What to Do If You Have a Dark Web Exposure

27th July 2026 | HowTo, MSP, Platform, Technology What to Do If You Have a Dark Web Exposure

A short guide to the exact steps to take, based on what kind of information was exposed.

You got a notification because some of your information showed up in a data breach. That doesn’t mean something is currently happening to your accounts, it means the information is out there and it’s worth taking a few steps to stay ahead of it.

Find the section below that matches what was exposed and follow those steps. It shouldn’t take more than a few minutes for most situations.

Just Your Password Was Exposed

This means your email and password showed up together, but nothing else — no Social Security number, no financial information.

What to do:

  • Change your password on that service right away.
  • Set up a passkey if the service offers one. A passkey is a login method tied to your device (like your fingerprint or face unlock) instead of a password. There’s nothing for a hacker to steal or trick you into typing, since there’s no password involved at all. It’s the strongest option available, better than a password plus a code. If passkeys aren’t offered, turn on two-factor authentication (preferably through an app like Google Authenticator, rather than by text message).
  • If you’ve used that same password anywhere else, change it there too — that’s usually the biggest risk.
  • Consider a password manager so you’re not reusing passwords going forward.

Your Password Was Exposed Along With Other Account Details

This means your password leaked along with things like a phone number, username, or security question answers.

What to do:

  • Change your password immediately.
  • Set up a passkey if it’s available, or two-factor authentication if not (see explanation above).
  • Update your security questions and recovery phone/email on that account.
  • Watch for password-reset emails or texts you didn’t ask for — that’s a sign someone’s trying to get in.

Your Email Account Itself Was Exposed

This is different from a random service being breached: this means your actual inbox email address and password (Gmail, Outlook, etc.) were exposed together. Your email is the master key to most of your other accounts, since it’s usually where password reset links get sent. Treat this one as urgent.

What to do right away:

  • Force a sign-out of all active sessions and devices first (Gmail and Outlook both have this option in security settings). Do this before changing your password, so an attacker who’s already logged in gets kicked out immediately rather than staying signed in through the password change.
  • Then change your email password.
  • Set up a passkey on your email account if your provider offers it (Gmail and Outlook both do) — this is the single most valuable place to use one, since it protects the account that protects everything else. More on passkeys here.
  • Check your mail settings for any forwarding rules or filters you didn’t create. Attackers sometimes quietly forward your mail to themselves even after you’ve changed your password.
  • Look at your recent sign-in activity for any devices or locations you don’t recognize.
  • Think about which of your other accounts (banking, medical, shopping) use this email for password resets, and consider adding a passkey or MFA to the most important ones.

Your Financial Information Was Exposed

This means a credit card number, bank account, or similar financial detail was part of the breach.

What to do:

  • Call your bank or card issuer and ask for a replacement card or account number.
  • Look through your recent statements for anything you don’t recognize.
  • Consider a fraud alert with one credit bureau (it automatically applies to all three). Links below.
  • If you spot fraudulent charges already, file a report at IdentityTheft.gov.

Your Social Security Number, Date of Birth, or Address Was Exposed

This is the most serious type of exposure, since this information can be used to open new accounts or credit in your name. It’s worth taking all of the steps below, ideally today.

What to do:

  • Freeze your credit with the three major bureaus — Equifax, Experian, and TransUnion — plus Innovis, a fourth, lesser-known bureau (links below). Innovis doesn’t issue credit scores and most people haven’t heard of it, but some lenders (especially auto loans and rent-to-own) check it, and it holds data the other three don’t, like rental and utility payment history. It’s free, doesn’t affect your credit score, and takes about 10-15 minutes per bureau. This is the single most effective thing you can do — it blocks anyone, including you, from opening new credit until you lift the freeze.
  • If you’d rather not freeze (for example, if you’re about to apply for a loan), a fraud alert with one of the three major bureaus is a lighter option — it lasts a year and automatically applies to the other two. Note that Innovis isn’t part of that automatic notification, so it needs to be handled separately if you want it covered too.
  • Pull your free credit report at AnnualCreditReport.com and check for any accounts or inquiries you don’t recognize.
  • Get a free IRS Identity Protection PIN (link below). This is easy to overlook: it stops someone from filing a fake tax return using your Social Security number, which a credit freeze doesn’t cover.
  • Check your earnings record at ssa.gov/myaccount to make sure there’s no work history on there that isn’t yours.
  • Keep an eye out for warning signs: calls about accounts you didn’t open, unexpected bills, or your tax return getting rejected because one was already filed in your name.

For a deeper walkthrough of identity theft protection, see this article.

Quick Links

OrganizationPhonePurposeFreeze OnlineFraud Alert Online
Equifax1-800-931-1931Credit freeze / fraud alertFreezeFraud alert
Experian1-888-397-3742Credit freeze / fraud alertFreezeFraud alert
TransUnion1-888-909-8872Credit freeze / fraud alertFreezeFraud alert
Innovis (4th bureau)1-800-540-2505Credit freeze / fraud alert — not covered by the other threeFreezeFraud alert
IRS1-800-908-4490Identity Protection PIN (blocks fraudulent tax filings)Get IP PIN
Social Security Administration1-800-772-1213Check earnings record for unauthorized work historymy Social Security account
FTC Identity Theft ReportingFile a report if fraud has occurredidentitytheft.gov
Free Credit ReportsOfficial FTC-authorized siteannualcreditreport.com

None of these steps require any special expertise, and most take just a few minutes. If anything about your specific situation feels unclear, your IT provider can help walk through it with you.

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

What Flock Cameras Teach Every Business About Data and Trust

What Flock Cameras Teach Every Business About Data and Trust

You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...

Read more
Urgency, Emotion, Authority: How One Scammer Almost Got Inside a CPA Firm

Urgency, Emotion, Authority: How One Scammer Almost Got Inside a CPA Firm

Tax season keeps accountants busy, and it keeps scammers busy too. Early this summer, a CPA firm became the...

Read more
The Ransomware an AI Model Built Without Trying

The Ransomware an AI Model Built Without Trying

Researchers went looking for a fake photo upscaler and found something stranger: a ransomware kit an AI model...

Read more