03

What to do when your information surfaces.

A calm, ordered response is more useful than panic. Start with the accounts that can unlock everything else, then work outward.

01

Your first hour after an exposure notice

Secure the email account connected to password resets, end active sessions, and review recovery methods before changing lower-priority accounts.

Open the response checklist
Start here
  1. Secure your emailChange the password and verify recovery channels.
  2. End unknown sessionsRevoke devices and browser sessions you do not recognize.
  3. Replace reused passwordsStart with banking, work, and social accounts.
  4. Enable stronger MFAPrefer an authenticator app or security key.
Guide · 6 min

Password reset, done properly

How to prioritize reused passwords, choose unique replacements, and avoid predictable variations.

Read guidance →
Explainer · 4 min

Why MFA method matters

Understand the difference between SMS codes, authenticator apps, passkeys, and security keys.

Read guidance →
Checklist · 3 min

Recognize the follow-up phish

Exposure notices often create a second opportunity for attackers. Learn the patterns to expect.

Read guidance →

Work from the center out.

Protect the accounts that control identity and recovery before addressing less consequential services.

  • 01

    Email and identity providerReview sessions, forwarding rules, recovery addresses, and MFA methods.

  • 02

    Work and financial accountsUse official apps or saved bookmarks—never links from an exposure email.

  • 03

    Every reused passwordReplace each one with a unique value stored in a password manager.

  • 04

    Authentication methodsUpgrade important accounts to phishing-resistant MFA where available.

  • 05

    Follow-up messagesExpect urgency, impersonation, and requests to “verify” account information.