PasswordSecure.org
Your password was leaked: what to do
The steps, in the right order and without the panic.
A password showing up in a breach does not mean you have been hacked. It means one of the services where you used it suffered a breach, and that password is now in the lists attackers work from. It is annoying, but it is fixable. Here are the steps, in the order that matters.
First of all: do not change everything at once
The classic mistake is to panic and start changing passwords at random. Work in order of risk, because time matters and not every account is worth the same.
Step 1: secure your main email
Your email account is the master key to everything else: with access to it, anyone can request a password reset on the rest of your services. If the leaked password is your email password, or something similar to it, start there, not with the site that was breached.
- Change the password to a randomly generated one.
- Turn on two-factor authentication if you had not already.
- Review the list of active sessions and sign out any you do not recognise.
- Check that no auto-forwarding rules were created without your knowledge: it is a common technique for keeping access after you change the password.
Step 2: everything else, by potential damage
After email, follow this order:
- Banking and payments (bank, PayPal, shops with a saved card).
- Accounts holding personal data (government services, health, work).
- Social media, which can be used to impersonate you to your contacts.
- Everything else.
Step 3: find everywhere else you reused it
This is the most overlooked part and the most important one. A leaked password is only dangerous where it still works. Attackers automate what is called credential stuffing: they try the leaked email-and-password combination across hundreds of popular services to see where it gets them in.
Think back and change it on every site where you used it, even years ago. If you cannot remember, search your email for welcome or sign-up messages — they tend to reveal forgotten services.
Step 4: check what moved
- Bank transactions from the last few weeks.
- Purchases or subscriptions you do not recognise.
- Messages sent from your accounts that you did not write.
- Changes to the recovery details (phone or backup email) on your important accounts.
What NOT to do
- Do not just add a number at the end. If your leaked password was
Summer2024, moving toSummer2025achieves nothing: transformation rules are the first thing attack tools try. - Do not use the same new password across several sites. You would be recreating the exact problem that brought you here.
- Do not trust emails warning you about the breach. Phishing thrives on these situations. Go to each service by typing the address yourself, never through a link in an email.
So it does not happen again
- A different password per service. It is the one measure that turns a breach into an isolated incident instead of a domino effect.
- A password manager, because nobody can memorise fifty different passwords. If you would rather remember one by heart (the manager's own, for instance), use a passphrase.
- Two-factor authentication on everything that offers it. With it enabled, a leaked password is no longer enough to get in.
Check your passwords
Our checker compares your password against billions of leaked credentials. The comparison uses k-anonymity: only the first 5 characters of its hash ever leave your browser, never the password itself.
And if you are wondering how long the new one would hold up, we have the cracking-time table.