because attackers move fast with freshly leaked credentials.

The good news is that the response is straightforward if you take it in order. The most important idea to hold onto is this: the breach is rarely just about the one account. If you reused that password anywhere, the real exposure is everywhere you reused it. Let's work through what to do.

Key takeaways

  • Change the breached password first, then change it everywhere you reused it.
  • Reuse is what turns a single breach into a cascade through credential stuffing.
  • Turn on two-factor authentication or a passkey for the affected accounts.
  • A Security Checkup can flag reused and breached passwords privately, on your device.

Step 1: Change the exposed password now

Start with the account that was breached. Change its password immediately, and make the new one long, unique, and random rather than a small tweak of the old one. If the account offers to log out other sessions or devices, do that too, so anyone already signed in is kicked out.

Do not stop at a cosmetic change. Adding a "1" to the end of a leaked password is not a new password, it is a hint. Use a generated one you do not have to remember.

Step 2: Change that password everywhere you reused it

This is the step people skip, and it is the one that matters most. Attackers take passwords from one breach and try them, in bulk and automatically, against email providers, banks, and shopping sites. This is credential stuffing, and it works precisely because so many people reuse passwords. If the breached password also unlocked your email or your bank, those accounts are the real emergency, not the site that leaked it.

One leaked password is only as dangerous as the number of places you used it.

A password manager makes this tractable. Instead of trying to remember every site that shared a password, you can see them listed. Kinship Vault's Security Checkup groups your logins and flags reuse, so you know exactly which accounts to rotate.

Step 3: Add a second factor

Once the passwords are fixed, raise the bar so a future leak is far less useful. Turn on two-factor authentication for the affected accounts, or better, switch to a passkey where the service supports one. A passkey cannot be phished or reused from a leak, because there is no shared secret to steal. Kinship Vault can store your TOTP 2FA codes and your passkeys alongside your logins, each fill gated by Face ID or Touch ID.

Step 4: Watch the accounts, and move to unique passwords for good

For the next few weeks, keep an eye on the affected accounts and anything financial, watching for logins you do not recognize or password-reset emails you did not request. Then make the fix permanent: give every account its own generated password so no single breach can ever chain into another.

Kinship Vault's Security Checkup keeps this honest over time. It scores your logins out of 100 and flags weak, reused, old, and, if you allow the online check, breached passwords. That online check uses k-anonymity, so a full password is never sent anywhere. Only a short partial hash prefix is used, and the comparison happens without exposing what you are checking. Prefer to stay fully offline? Strict Offline mode turns the online check off while the weak, reused, and old checks keep running on device.

Watch for the follow-up scam. Breaches are often followed by phishing emails that pretend to be the breached company, urging you to "reset your password" through a link. Do not use links in these messages. Go to the site directly, or let your password manager confirm the real domain before it fills anything.

The calm version of all this

Change the exposed password, change it wherever you reused it, add a second factor, watch the accounts, and switch to unique passwords so this is a one-time chore rather than a recurring scare. A breach you respond to well is a minor event. A breach you ignore, on a password you reused, is how people lose accounts they thought were safe.

See which passwords need changing.

Kinship Vault's Security Checkup flags weak, reused, old, and breached logins, privately and on your device, on iPhone, iPad, and Mac.

Learn about Security Checkup