what to do after your email appears in a data breach

work from the exposed account outward. this is account cleanup, not incident response for a business or a person facing targeted abuse

01
do not use the link in a surprise text or email to reach either site
02
change the password on the affected account
go directly to the service and make the new password unique
03
replace every reused or closely related password
04
turn on multi-factor authentication
prefer an authenticator app or security key when the service supports one
05
sign out other sessions and remembered devices
06
check recovery email addresses and phone numbers
remove anything unfamiliar before relying on a password reset
07
review passkeys, app passwords, and connected applications
08
inspect email forwarding rules and filters
attackers sometimes leave a quiet copy of incoming mail after losing access
09
replace exposed payment credentials if the issuer advises it
10
watch statements and account notifications
report unfamiliar activity through the official bank or card channel
11
expect phishing that references the breached company
accurate personal details do not prove the sender is legitimate
12
save the breach notice and a record of actions taken
13
close the account if it is abandoned and deletion is available
download anything needed first, then confirm the closure by signing in again

Or start a list of your own. Free, it takes a minute.