Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Login securityPublished
When you learn your data was in a breach, do five things in order: confirm what leaked, change the affected password and any copies of it, turn on a second factor, secure your email, and stay alert for phishing that uses the leaked details. Most breaches expose an email address and a password, and the damage stays small if you act quickly.
Step 1: confirm and find out what leaked
- Have I Been Pwned. haveibeenpwned.com lists known breaches and shows which data types were included, such as passwords, phone numbers or addresses. You can sign up for notifications about future ones.
- HPI Identity Leak Checker. The Hasso Plattner Institute in Germany runs sec.hpi.de/ilc, which sends its result to the address you entered, so only the mailbox owner sees it.
- The company’s notice. If the service itself writes to you, verify it by visiting the site or app directly, never through the link in the message.
Note which data was exposed. A leaked password is a different problem from a leaked address or ID number.
Step 2: change the right passwords
- Change the password on the breached service.
- Change it everywhere else you used the same or a similar one. If you recognise this as many accounts, it is a sign to move to a password manager, which makes unique passwords effortless.
- Start with the accounts that unlock others: email, Apple or Google account, banking.
- Choose long, new passwords, following the guidance in strong passwords in 2026. You do not need to change them again on a schedule.
Step 3: add a second factor
Turn on two-factor authentication or a passkey on the breached service and on your important accounts. A stolen password is then not enough on its own. Where you can, choose an authenticator app or a security key over SMS.
Step 4: secure your email and sessions
Your inbox is where resets arrive, so check it first. Our guide to securing your email account covers forwarding rules, connected apps and recovery details. Then use “sign out of all devices” on the breached service to end any session an attacker may hold.
Step 5: protect against what comes next
| What leaked | What to do |
|---|---|
| Email address only | Expect spam and phishing. Do not open attachments, do not trust links. |
| Password | Steps 2 and 3 above, urgently. |
| Phone number | Be careful with calls and texts claiming to be your bank or a courier. Consider extra protection against SIM swapping. |
| Payment card | Contact your bank, ask for a card replacement, check statements. |
| ID, date of birth, address | Watch for misuse in your name. Consider identity-theft protection if you want help monitoring. |
| Security questions | Replace them where you can, and treat answers as passwords. |
Attackers often send follow-up emails that use real details from the leak to look convincing. A message that knows your name or a past order is not proof of honesty.
Your rights under the GDPR
Companies in the EU must notify the supervisory authority of certain breaches, generally within 72 hours of becoming aware, and tell affected individuals when the risk to them is high (Articles 33 and 34 of the GDPR). You can also ask what data a company holds about you under Article 15, and file a complaint with your national data protection authority if you think a company handled the breach badly.
What you do not need to do
- Delete your accounts in a panic. Closing an account does not remove data that already leaked.
- Pay anyone who contacts you claiming to hold your data.
- Install “cleaning” tools offered through an unsolicited email.
How to read a breach notification
A notice usually states what happened, which data was involved and what the company recommends. Look for three things: whether passwords were stored hashed or in plain text, whether payment data was included and whether the company says the breach is fixed. If a notice is vague, check the tools above for the date and the data types.
Have I Been Pwned and passwords
Have I Been Pwned also offers a way to check whether a particular password has appeared in known leaks. The lookup is designed so that your full password never leaves your device: only a short fragment of its hash is sent. Many password managers use the same service to flag weak or exposed passwords for you, which is a convenient way to find reuse without typing secrets into websites.
A simple 15-minute routine
- Search your main address in a leak checker.
- List the breaches shown and the data types for each.
- For every breach with passwords, change that password and any copy of it.
- Open the security settings of your email account and review devices, forwarding rules and recovery options.
- Turn on 2FA wherever it is still missing.
- Set a reminder to check again in a few months, or subscribe to alerts.
When to take it further
If financial data or identity documents were part of a leak, contact your bank or card issuer, and consider reporting identity misuse to the police and the relevant authority in your country. In the EU you can also raise a complaint with your national data protection authority. Keep copies of the notice and any correspondence, because they help if you need to dispute a transaction later.
Make the next breach harmless
Unique passwords, 2FA and a few minutes of monitoring turn a breach from a crisis into a notification. Subscribe to alerts so you hear about the next one early.
Frequently asked questions
How do I find out whether my data was in a breach?
Enter your email address at Have I Been Pwned, which lists known breaches, or at the HPI Identity Leak Checker of the Hasso Plattner Institute in Germany, which sends its result to your mailbox. You can also subscribe to alerts for future breaches.
Do I have to change all my passwords?
Change the password of the breached service and every account where you used the same or a similar one. Start with your email account. Accounts with unique passwords that were not part of the breach do not need to change.
Is it a scam if a company emails me about a breach?
It can be. Criminals imitate breach notices. Do not click the link. Open the service by typing its address or using its app, and look for the notice there.
Do I have any legal rights after a breach in the EU?
Under the GDPR, companies must report certain breaches to the supervisory authority and, when the risk is high, inform affected people. You can also request a copy of the data a company holds about you.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.