What to do after a data breach

A "we've had a security incident" email is unsettling, but the actual to-do list is short. What matters is what was taken, whether you reused the password, and what turns up in your inbox over the next few weeks.

Work through the steps below. Then turn on Breach Detection so every address you own is checked against Have I Been Pwned, and re-checked weekly on a paid plan. That way you find out about the next one from us, not from a scammer.

Check my addresses

What was stolen decides what you do

Not every breach is equal. If only email addresses were taken, expect spam and phishing, but there's no password to change. If passwords were taken, even scrambled ones, treat them as known and change them, on that site and anywhere you reused them. If payment cards were taken, watch your statements and ask your bank for a new card. If it was ID documents or your home address, you're looking at fraud risk, and it's worth putting a fraud alert on your credit file.

Whatever was taken, the one thing you can count on is more spam. Stolen lists get sold and resold, and scammers use the hacked company's name to make phishing emails look real. A message that says "your account was affected, log in here to secure it" is far more likely to be the scam than the company. Go to the site directly instead of clicking.

And a bit of perspective. Most people who've used the internet for a few years show up in at least one hack. It doesn't mean your email account has been broken into. If you're worried it has, here are the signs your email has been hacked.

The checklist

Here's the order we'd do it in. The first three steps are the ones that matter, and they take about ten minutes. The help article has the same list.

  1. Change the password on the site that was hacked, or delete the account if you don't use it any more. Don't wait for the company to force a reset.
  2. Change it everywhere else you used the same password. This is the step people skip, and it's how a hacked forum turns into a hacked bank account. If you can't remember where you used it, that's your sign to start a password manager.
  3. Turn on two-factor authentication on your email account, your bank, and anything with a card saved. Even with the password, an attacker can't get past it.
  4. Be suspicious of emails that mention the hacked site. Especially ones with a login link. Go to the site yourself instead.
  5. Check for the ones you don't know about. Turn on breach detection in Leave Me Alone. Every address on your account is checked against Have I Been Pwned, and you'll see every known hack with what was taken and what to do.

On a paid plan your addresses are re-checked every week and new hacks are flagged automatically, so this checklist runs itself next time. On the free plan they're checked when you turn it on and when you add an account.

Only your email addresses are ever sent to Have I Been Pwned. Never a password, never your emails.

Turn on breach detection

The spam that comes after

The breach itself is a one-off. The spam is what lasts. Your address is now on a list that will be sold on for years, and every buyer gets a go at your inbox. That's the part Leave Me Alone was built for. The Spam Blocker learns what junk looks like and moves it out of the way as it arrives, including the phishing emails dressed up as the hacked company, without deleting anything or reporting real senders.

For the future, stop handing out your real address. A private email is a forwarding address you can use for a signup, then switch off if it starts getting spam. If the site behind it gets hacked, the address that leaks is the disposable one.

Doing it once, by hand vs monitored

Everything above you can do yourself for free. Here's what changes when it's monitored.

Doing it once, by hand Monitored with Leave Me Alone
Which addresses get checked The one you thought of Every address on your account
The next breach You find out when the spam starts Flagged automatically, re-checked weekly on a paid plan
What to change Work it out from the news Advice matched to what was stolen
Where the data comes from Have I Been Pwned Have I Been Pwned, the same data
The spam afterwards Yours to deal with Caught by the Spam Blocker

"Leave Me Alone has helped me make my inbox tidy again! An amazing product that is affordable, fast and easy."

Dominic Monn, Creator - MentorCruise

"Leave Me Alone is a life-changer that has become essential to tame my overwhelming email inbox. Goodbye to hundreds of pointless marketing emails and spam!"

Drew Fleischer

FAQ

Does a data breach mean my email has been hacked?

No. It means a company that had your details lost them. Your email account is only at risk if you used the same password for it. The signs of an account that's actually been broken into are sent mail you didn't write, forwarding rules you didn't set, and password resets you didn't ask for. More on that here.

Can you get my data removed from a breach?

No. Once data has been copied and passed around it can't be recalled, so a breach list is a record of what happened, not something anyone can delete you from. What you can do is make the stolen details useless by changing the password.

Should I change my email address?

Usually not. The address isn't the danger, a reused password is. A new address means updating every account and contact you have, and it'll end up in a breach eventually too. Change the password, turn on two-factor authentication, and use a private email for future signups so the next leak is a disposable address.

How do I get off data broker sites?

Data brokers collect your name, address, phone number, and more, then sell it to anyone who asks, and a lot of it comes from breaches. Each one has its own opt-out form, and there are hundreds. If you're in the US, our partner EasyOptOuts handles the forms for you, with a discount for Leave Me Alone subscribers.

The breach was years ago. Do I still need to do anything?

If you've changed that password since, no. If you haven't, or you're not sure, change it now. Old breaches get re-sold and passwords get re-tried for years.

What if the breach says "unconfirmed" or "spam list"?

A spam list is a leaked marketing database, so there's no password to change. Unconfirmed means Have I Been Pwned couldn't verify the hack. Change the password anyway. And if it says virus, the details were stolen by malware on a device, so scan the device first or new passwords get stolen too.

How much does it cost?

Breach detection is on every plan, including free. Free checks your addresses when you turn it on and when you add an account. Paid plans re-check every week and flag new hacks automatically.

Ten minutes now, then let us watch for the next one.

Check my addresses