June 27, 2026 breaches passwords 2fa habits

Your password was in a breach — here's what actually matters next

You get the notification: a company informs you that your email address and password were exposed in a data breach. Maybe the message came from the company itself. Maybe it came from a service that monitors breach lists on your behalf. Either way, the instinct is to do everything at once — change every password, cancel your credit cards, lock down every account immediately.

Most of that instinct is either misdirected or premature. There is a clear order to what actually matters after a breach notification, and the list is shorter than the panic suggests.

Step one: change the password on the breached site

Go to the specific site that was breached, log in with your current credentials, and change your password to something new. Do this before anything else.

The replacement should be long and random — something that hasn't been used anywhere else. If you use a password manager, let it generate a new one. If you're choosing manually, aim for at least 16 characters, or a phrase of four or more words chosen at random.

Some company notifications will say your password was "hashed" — stored in a protected form rather than as plain text. That's better than storing it in plain text, but the quality of that protection varies, and there's no reliable way to assess it from the outside. Changing the password closes the question.

Step two: find every other place you used that same password

This step is where the real exposure lives. Attackers who collect credentials from a breach routinely try those same username-and-password combinations on other services — email providers, banks, shopping sites, anywhere the combination might work. The technique is common and effective precisely because password reuse is widespread.

Think carefully about where else you used the exposed password. If you're not sure, searching your email inbox for "welcome to" and "verify your account" can surface accounts you've forgotten about. Any site where you used the same password should be updated now.

This can be tedious if the password was reused in many places. It is still the most meaningful thing you can do in response to a breach.

Step three: turn on two-factor authentication

While you're in the account settings for the breached site, look for a two-factor authentication option. If it's available and you haven't enabled it, turn it on. Then do the same for your email account — which, if compromised, can be used to reset passwords elsewhere — and any other accounts you consider high-stakes.

Two-factor authentication (commonly called 2FA) requires something beyond your password to log in, typically a short code generated by an app on your phone. Even if someone has your correct password, they can't log in without that second piece.

If you're given a choice between receiving codes by text message versus an authenticator app, the app is the more resistant option. SMS codes can occasionally be intercepted or redirected. That said, either form of 2FA is meaningfully better than relying on a password alone.

What doesn't belong on the list

A few common post-breach actions feel urgent but aren't.

Changing passwords at sites that weren't part of the breach is only necessary if you used the same password there — which brings you back to step two. A breach at one company doesn't expose your credentials at unrelated services.

Canceling credit cards is usually premature unless the breach specifically involved payment card data. Most credential breaches contain email addresses and passwords, not full card numbers. If the breach notification mentions financial data specifically, your card issuer will typically reach out, and their guidance is the right one to follow.

Immediately signing up for a monitoring service in the hours after a breach puts the secondary concern ahead of the primary one. Deal with the specific exposure first.

The short version

A breach notification is worth taking seriously. It is not a signal to upend your entire digital life.

Change the password at the site that was breached. Update it at every other site where you used the same password. Add a second factor to your most important accounts. That covers the meaningful response, and it's enough to work through in an afternoon.

One incident, handled clearly, is more useful than a general sense of alarm that dissipates before any of the important steps get done.

← All posts