A short guide to the exact steps to take, based on what kind of information was exposed.
You got a notification because some of your information showed up in a data breach. That doesn’t mean something is currently happening to your accounts, it means the information is out there and it’s worth taking a few steps to stay ahead of it.
Find the section below that matches what was exposed and follow those steps. It shouldn’t take more than a few minutes for most situations.
Just Your Password Was Exposed
This means your email and password showed up together, but nothing else — no Social Security number, no financial information.
What to do:
Change your password on that service right away.
Set up a passkey if the service offers one. A passkey is a login method tied to your device (like your fingerprint or face unlock) instead of a password. There’s nothing for a hacker to steal or trick you into typing, since there’s no password involved at all. It’s the strongest option available, better than a password plus a code. If passkeys aren’t offered, turn on two-factor authentication (preferably through an app like Google Authenticator, rather than by text message).
If you’ve used that same password anywhere else, change it there too — that’s usually the biggest risk.
Consider a password manager so you’re not reusing passwords going forward.
Your Password Was Exposed Along With Other Account Details
This means your password leaked along with things like a phone number, username, or security question answers.
What to do:
Change your password immediately.
Set up a passkey if it’s available, or two-factor authentication if not (see explanation above).
Update your security questions and recovery phone/email on that account.
Watch for password-reset emails or texts you didn’t ask for — that’s a sign someone’s trying to get in.
Your Email Account Itself Was Exposed
This is different from a random service being breached: this means your actual inbox email address and password (Gmail, Outlook, etc.) were exposed together. Your email is the master key to most of your other accounts, since it’s usually where password reset links get sent. Treat this one as urgent.
What to do right away:
Force a sign-out of all active sessions and devices first (Gmail and Outlook both have this option in security settings). Do this before changing your password, so an attacker who’s already logged in gets kicked out immediately rather than staying signed in through the password change.
Then change your email password.
Set up a passkey on your email account if your provider offers it (Gmail and Outlook both do) — this is the single most valuable place to use one, since it protects the account that protects everything else. More on passkeys here.
Check your mail settings for any forwarding rules or filters you didn’t create. Attackers sometimes quietly forward your mail to themselves even after you’ve changed your password.
Look at your recent sign-in activity for any devices or locations you don’t recognize.
Think about which of your other accounts (banking, medical, shopping) use this email for password resets, and consider adding a passkey or MFA to the most important ones.
Your Financial Information Was Exposed
This means a credit card number, bank account, or similar financial detail was part of the breach.
What to do:
Call your bank or card issuer and ask for a replacement card or account number.
Look through your recent statements for anything you don’t recognize.
Consider a fraud alert with one credit bureau (it automatically applies to all three). Links below.
If you spot fraudulent charges already, file a report at IdentityTheft.gov.
Your Social Security Number, Date of Birth, or Address Was Exposed
This is the most serious type of exposure, since this information can be used to open new accounts or credit in your name. It’s worth taking all of the steps below, ideally today.
What to do:
Freeze your credit with the three major bureaus — Equifax, Experian, and TransUnion — plus Innovis, a fourth, lesser-known bureau (links below). Innovis doesn’t issue credit scores and most people haven’t heard of it, but some lenders (especially auto loans and rent-to-own) check it, and it holds data the other three don’t, like rental and utility payment history. It’s free, doesn’t affect your credit score, and takes about 10-15 minutes per bureau. This is the single most effective thing you can do — it blocks anyone, including you, from opening new credit until you lift the freeze.
If you’d rather not freeze (for example, if you’re about to apply for a loan), a fraud alert with one of the three major bureaus is a lighter option — it lasts a year and automatically applies to the other two. Note that Innovis isn’t part of that automatic notification, so it needs to be handled separately if you want it covered too.
Pull your free credit report at AnnualCreditReport.com and check for any accounts or inquiries you don’t recognize.
Get a free IRS Identity Protection PIN (link below). This is easy to overlook: it stops someone from filing a fake tax return using your Social Security number, which a credit freeze doesn’t cover.
Check your earnings record at ssa.gov/myaccount to make sure there’s no work history on there that isn’t yours.
Keep an eye out for warning signs: calls about accounts you didn’t open, unexpected bills, or your tax return getting rejected because one was already filed in your name.
For a deeper walkthrough of identity theft protection, see this article.
None of these steps require any special expertise, and most take just a few minutes. If anything about your specific situation feels unclear, your IT provider can help walk through it with you.
Latest Blogs
Stay sharp with the latest security insights
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.