What to do if…
you get notified of a data breach and you reuse that password on other accounts
Short answer
Treat that password as unsafe to reuse. Change it everywhere you used it, starting with your email account, then turn on two-step verification on your most important accounts.
Do not do these things
- Don’t click links in the breach message until you have independently opened the company’s official website or app; criminals can copy breach messages.
- Don’t reuse a slightly changed version of the old password, such as adding a number or symbol.
- Don’t start with low-risk accounts first if your email, banking, payment, phone, cloud, or work accounts used the same password.
- Don’t store the new password in notes, screenshots, or an unprotected document.
- Don’t ignore the risk because there is no suspicious activity yet; attempts to use reused passwords can happen later.
What to do now
-
Make a quick list of where you used that password.
Include accounts that used a close variation of it. If you are unsure, treat that account as if it used the same password. -
Secure your email account first.
Your email is often the reset route for other accounts. Change the email password to a strong, unique one, turn on two-step verification, and check your email filters and forwarding rules. Remove any rule you did not set. -
Change the breached account password next.
Use a completely new password that you have not used anywhere else. If the service has a page called devices, sessions, login activity, or where you’re logged in, sign out other sessions and review recent activity. -
Change the reused password on other high-risk accounts.
Do these before lower-risk accounts:- bank, credit card, PayPal, and other payment accounts
- phone network account
- Apple, Google, Microsoft, cloud storage, and password manager accounts
- work, school, or business accounts
- shopping accounts that store cards, addresses, or order history
-
Turn on two-step verification on the accounts that matter most.
Use the strongest option the service offers, but do not let choosing the perfect option delay turning it on. Save backup or recovery codes somewhere you can still access if your phone is lost. -
Set alerts where they are easy to switch on.
Enable new-login or new-device alerts on your email, banking, payment, cloud, and phone accounts where available. Confirm that the recovery email and phone number are yours and are still secure. -
Watch for signs that someone has tried to use the password.
Look for password reset emails you did not request, new logins, changed profile details, new payees, orders, or messages sent from your account. If money is involved, contact your bank or payment provider using the number in the app, on your card, or on the provider’s official website. -
If personal details were exposed too, consider identity-fraud precautions.
If the breach included details that could be used to apply for products or services in your name, Cifas Protective Registration may add extra checks. It is a paid service, can make genuine applications take slightly longer, is not credit monitoring, and does not guarantee prevention of all fraud or identity theft. -
If the organisation mishandled your personal information, use the ICO route later.
Complain to the organisation first and give it one month to respond. If you are not satisfied with the response, or it does not respond, you can raise the concern with the ICO.
What can wait
- You do not need to decide today whether to close accounts or change your email address or phone number.
- You do not need to overhaul every security setting everywhere right now.
- You do not need to reply to the breach email unless you are sure you are using the organisation’s official website or app.
- You can pause after the high-risk accounts if you are overwhelmed, then continue with lower-risk accounts when you have steadied.
Important reassurance
Reusing passwords is common, and attackers usually rely on automated attempts rather than personal attention. Securing email first, then replacing the reused password on important accounts, quickly removes the easiest route in.
Scope note
These are first steps only for the next hour or two. If you find evidence of account takeover, financial loss, identity fraud, or work-account exposure, later decisions may need help from the affected service, your bank, your employer, or a specialist adviser.
Important note
This guide provides general information for immediate stabilisation and harm reduction, not legal, financial, cybersecurity, therapeutic, or other professional advice. If you have lost money, feel unsafe, or believe identity fraud is underway, contact the relevant provider promptly.
Additional Resources
- National Cyber Security Centre — Recovering a hacked account
- National Cyber Security Centre — Hacked accounts
- Information Commissioner's Office — What steps should I take if I have experienced a data breach?
- Information Commissioner's Office — How to make a data protection complaint to an organisation
- Cifas — Protective Registration
- Cifas — Protective Registration Terms and Conditions
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.