Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assume the password is exposed. Go to the real service through its app, a saved bookmark, or an address you type yourself, and change the password immediately. Use a new password that you do not use anywhere else. Then secure any accounts where you reused the old password, sign out other sessions, turn on two-factor authentication, and check your account’s recovery details and activity.

1. Change the exposed password on the real service

Do not follow links from the suspicious website or from messages claiming to help with the incident. Open the legitimate service using its official app, a bookmark you trust, or an address you enter manually. If you are unsure of the correct address, find the service’s official site independently.

Replace the password with a new, unique one. Do not make a small variation of the exposed password, and do not reuse the replacement on another account. The FTC explains that phishing can steal login details and that attackers may try stolen username-and-password combinations elsewhere; Google advises changing compromised passwords promptly and using unique passwords. FTC guidance on protecting accounts and Google’s guidance on compromised passwords cover these risks.

2. Change every other account that used that password

If you reused the exposed password, change it on every account where it appears. Prioritize your email account, financial accounts, shopping accounts with saved payment details, and any account that can reset another account. An email inbox is especially important because password-reset links for other services often arrive there. Google’s compromised-account guidance also recommends reviewing other accounts that may share the password.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

If you have many passwords to replace, a password manager can help you create and keep distinct passwords. It is a convenience for managing the cleanup, not a substitute for changing the exposed credentials. The FTC explains why unique passwords matter in its account-protection guidance.

3. Sign out other sessions and enable two-factor authentication

In the legitimate service’s security settings, use its control to sign out of other devices or sessions. Password changes do not necessarily end every existing session, so use the service’s explicit session-management or sign-out option where available.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Then enable two-factor authentication (also called multifactor authentication) if the service offers it. This adds a second check beyond the password, which can help block access even if someone knows the exposed password. CISA explains the protection MFA provides when a password is compromised in its guidance on phishing-resistant MFA. The FTC describes text-message codes, authenticator-app codes, and security keys as options in its two-factor authentication guide.

Choosing a second factor

Use a method the service supports and make sure you understand how to recover access if you lose the device or factor. A hardware security key is an optional choice where supported. The FTC calls security keys the strongest method of two-factor authentication among the methods it discusses because they use encryption to confirm association with the account and do not use credentials hackers can steal. A key does not replace changing the exposed password or regaining control of an account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

4. Check recovery details, sign-ins, and account changes

Review the account’s recovery email address and phone number and remove anything you do not recognize. Check recent sign-ins, connected devices, and security changes for activity you did not make. If the account is email, also inspect forwarding rules and filters, plus the sent and deleted folders, for changes or messages you do not recognize.

The FTC’s account recovery guidance recommends reviewing account settings and signing out of other sessions. If you find suspicious activity, secure the account and follow the provider’s official help instructions for the specific change or alert.

5. If you cannot sign in, use official account recovery

Go to the service’s official recovery flow from its app or independently located website. Do not use a recovery link supplied by the suspicious page or an unsolicited message. Recovery steps vary by provider; follow that service’s instructions and, once access is restored, change the password, sign out other sessions, enable MFA, and recheck recovery details and activity.

If the compromised account sent suspicious messages, alert affected contacts through a separate trusted channel so they do not open links or attachments from it. The FTC’s recovery advice includes warning contacts when an account was used to send suspicious messages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Check for financial or identity exposure

If you entered financial details or sensitive personal information on the site, or stored them in the affected account, review the relevant accounts for unfamiliar activity. Contact your bank, payment provider, or other organization through a known official channel if you see suspicious transactions or believe its information was exposed. Google’s compromised-account guidance advises contacting a bank or local authorities if someone may have used bank or government information.

7. Scan your device only if malware may be involved

Entering a password on a fraudulent page does not by itself show that your device is infected. If you have signs of harmful software or another reason to suspect malware, update your antivirus software and run a scan. Google recommends those steps when harmful software may be involved in its account security guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.