Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should I do after a data breach? First, verify the notice using the organization’s official website or app, then visit IdentityTheft.gov/databreach for steps tailored to the information exposed. For an account you can still access, change its password to a strong, unique one, sign out of other sessions, enable two-factor authentication if available, and check its recovery details. If you reused that password, change it on other accounts too—especially your email account.

1. Verify the breach notice and identify what was exposed

Go to the organization’s official website or app yourself and look for its breach information or contact details. Don’t use links or phone numbers in an unexpected email or text until you have verified them through a known official channel. The FTC recommends checking unexpected communications carefully because scammers may use them to solicit personal information. See the FTC’s guidance on identity theft.

Read the notice to find out whether it names login credentials, payment information, Social Security information, or other personal data. The right response depends on what was exposed; changing a password alone will not address every kind of exposure. For a U.S.-focused checklist based on the type of information involved, start at IdentityTheft.gov/databreach. The FTC’s transcript gives the same direct instruction: “Then, visit identitytheft.gov/databreach.” FTC, What To Do After a Data Breach.

2. Secure the affected account

Change the password

If you can still access the affected account, replace its password with a strong password you do not use anywhere else. If the exposed password was reused—or was only slightly different from passwords on other services—change those passwords as well. Prioritize email and accounts that hold payment information or can be used to reset other accounts. A password manager can help generate and keep track of unique passwords; the FTC and FBI discuss password managers as a way to support safer sign-ins. FTC guidance; FBI online-safety tips.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Sign out other sessions and turn on two-factor authentication

Use the account’s security settings to sign out of all devices or sessions, then enable two-factor authentication (2FA) if the service offers it. This can help prevent someone from continuing to use an existing session or signing in with a password alone. The available methods vary by service. FTC guidance identifies authenticator apps and security keys as stronger options than passcodes sent by text or email; choose a method the provider supports and that you can reliably access. FTC guidance on protecting personal information.

Check recovery details and recent activity

Confirm that the recovery email address and phone number are yours, accurate, and still under your control. Review recent sign-ins and account activity for changes or actions you do not recognize. If the account may have been used to contact other people, alert those contacts through a separate channel so they can treat unexpected messages cautiously. For compromised email or social-media accounts, follow the service’s official recovery process and the FTC’s account-recovery guidance: How To Recover Your Hacked Email or Social Media Account.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

3. Protect email and other accounts that can reset passwords

Email deserves early attention because password-reset messages for other services may arrive there. Give it a unique password, enable an available second factor, and check its recovery details and recent activity. Then review other accounts that use the exposed password or depend on the affected account for recovery. The FTC recommends securing hacked email and social-media accounts and using the provider’s recovery steps if you cannot regain access. FTC account-recovery guidance.

4. Respond to signs of identity theft or financial fraud

A breach notice alone does not prove that someone has used your information. If you find unfamiliar transactions, accounts, or other signs of misuse, contact the affected business or financial institution using contact details from its official website or app. IdentityTheft.gov advises contacting companies involved, requesting account closure or a freeze where appropriate, and changing affected logins, passwords, and PINs. Its recovery guidance also describes a free one-year fraud alert. Follow the steps that fit your circumstances at IdentityTheft.gov’s recovery steps.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

If the notice says your Social Security information was exposed, the FTC’s breach guidance recommends checking your free credit reports and looking for accounts you do not recognize. If you find unfamiliar accounts or other misuse, contact the institutions involved and use the IdentityTheft.gov recovery process. FTC, What To Do After a Data Breach; IdentityTheft.gov recovery steps.

5. If you can’t get into the account

Use the provider’s official account-recovery process, reached from its website or app—not a recovery link in a suspicious message. The service may ask you to verify your identity or use recovery information already associated with the account. For email and social-media accounts, see the FTC’s guide to recovering a hacked account. Once access is restored, change the password, review recovery details and activity, sign out other sessions, and turn on 2FA if available.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Consider optional security tools carefully

A password manager can help you create and maintain a different password for each account, but it does not replace changing passwords exposed in a breach. A FIDO2-compatible hardware security key is another possible second factor when a service supports it. Check the service’s requirements and the key’s compatibility with your devices and accounts before buying one; support is not universal. The FTC’s guidance covers password managers and security keys as security options: Protect Your Personal Information From Hackers and Scammers.

Some organizations may offer credit monitoring or other services after a breach. Treat these as an offer to evaluate, not as a substitute for securing accounts or following recovery steps relevant to the exposed data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Who this guidance applies to

The recovery resources linked here are U.S. services. If you live elsewhere, use your country’s official consumer-protection and identity-theft resources. Account-recovery procedures and available sign-in methods vary by provider and may change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.