What to Do After a Data Breach
You just got a notification that one of your accounts was part of a data breach. Maybe a company you used emailed you, or you spotted your details on a site like Have I Been Pwned. Don't panic — but do act quickly. The first few hours after a breach matter most.
1. Change your password immediately
Start with the compromised account. Create a brand-new, strong password — don't just add a character or two to the old one. Use our password generator to create a random 20+ character password that has no connection to anything you've used before.
2. Check for password reuse
If you used that same password anywhere else — and most of us have done this — every one of those accounts is now at risk. Change the password on every shared account. This is the moment when a password manager proves its worth: you can quickly see exactly where a password was used and rotate it everywhere.
Stay organised: A tool like NordPass can scan your saved passwords against known breaches and help you update vulnerable logins in minutes instead of hours.
3. Enable multi-factor authentication
If you haven't already, turn on 2FA for the breached account and any other important accounts. Even if your password is out there, an attacker still can't log in without the second factor.
4. Watch for phishing
After a breach, scammers often send fake emails pretending to be the affected company. They'll ask you to "verify your account" or "reset your password" by clicking a link. Always navigate to the site directly in your browser rather than clicking links in emails.
5. Monitor your accounts
Keep a close eye on your bank statements, credit reports and login activity for the next few weeks. If you see something unusual, report it immediately. Many breached accounts are used months after the leak, not days.