A company you used got breached and now there is an email about it sitting in your inbox. It is vague on purpose, it leans on the phrase “may have been affected,” and it offers you a year of free credit monitoring as though that closes the matter.
Work through it in this order. The sequence matters more than any single step, because doing the right things in the wrong order leaves a window open while you are busy with something that could have waited.
Read the notice for what actually leaked
Every decision below comes from this one detail, and it is the part people scroll past on their way to the free monitoring offer.
The notice has to tell you which categories of data were involved. It is usually a paragraph or two down, written in the flattest language the lawyers could manage. Find it and match it against this:
- Email address only. Low stakes. Expect more phishing, and expect it to name the breached company, because that is what makes it convincing.
- Email and password. Act today. This is the combination that spreads to your other accounts.
- Payment card number. Call the number on the back of the card and ask for a reissue. Do not wait to see whether a charge shows up.
- Social Security number, date of birth, driver’s license number. This is the serious tier. Freeze your credit, and keep reading.
- Security question answers. Underrated, and ugly. Your mother’s maiden name does not change after a breach, so every account where you used that answer stays exposed until you go and change it yourself.
If the notice will not say, check the company’s breach page, or look up the address you used there on Have I Been Pwned, which lists what each breach contained.
Do you still need to change the password if you have 2FA?
Yes. Change it today.
Two-factor stops someone logging in with your password alone, and it is worth having. It does not make a leaked password harmless, and there are three reasons people get caught believing it does.
It only covers the account you put it on. If the password from the breached company is also on your bank, your email, or an old shopping account you forgot about, the two-factor you enabled somewhere else does nothing for any of them. Attackers take leaked email and password pairs and run them against hundreds of sites automatically, and that is the entire attack, they are just looking for the one place you reused it.
Some two-factor holds up better than others. CISA’s guidance on phishing-resistant MFA splits these methods into tiers, with passkeys and hardware keys in the strong group and text-message codes and app codes in the weaker one. A convincing fake login page can collect your code while you are typing it and use it before it expires. If your second factor is a text message, a SIM swap defeats it, and a SIM swap happens at your phone carrier, where you have almost no control.
Sometimes nobody has to log in at all. Malware that scrapes a browser goes after the session cookie, which is what your browser holds onto after you have already passed the password and the code. Whoever gets that cookie is inside the account without touching either one.
So the password change has little to do with how well that one account is defended. The password itself is now in circulation, attached to your email address, on a list that gets copied and resold for years.
The other accounts are where this actually hurts
The breached company will recover. Your reused password is the thing that follows you around.
Sit down and think about where else that password went, and be honest, because most people have a password they have been carrying since about 2014 and reusing ever since. Change it anywhere it appears, and start with the accounts that can be used to reach everything else:
- Your primary email. This is the master key. Password resets for every other account land here, so an attacker who owns your email owns the rest by working through “forgot password” one site at a time.
- Your bank and anything holding a card on file.
- Your phone carrier account. This is the one people never think of, and it is where SIM swaps get authorized.
- Anything with your address and full name in it, which is the raw material for impersonating you to a call center.
If reconstructing that list from memory sounds unpleasant, that is the argument for a password manager. Not for the encryption, for the inventory. You cannot secure accounts you have forgotten you opened.
Take the free monitoring, with one caveat
The year of credit monitoring is free and you may as well have it, so sign up. It is worth understanding what you are getting.
Monitoring watches and tells you after something happens. It does not stop the thing from happening. A service that emails you the day a credit card is opened in your name has done its job, and you still have a fraudulent card to unwind.
The caveat is the renewal. These offers convert to a paid subscription after twelve months by default, usually somewhere between $15 and $30 a month. Put a reminder in your calendar for eleven months out, because the charge is easy to miss and hard to notice once it blends into a statement.
Freeze your credit if the breach included your SSN
A freeze does the thing monitoring cannot, which is stop a new account from being opened in the first place. A lender who cannot pull your credit report will not approve the loan, and that is the whole mechanism.
It is free, at all three bureaus, by federal law since September 2018. Anybody charging you for it is selling you something you already have. You will freeze it three separate times, once each at Equifax, Experian and TransUnion, and it takes about fifteen minutes total.
The part people get wrong: a freeze protects against new accounts. It does nothing about the accounts you already have. If your card number leaked, the freeze does not help, and the reissue does.
Unfreezing is free too, and takes a few minutes online when you actually need to apply for something. The inconvenience people imagine is worse than the real one.
Working through all of this takes an afternoon and a lot of tab-switching. The Breach Recovery Playbook is the whole sequence laid out as a checklist you can work down, with the bureau links, the carrier PIN steps, and the account-inventory worksheet already built. $11.99.
What to skip
Some of the standard advice does not earn the time.
Chasing the class action. An email about a settlement turns up sooner or later. The payouts run from a few dollars to a few hundred, it arrives two or three years later, and it has no bearing on anything you do this week. File it if it shows up, and do not organize your response around it.
Deleting the account at the breached company. Tempting and mostly symbolic. Your data was taken before you deleted anything, and the company keeps records after closure anyway. Change the password, remove any stored card, and move on.
Buying identity theft insurance in a panic. The coverage usually reimburses costs you are unlikely to incur, and the recovery help it bundles duplicates what IdentityTheft.gov gives you free. Decide about it in a calm month, not this week.
The bottom line
Read the notice for what actually leaked, change that password today even with two-factor turned on, then change it everywhere else you reused it, starting with your email. Take the free monitoring and set a calendar reminder to cancel it. Freeze your credit if a Social Security number was in there.
Ignoring the notice is the only wrong move here, and the reason it is wrong is that a leaked password does not expire. It sits on a list and gets tried against new sites for years, and the cost of closing that off is one focused afternoon.
