The message arrives on a Tuesday: a company you used two years ago got hacked, and your login was in the stolen data. The instinct is either to panic or to ignore it. Neither helps. What helps is a clear order of operations, so you fix the important things first and do not miss a step.

Think of this as triage. Some accounts need attention in the next hour; others can wait until the weekend. Work down this checklist in order, and you will shut the door on an attacker before they get anywhere useful.

Key takeaways

  • Order matters: secure your email first, because it can reset every other account.
  • Change the breached password, then every place you reused it.
  • Turn on two-factor authentication as you go, not later.
  • Watch for follow-up scams that use the breach as bait.

First hour: lock down the critical accounts

The first sixty minutes matter most. These moves cut off the paths an attacker would take next.

Secure your email account

Start here even if your email was not the breached account. Your inbox is the master key: whoever controls it can reset the password on almost everything else you own.

A padlock resting on a printed envelope symbolizing a secured inbox
Your email is the master key, so it gets secured before anything else.

Give your email a brand-new, long, unique password, and turn on two-factor authentication immediately. If you are not sure how, our walkthrough on password security basics covers the setup in plain steps.

Change the breached password everywhere

Change the password on the account that was actually breached. Then change it on every other site where you used the same password, because attackers will try that combination across hundreds of services.

Watch out

Do not just tweak the old password by adding a number. If “Summer2024” leaked, then “Summer2025” is the first thing an attacker tries. Make each new password genuinely different and unrelated to the old one.

Secure anything tied to money

Next, your bank, card accounts, and any service with your payment details saved. Give each a unique password and enable two-factor. If you see a charge you do not recognize, contact the bank straight away.

Same day: widen the cleanup

With the critical accounts locked, spend the rest of the day on the next tier.

Work through your other important logins: shopping sites with saved cards, cloud storage, social media, and your phone carrier account. Each gets a unique password. This is far faster with a password manager generating them for you.

If you reused passwords a lot, do not try to remember every place. Your password manager or browser can list reused passwords for you, which turns guesswork into a simple to-do list. Our reader questions on password reuse danger explain why this step catches the accounts you would otherwise forget.

Review what is connected to each account

While you are in each account’s settings, check two things beyond the password. First, look at “connected apps” or “third-party access,” since a breach is a good moment to remove anything you no longer use. Old connected services are a quiet way in.

Second, review the recovery options: the backup email and phone number on file. If an attacker had brief access, they may have added their own recovery address to let themselves back in later. Remove anything you do not recognize.

Tip

Log out of all sessions where the option exists. Most major services have a “sign out of all devices” button in security settings. This kicks out anyone already logged in with your old credentials, not just future attempts.

This week: verify and monitor

The immediate risk is handled. Now confirm nothing slipped through and set up an early warning system.

Check what else leaked

Look up all your email addresses to see the full scope of what was exposed. The free service at haveibeenpwned.com lists every known breach your address appeared in. Our step-by-step guide to checking if your password was in a breach shows exactly how to read the results.

Watch for follow-up scams

After a breach, criminals often already have your email, name, and sometimes your phone number. They use it to send convincing phishing messages that reference the breach to seem legitimate.

Treat any urgent “secure your account” message with suspicion. Never click its links; go to the site directly. Official advice on spotting these follow-up scams is available from the US Federal Trade Commission.

The cleanup at a glance

Here is the whole sequence in one place, sorted by how urgently each part needs doing.

When Action Why it is in this order
First hour Secure email, add two-factor Email can reset everything else
First hour Change breached and reused passwords Stops credential stuffing attacks
First hour Lock down money accounts Limits direct financial loss
Same day Update other important logins Closes the remaining reused passwords
This week Check breach records, watch for scams Confirms scope and catches follow-ups

If money or identity may be involved

Some breaches expose more than logins. If your Social Security number, financial details, or full identity documents leaked, take a couple of extra steps.

Consider placing a fraud alert or credit freeze with the major credit bureaus, which is free and stops new accounts being opened in your name. Watch your bank and card statements closely for a few months.

When a relative of mine had their old tax-prep account breached, the credit freeze took about fifteen minutes to set up and gave them real peace of mind. It is a small effort for a large reassurance.

Your afternoon checklist

  • Change your email password and turn on two-factor authentication.
  • Change the breached password and every account that reused it.
  • Secure your bank and any account with saved payment details.
  • Update your other important logins with unique passwords.
  • Sign out of all devices on your major accounts.
  • Look up your email on Have I Been Pwned to see the full scope.
  • Stay alert for phishing that references the breach, and never click its links.
  • Freeze your credit if financial or identity data was exposed.

A breach is not the end of the world; it is a to-do list with a deadline. Follow the order here, tackle the critical accounts first, and you will move from anxious to in control within an afternoon. That steady, unglamorous cleanup is exactly what keeps attackers empty-handed.