what to do after your email appears in a data breach

work from the exposed account outward. this is account cleanup, not incident response for a business or a person facing targeted abuse

1
do not use the link in a surprise text or email to reach either site
2
change the password on the affected account
go directly to the service and make the new password unique
3
replace every reused or closely related password
4
turn on multi-factor authentication
prefer an authenticator app or security key when the service supports one
5
sign out other sessions and remembered devices
6
check recovery email addresses and phone numbers
remove anything unfamiliar before relying on a password reset
7
review passkeys, app passwords, and connected applications
8
inspect email forwarding rules and filters
attackers sometimes leave a quiet copy of incoming mail after losing access
9
replace exposed payment credentials if the issuer advises it
10
watch statements and account notifications
report unfamiliar activity through the official bank or card channel
11
expect phishing that references the breached company
accurate personal details do not prove the sender is legitimate
12
save the breach notice and a record of actions taken
13
close the account if it is abandoned and deletion is available
download anything needed first, then confirm the closure by signing in again

Or start a list of your own — free, it takes a minute.