You checked a breach notification site, or got a letter from a company, and there it is: your email address was part of a data breach. First, the reassuring part — this is common, it is fixable, and the next hour of focused work removes most of the risk. Here is exactly what to do, in priority order.
First, understand what actually leaked
"Your email was in a breach" can mean very different things depending on what sat next to it in the stolen database:
- Email address only. Expect more spam and phishing. Annoying, low danger.
- Email plus password (hashed or plain). Serious. Attackers will try that combination on other sites — this is called credential stuffing, and it works because people reuse passwords.
- Email plus personal data (name, phone, address, birth date). Raises the risk of targeted phishing and, in bad cases, identity fraud.
- Email plus financial data. Requires bank and card vigilance on top of everything below.
If you have not verified the exposure yourself, run your address through a breach check to see which breaches it appears in and what data classes were involved.
Step 1: Change the password on the breached account
Do this immediately, even if the company says passwords were hashed. Hashes can be cracked, especially weak ones. Make the new password long, random, and unique — a password generator plus a password manager is the standard combination for a reason.
Step 2: Hunt down every reuse of that password
This step matters more than any other. If the leaked password guarded other accounts, those accounts are now effectively public.
- List every site where you used the same or a similar password (your password manager can find duplicates; your memory works too, sites you joined around the same time are good candidates).
- Change each one to a unique password.
- Start with the highest-value targets: your primary email account, then anything with stored payment methods, then social accounts.
You can also confirm whether a specific password is circulating in cracked-password lists with a password leak check. If it appears, treat every account using it as compromised.
Step 3: Lock the doors that matter most
- Enable two-factor authentication on your primary email, bank, and any account you would genuinely miss. An authenticator app beats SMS.
- Check your email account's settings for forwarding rules, filters, or connected apps you did not create. Attackers who briefly gained access often leave these behind to keep reading your mail.
- Review recent activity where the service offers it — sign-in history, connected sessions, sent items you do not recognize.
Step 4: Raise your phishing guard
Post-breach phishing is the threat people underestimate. Attackers now know your address, often your name, and which service leaked it — enough to write convincing messages like "Following the recent incident, please verify your account."
- Never log in through a link in an email. Type the site address yourself.
- Be suspicious of urgency, threats of closure, and unexpected attachments.
- Remember that real breach notifications rarely ask you to click anything time-sensitive.
Step 5: Watch for slow-burn consequences
- Monitor bank and card statements for small "test" charges if financial data was involved.
- Where identity data leaked, consider a credit freeze or fraud alert through your local credit bureaus.
- Expect spam on the leaked address to increase permanently. Our guide on how to stop spam emails covers containment.
Step 6: Reduce the blast radius of the next breach
There will be a next breach — not necessarily of you, but of some database somewhere containing some address of yours. The goal is to make that a non-event.
- Stop using one address everywhere. Segment: one core address for critical services, aliases for real accounts, and disposable addresses for everything one-time. The full system is in our email privacy guide.
- Give throwaway forms a throwaway address. Downloads, trials, gated content, and store sign-ups can go to a MailDrop inbox that expires on its own. When that database leaks — and sign-up databases leak constantly — attackers get an address that no longer exists and was never linked to you. See what is temporary email if you have not used one before.
- Never reuse passwords again. Unique passwords turn a breach from a master-key theft into a single lost key.
- Recheck periodically. A quick pass through the breach check every few months, or after major incidents in the news, keeps you ahead of the curve.
The honest takeaway
A breach involving your email is rarely a catastrophe by itself. The catastrophe happens when a leaked password was reused, or when a phishing email lands during the confusion. Rotate the affected password, kill every reuse, turn on two-factor authentication, and stay skeptical of your inbox for a few weeks. Then take the lesson forward: the less real data you put into databases you do not control, the less the next breach can take from you.