How-To

What to Do After a Data Breach: A Step-by-Step Guide

What to do after a data breach, step by step — change the exposed password, turn on 2FA, watch for scams, freeze your credit and stop the damage spreading.

By · Updated 21 July 2026 · 7 min read
Disclosure: Zen Tech Hub is reader-supported. When you buy through links on our site we may earn an affiliate commission, at no extra cost to you. As an Amazon Associate we earn from qualifying purchases. This never changes our verdicts — see our affiliate disclosure and testing methodology. Prices and availability are accurate as of the date shown and can change.
What to Do After a Data Breach: A Step-by-Step Guide

If your data was caught in a breach, act in this order: change the password on the breached account immediately (and on every other account that shared it), turn on two-factor authentication, then watch closely for scam emails and calls that will follow. If payment cards or financial details were exposed, alert your bank and consider freezing your credit. The single most urgent move is the password change, because a leaked login is the key attackers use to walk into your other accounts — and they do it within hours of a breach going public.

A breach notification is unsettling, but panic is the wrong response and so is ignoring it. Damage from a breach is largely preventable if you move quickly and methodically. Work through the steps below in order; the early ones matter most.

First, confirm the breach is real

Scammers exploit breach anxiety with fake “your account was hacked” emails designed to make you click a malicious link in a hurry. Before doing anything, verify:

  • Don’t click links in the notification email. Instead, go to the service directly by typing its address yourself and log in to check for official alerts.
  • Check independently whether your address appears in known breaches at a reputable aggregator like Have I Been Pwned (haveibeenpwned.com), which lets you search your email safely.
  • Confirm what was exposed. Legitimate breach notices state which data was involved — email only, passwords, payment cards, or ID documents. The response differs for each.

Once you’ve confirmed it’s genuine and know what leaked, proceed.

Step 1: Change the breached password immediately

This is the most time-sensitive action. Change the password on the affected account right away, using a strong, unique password you’ve never used anywhere else.

  • Make it long and random — a password manager generates and stores these for you, so you never have to remember or reuse them. See our Best Password Managers 2026: Top Picks Compared & Ranked guide.
  • Do it from a device you trust, not public Wi-Fi or a shared computer.
  • If you can no longer log in because an attacker already changed the password, use the service’s account-recovery process immediately and contact its support.

Speed matters because attackers automate this: a fresh dump of credentials gets tried against banks, email and shops within hours.

Step 2: Change that password everywhere you reused it

This is the step most people skip, and it’s where the real damage happens. Attackers take a leaked email-and-password pair and try it on dozens of other sites — a technique called credential stuffing. If you used that same password on your email, your bank, or a shopping account, every one of those is now exposed even though only one site was breached.

Go through every account that shared the breached password and change each to its own unique password. Prioritise in this order:

  1. Your primary email — it’s the reset gateway to everything else, so secure it first.
  2. Financial accounts — banking, PayPal, anything with money or cards.
  3. Accounts with stored payment details — shopping, subscriptions.
  4. Everything else.

A password manager makes this far less painful and flags reused passwords for you, so this is the moment to adopt one if you haven’t.

Step 3: Turn on two-factor authentication

Two-factor authentication (2FA) means that even if a criminal has your password, they still can’t get in without a second code. Turn it on for the breached account and, at minimum, your email and financial accounts.

  • Prefer an authenticator app (or a hardware security key) over SMS codes, which can be intercepted via SIM-swapping.
  • If your accounts already had 2FA, that likely blunted this breach — keep it on everywhere.

For a full walkthrough of how it works and how to set it up, see What Is Two-Factor Authentication (2FA)?. This one habit blocks the overwhelming majority of account takeovers.

Step 4: Watch for phishing and scams

After a breach, expect a wave of targeted scams. Criminals now know you use the breached service and may have your name, email or phone number, which makes their fakes more convincing.

  • Be suspicious of any email or text about the breach urging you to “secure your account” via a link — go to the site directly instead.
  • Watch for phone calls claiming to be the breached company, your bank, or “fraud protection.” Real institutions won’t ask for passwords, full card numbers or 2FA codes. Hang up and call back on the official number.
  • Treat unexpected attachments and “you must act now” urgency as red flags.

If the breach exposed your email or phone, this scam pressure can continue for weeks. Stay skeptical.

Step 5: If financial data was exposed, protect your money

When card numbers, bank details or government IDs were part of the breach, escalate:

  • Contact your bank or card issuer, tell them your details were in a breach, and ask them to watch for fraud or reissue the card. Report any unauthorised charge immediately.
  • Freeze your credit with the major bureaus. In the US that’s Equifax, Experian and TransUnion; in the UK, Experian, Equifax and TransUnion offer protective measures. A freeze stops criminals opening new credit in your name and is free to place and lift.
  • Monitor statements closely for months — some fraud surfaces long after the breach.
  • If your government ID or Social Security number leaked, look into an identity-theft protection service or the official identity-recovery resources for your country.

Step 6: Clean up and harden the account

Once the immediate fire is out, reduce future exposure:

  • Review account activity and active sessions on the breached service; log out unknown devices.
  • Check recovery settings — make sure the recovery email and phone are still yours and weren’t changed by an attacker.
  • Remove saved payment methods you don’t need stored.
  • Run a malware scan if you suspect your own device was the leak point rather than the company; our How to Remove Malware From Your PC or Phone guide covers this.
  • Delete accounts you no longer use — data you don’t have stored somewhere can’t be breached later.

How to reduce the damage of the next breach

Breaches are now a fact of online life, so the goal is containment rather than prevention. Three habits make any future breach a minor event:

Do those and a breach notification becomes a five-minute chore instead of a crisis.

FAQ

What is the first thing to do after a data breach?

Change the password on the breached account immediately, using a strong, unique password, and then change it on any other account where you reused it. A leaked login is what attackers use to break into your other accounts, and they act within hours — so speed on the password is the single most important response.

How do I know if my data was in a breach?

You’ll often get a notification from the affected company, but verify independently rather than clicking its links. Search your email address at a reputable checker like Have I Been Pwned (haveibeenpwned.com), and log in to the service directly to look for official alerts. The notice should also say what data was exposed.

Should I freeze my credit after a data breach?

If financial details, a Social Security number, or government ID were exposed, yes. A credit freeze stops criminals opening new accounts in your name, is free to place and lift with each major bureau, and doesn’t affect your existing accounts or credit score. For email-only breaches it’s usually unnecessary — focus on passwords and 2FA.

Can I get my leaked password back or remove it from the internet?

No — once data is in a breach dump it’s effectively public and can’t be recalled. That’s why the fix is to make the leaked password worthless by changing it everywhere you used it and turning on two-factor authentication, so the exposed credential no longer opens anything.

Why do I get more scam emails after a breach?

Because the breach handed criminals your email, name and knowledge of which services you use, making their phishing far more convincing. Expect targeted emails, texts and calls impersonating the breached company or your bank. Never act on links or urgent demands in them — go to the official site or number directly.

How can I protect myself from future breaches?

You can’t stop companies being breached, but you can make it harmless: use a unique password for every account via a password manager, turn on two-factor authentication everywhere, and adopt passkeys where they’re offered. With those in place, a single breach can never cascade into your other accounts.

Zen Tech Hub may earn a commission from links on this page, at no extra cost to you.

Related in Software, Security & AI

All Software, Security & AI →