Finding out your data was caught in a breach is stressful, but the steps you take in the first hours and days make a real difference. Here is a clear, practical checklist for what to do after a data breach.
1. Change the affected password immediately
Start with the breached account, then change the same password anywhere else you used it. Password reuse is how one breach turns into many.
2. Turn on multi-factor authentication
MFA blocks most account-takeover attempts even when a password is known. Enable it on email, banking and any account that supports it.
3. Secure your email first
Your email is the master key to password resets. Lock it down with a strong, unique password and MFA before anything else.
4. Watch for fraud and phishing
Breached data fuels targeted scams. Be sceptical of urgent messages, monitor bank and card statements, and consider a credit freeze if financial data was exposed.
5. Find out what else is exposed
A single breach notification rarely shows the full picture. Your data may already be circulating in combolists and stealer logs. Run a free dark web check to see where your email and information appear.
6. Set up ongoing monitoring
Breaches keep happening, so one-off checks are not enough. Personal dark web monitoring alerts you the moment new exposures appear, and family plans protect everyone in your household.
Stay ahead of the next breach
You cannot prevent companies from being breached, but you can make sure stolen data is useless by acting fast and monitoring continuously. Start with a free scan today.