Password reset, done properly
How to prioritize reused passwords, choose unique replacements, and avoid predictable variations.
Read guidance →Resources
A calm, ordered response is more useful than panic. Start with the accounts that can unlock everything else, then work outward.
Priority guide
Secure the email account connected to password resets, end active sessions, and review recovery methods before changing lower-priority accounts.
Open the response checklist →How to prioritize reused passwords, choose unique replacements, and avoid predictable variations.
Read guidance →Understand the difference between SMS codes, authenticator apps, passkeys, and security keys.
Read guidance →Exposure notices often create a second opportunity for attackers. Learn the patterns to expect.
Read guidance →Response checklist
Protect the accounts that control identity and recovery before addressing less consequential services.
Email and identity providerReview sessions, forwarding rules, recovery addresses, and MFA methods.
Work and financial accountsUse official apps or saved bookmarks—never links from an exposure email.
Every reused passwordReplace each one with a unique value stored in a password manager.
Authentication methodsUpgrade important accounts to phishing-resistant MFA where available.
Follow-up messagesExpect urgency, impersonation, and requests to “verify” account information.