What to Do If Your Email is in a Data Breach
You checked HaveIBeenPwned and your email showed up. Don't panic โ here's exactly what to do, in order, from a security professional.
First: don't panic
Finding your email in a breach is alarming but extremely common. Billions of records from thousands of breaches are in circulation. The fact that your email appears in a breach database doesn't mean your accounts have been compromised โ it means attackers have your data and may try to use it. Here's how to stay ahead of them.
Step 1: Identify which breach and what was exposed
HaveIBeenPwned tells you which breach your email appeared in and what data was exposed. The severity varies enormously. An email-only breach is relatively low risk. A breach that exposed your password, SSN, or financial data requires more urgent action.
Step 2: Change the password on the breached site immediately
If the breach exposed your password โ even a hashed one โ change it on that site immediately. Use a unique, strong password generated by a password manager. Never reuse the old password anywhere.
Step 3: Check if you reused that password anywhere
This is the critical step. If you used the same password on other sites, change it everywhere. Attackers use automated tools to try breached credentials across hundreds of sites simultaneously โ a technique called credential stuffing. Your Netflix, Amazon, and bank accounts are all targets if they share a password with the breached site.
This is why a password manager is essential. If you're using unique passwords everywhere, a single breach is contained to that one site.
Step 4: Enable two-factor authentication
On the breached site and on your email account. Even if an attacker has your password, 2FA prevents them from logging in.
Step 5: Watch for phishing
After a breach, attackers often send targeted phishing emails using the information they stole. If they know your name, address, and that you're a customer of a particular company, they can craft convincing fake emails. Be skeptical of any email asking you to click a link or provide information, especially in the weeks after a breach.
Step 6: Consider a credit freeze if financial data was exposed
If the breach included your SSN or financial information, place a credit freeze at all three bureaus (Equifax, Experian, TransUnion). It's free, reversible, and prevents anyone from opening new credit accounts in your name.
The long-term fix
Breaches will keep happening. The only sustainable defense is unique passwords on every site (requires a password manager), 2FA on important accounts, and periodic checks on haveibeenpwned.com. Do these three things and a breach becomes an inconvenience rather than a crisis.