Compromised password: how to react
Your password appears in a data breach? Which accounts to secure first, how to choose a new password and turn on two-factor authentication.
Even if it was encrypted, a leaked password must be considered known to attackers. The main risk is reuse: bots automatically try stolen credentials on thousands of other sites.
Accounts to secure first
- Your email: it is used to reset every other account.
- Bank, tax, health insurance, mobile operator.
- Online shops where a bank card is saved.
- Social networks, often used afterwards to scam your friends and family.
- The site where the breach happened, and every site where you used the same password.
Choosing a new password
- A different password for every site: this is the most important rule.
- Long rather than complicated: a phrase of several unrelated words is both strong and memorable.
- A password manager remembers them for you and generates them randomly.
Turning on two-factor authentication
With two-factor authentication, a stolen password is no longer enough: a code sent to your phone or generated by an app is also required. Prefer an authenticator app to SMS when it is offered.
Checking that nobody got in
Review the login history and connected devices of your important accounts, check your email's automatic forwarding rules, and sign out of unknown sessions.