Password in the leak: what to do one at a time

First confirm the information from the supplier and secure the account. Then take care of the places where the same password was used.

2 min readFor execution: 20–40 minutes; more for repeated passwords
In this guide

The leak message may refer to a password, email address or other data. It does not automatically mean that someone has already logged into the account. However, it is worth to limit the possibility of using the disclosed information quickly.

Check with source

Open the supplier's page or application regardless of the link in the received message. Seek an incident message and instructions. False leak alarms are also used for logging in.

Do not paste the actual password into an accidental “disperse checker”. Our analyzer evaluates the patterns on an example; it does not confirm that the data has been found in the leak database.

Secure affected account

Set a new unique password on the trusted device. Save it in the manager and make sure the save is for the right service. If you cannot log in, use the official recovery procedure.

View sessions, recovery data, 2FA methods and passkeys. Remove only those items you do not recognize or have been confirmed as unauthorized. Enable available 2FA and prepare a backup method. The password change itself does not remove any form of fixed access.

Change Repeated Passwords

If your password has been revealed elsewhere, each of these accounts needs a separate new password. Start with mail, password manager, finance manager and accounts through which you recover other services.

Do not fix the situation by adding a year or a sign to the old password. Password generator help create an independent string. Do not enter an account name or an old secret here.

Check the results

In the mail, review the transmission of messages, rules and application permissions. Contact the bank via its official channel at unknown payments.

Keep non-secret event information: date, supplier message and changes noted. Do not publish drop-offs with codes, payment data or active recovery links. In the coming days, watch notifications about new logins and security changes.