My Password Was Compromised, What Do I Do?

A compromised password gets fixed in one sitting: change your email password first, then your money accounts, then the site that leaked, and make every new password different. That's the whole plan, and below is the same plan explained slowly, with reasons.

First, take a breath, because a "password compromised" warning does not mean someone is in your accounts right now. It usually means some website you signed up for got breached, its password list ended up on the internet, and yours was on it. The warning exists so you can fix the problem before anyone uses it.

Is the warning even real?

If the warning came from your own browser or phone, yes. Google Chrome checks your saved passwords against known breach lists and shows a "change your compromised password" alert, and iPhones do the same thing, so "This password has appeared in a data leak" comes from Apple's own Passwords app rather than a scammer. Both companies do the check without exposing your actual passwords, so these warnings are legitimate and worth acting on.

If the warning came in an email with a handy button to "secure your account," slow down, because that is the classic phishing pattern. Don't click the button. Go to the website yourself by typing its address, and change the password there. Everything below assumes you're doing it that way.

Step 1: Change your email password first

Start with your email rather than the account that leaked. This surprises people, so here's the reason: every "Forgot password?" link on the internet sends a reset to your email, which means whoever controls your inbox can take over almost everything else you own. Your email password controls the resets for all your other accounts, so it gets changed first, even if it wasn't the one in the breach. If it happens to be the same password as the leaked one, you now know why we started here.

Step 2: Then anything that touches money

Change your bank, credit cards, PayPal, Venmo, Amazon, and anything else with a stored card or a balance next. While you're logged in, glance at the recent activity, and if you see charges or transfers you didn't make, call that company today rather than this weekend.

Step 3: Now the account that actually leaked

Change the password on the site the warning was about, and change it even if that site feels unimportant, such as an old forum. Criminals take leaked email-and-password pairs and try them on hundreds of other sites automatically, so a leak from an account you don't care about gets used to attack the accounts you do care about.

Step 4: Make every new password different

This is the step that actually ends the problem. If your new passwords are all the old one plus an exclamation point, the same thing will happen again, because a breach at any one site will still expose the pattern you use everywhere. A long, unique password for each account is stronger than a clever one you reuse. If you used the leaked password on other sites too, change it there as well. We wrote a realistic way to stop reusing passwords without changing 200 accounts in one night: how to actually stop reusing passwords.

Step 5: Turn on two-factor authentication

Turn it on for your email and bank at minimum. Two-factor (also called 2FA or two-step verification) means a stolen password alone isn't enough to log in, because the thief also needs the code from your phone. It's in the security settings of nearly every major site, it takes about two minutes each, and it's the single biggest upgrade on this page.

Step 6: Check how big the damage is

Go to haveibeenpwned.com, the free breach-checking site the security world actually uses, and enter your email address. It shows every known breach your address appears in, so you know which other accounts to fix, and it can notify you if you show up in a future one. We walk through it here: how to check if your password leaked.

Step 7: Expect the follow-up scams

After a breach, the leaked data gets used to write convincing fake emails about suspicious activity on your account, identity verification, or a held package. The senders will know your name and which sites you use, because that's what leaked. One rule protects you from all of them: never log in through a link someone sent you. Type the address yourself, and if a real problem exists, it will still be there when you log in normally.

That's it

Email, money, the breached site, unique passwords, 2FA, a breach check, and healthy suspicion of your inbox for a few weeks. It's about an hour of work, and most of that is waiting for reset emails.

One last honest note from the two of us who built this site. Almost every time this happens to someone, the real cause was one password reused across many sites, because nobody can memorize 60 unique ones. That's the problem we started NuLenke to fix. We make Lomenett, a small offline gadget we call a password typer, and it keeps your logins in your pocket and types them for you, with no app and no cloud account to breach. It exists for people who never want to do today's cleanup again, but either way, finish the steps above first, because they're the part that matters today.