Here’s a statistic that should be shocking but isn’t anymore: billions of account credentials from thousands of company breaches circulate freely online. Statistically, if you’ve used the internet for more than a few years, some of your data is in that pile. The good news: checking takes two minutes, and the cleanup — done right — takes one evening.
Step 1: Check yourself (two minutes, free)
Have I Been Pwned (haveibeenpwned.com) is the gold standard — a free, trusted service run by a respected security researcher that indexes billions of breached records. Enter your email address and it lists every known breach containing it, what was exposed (passwords? phone numbers? addresses?), and when.
Also worth checking: your password manager’s built-in breach monitor (Google Password Manager, Apple’s Passwords app, Bitwarden and others flag compromised passwords automatically), and your email provider’s security dashboard. Firefox Monitor offers ongoing alerts for future breaches — sign up once, get emailed if you appear in a new one.
A quick reassurance: entering your email on Have I Been Pwned is safe and doesn’t expose you further. Do be wary of random “breach checker” sites you’ve never heard of — some are data harvesters wearing a security costume. Stick to the known names above.
Step 2: Read the results calmly
Finding yourself in five old breaches is normal, not an emergency. What matters is what leaked:
- Password exposed → the account itself is at risk, plus every other account where you reused that password (this is the real danger).
- Email + phone only → expect more phishing and spam; your accounts aren’t directly compromised.
- Financial or ID data → higher alert; monitoring and freezes become relevant (below).
Step 3: The cleanup, in priority order
- Change passwords on breached accounts — and everywhere you reused them. Attackers take leaked email-password pairs and try them on every major site (“credential stuffing”). Password reuse is what turns one old forum breach into a hijacked email account. Make each new password unique.
- Install a password manager tonight. This is the structural fix. It generates and remembers a unique strong password per site, so any future breach is contained to one account. Free options like Bitwarden are excellent; the built-in Apple/Google managers are fine too. The best one is whichever you’ll actually use.
- Turn on two-factor authentication (2FA) on your important accounts. Email first — it’s the master key that resets everything else — then banking, and your main social accounts. App-based codes or passkeys beat SMS, but any 2FA massively beats none. With 2FA on, even a leaked password usually isn’t enough to get in.
- Secure the email account itself. Check its recovery phone/email are yours and current, review “connected devices/sessions,” and sign out anything unfamiliar.
- For financial or identity data leaks: watch statements closely, enable transaction alerts, and consider the protections available in your country — card replacement is quick and free-ish; many banks let you freeze/unfreeze cards in-app instantly.
Step 4: Recognize the aftermath scams
Post-breach, criminals run a nasty second act: emails pretending to be the breached company, urging you to “secure your account” via their handy link. Never secure an account through an emailed link — go to the site directly yourself. Also expect “we have your password: [your real old password]” extortion emails; they’re mass-produced from the leak and safe to delete.
The mindset
You can’t prevent companies from being breached — that part was never in your control. What you can control is the blast radius: unique passwords mean one breach compromises one account; 2FA means even that account holds the door. Check yourself today, spend one evening on the list above, and future breach headlines become mildly annoying news instead of personal emergencies.