The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →If your username and password were exposed in a data breach, change the password on the affected account, then change it anywhere else you reused it. Use the service’s official website or app—not a link in an unexpected message. After you regain control, end other sessions, secure sign-in and recovery settings, and watch for follow-on scams.
1. Change the exposed password—and every reused copy
Go directly to the affected service’s official website or open its app and change the password. Choose a strong, unique password that you have not used on another account. The Federal Trade Commission (FTC) warns that scammers use credentials stolen in data breaches to try logging in to the affected account; reused passwords can put other accounts at risk too. See the FTC’s guidance on two-factor authentication.
Make a list of other accounts that used the exposed password and change each one to a different password. Do not use the new password from the breached account elsewhere. A password manager can help you keep distinct passwords, but it is optional for completing these steps.
2. Secure the account and check for changes
If you can still sign in, use the service’s own security settings. Menu names and available controls vary by provider, so consult its official support instructions if you cannot find an option.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
- End other sessions: Sign out of all devices or sessions, especially if you see activity you do not recognize. A password change may not end an intruder’s existing session. The FTC advises signing out on all devices so other active users are kicked out; see its hacked-account advice.
- Turn on two-factor or multifactor authentication (2FA/MFA): This requires a second factor in addition to your password. CISA explains how MFA adds protection if a password is stolen. Available methods depend on the service. Options can include an authenticator app, a one-time code, or a physical security key; check what the provider supports and how you can recover access if you lose the factor. A security key must be compatible with the account.
- Review recovery and access details: Confirm that the recovery email address and phone number are yours, and review recent activity and linked devices. Remove unfamiliar devices or details using the provider’s official controls.
- Check email rules: If the affected account is an email account, inspect filters and forwarding rules for changes you did not make. An unauthorized rule can copy messages or hide account alerts, and email access may be used to reset passwords elsewhere.
3. If you cannot sign in
Start account recovery from the service’s known official website or app. Do not follow an unexpected recovery link in an email or text; navigate to the service yourself and find its published recovery process. If you regain access, work through the security checks above.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.4. Be alert for breach-related scams and other exposed data
Be cautious about unexpected messages or calls referring to the breach, asking you to click a link, disclose a code, or provide personal information. Contact the service through its official app or website instead of using contact details in a suspicious message.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If the breach notice says information beyond login credentials was exposed, follow guidance tailored to that information. In the United States, the FTC’s IdentityTheft.gov data breach resource explains next steps. Exposure of a Social Security number (SSN) calls for identity-protection steps beyond changing passwords, including checking for accounts you do not recognize. Outside the U.S., consult your country’s identity-theft or privacy regulator.
Quick Recap
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #4
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors

