Your Password Was in a Breach: The First Hour
Chrome says it. Your iPhone says it. An email from a company you barely remember says it. The first hour after that notice decides whether this is a chore or a takeover. Here's the order to do things in.
A breach notice feels like an emergency and reads like spam, which is exactly why most people do nothing with it. The truth is in between. The company that lost your password is rarely the problem. The problem is every other place you used the same one, and the automated tools that will try it there within hours.
First: Is the Notice Real?
Breach notices are phishing bait too. A real one never needs you to click a link to “secure your account.” Close the message, open the site or app the way you normally do, and look at its security settings. Alerts from inside your browser, your phone's password settings, or your password manager (Chrome, Safari, Edge, 1Password Watchtower, Bitwarden Reports) are legitimate: they compare your saved passwords against known breach lists without sending them anywhere. You can check any email address yourself at haveibeenpwned.com, typed in by hand.
The Order Matters
Attackers don't try a leaked password on one site. They load it into a tool that tries it on hundreds, and your email account is the one they want most, because it resets everything else. So it goes first.
Change your email password first
From a device you trust. Make it new, long and unique; let a password manager generate it. If the email password was the one leaked, assume someone has already tried it.
Then the site that was breached
Even if it's an account you don't care about. It's the one attackers know is live.
Then everywhere you reused it
A password manager's report lists them for you. If you don't use one, this is the day to start; it turns a weekend of guessing into a ten-minute list.
Turn on a second factor
A passkey or an authenticator app, not a text code. With that in place, a leaked password on its own gets an attacker nowhere. See Passkeys, Explained.
Sign out everywhere
Google, Microsoft, Apple and Facebook all have a “sign out of all sessions” button under security. It ends any session an attacker already opened. Changing the password alone doesn't always do that.
Look for what they left behind
Email forwarding rules and filters. A changed recovery phone or email. Apps you didn't connect. Devices you don't recognize. A forwarding rule to an outside address is the classic sign someone was already in.
Check the money
Bank and card activity, PayPal, Venmo, Amazon orders and saved addresses. Anything that stores a card and ships things is worth thirty seconds.
Freeze your credit if the breach included your SSN or birth date
Equifax, Experian and TransUnion each take about ten minutes online, it's free, and you lift it in minutes when you need a loan. Then request an IRS Identity Protection PIN so nobody files a return as you.
What “Found on the Dark Web” Actually Means
Old breaches get repackaged and resold for years, so a dark-web alert usually points to a password you retired long ago. The test is simple: is that password, or a close variation of it, still in use anywhere? If not, you're done. If so, it goes to the top of the list. Our three layers of cyber threats guide explains the bigger picture: this is the mass-volume layer, not someone targeting you, which is exactly why unique passwords beat every other fix.
What Not to Bother With
- Changing every password you own tonight. Only the breached one and its reuses; the manager will flag the rest over time.
- Paying for identity monitoring before freezing your credit. The freeze is free and does more.
- Following the breach email's “verify your identity” link. See above.
- Buying a new computer. A breach at a company you use says nothing about your machine.
If It's a Work Account
One reused password on a Microsoft 365 or Google Workspace account is how most small-business breaches start, and the attacker's first move is usually a quiet forwarding rule, not a ransom note. Tell whoever handles your IT the same hour. On our Advanced plan, dark-web account monitoring flags a staff credential in a dump before someone uses it, and identity threat detection catches the sign-in if they do. That's the difference between a password reset and an incident.
Quick Self-Check
| Question | If “no” or “not sure”... |
|---|---|
| Do you use a password manager, so reuse is impossible by default? | Start today |
| Does your email account have a passkey or authenticator app? | Do this first |
| Is your credit frozen at all three bureaus? | Free, ten minutes each |
| Business: would you know if a staff password showed up in a dump? | Worth a call |
Not Sure What They Touched?
We'll go through the account with you, check the rules and devices, and set up the second factor properly. Remote, usually in about an hour.
Frequently Asked Questions
Should I pay for identity theft protection?
Freeze your credit first; it's free and it actually stops new accounts being opened. Paid monitoring mostly tells you after something happened. If you want it on top of the freeze, fine, but not instead of it.
Do I really have to change every password I own?
No. Change the one that leaked and anywhere you reused it. A password manager finds the reuses for you and generates a unique replacement for each.
The breach included my Social Security number. Now what?
Freeze your credit at Equifax, Experian and TransUnion, get an IRS Identity Protection PIN, file your taxes early next year, and watch your mail for accounts you didn't open. The freeze is the part that matters.
How do I know if my company's accounts are in a breach?
Our Advanced maintenance plan monitors the deep and dark web for your organization's credentials continuously. If you're not on it, call and we'll run a one-time check with no obligation.
Is the 'password found in a data leak' alert from Chrome or my iPhone trustworthy?
Yes. Those checks run inside the browser or device against known breach lists, and they never send your actual password anywhere. Act on them the same day.
More Guides
The sign-in method a fake login page can't steal, and how to set one up.
Why a stolen password is now the most common way in, and how it's stopped.
The five tells, the scams hitting Tampa Bay right now, and what to do if you already clicked.
The three layers of cyber threats, and which one is actually your problem.
California's DROP tool plus the DIY opt-out list for every other state.
Lock it, protect the accounts on it, and suspend the line, in the right order.
📞 727-579-4335 · ✉️ support@baygeeks.com · Privacy Policy · Terms of Service
