Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A breach notice does not by itself mean someone has accessed your account or taken money. First verify the notice through the organization’s official website, app, or a contact method you already trust. Then respond according to what was exposed: secure reused passwords, check accounts for signs of takeover, and contact your bank or take identity-protection steps if financial or identity data was involved.

1. Verify the breach notice safely

Go to the affected organization’s official website or app yourself, or use a phone number or other contact method you already know is genuine. Ask whether the breach occurred, what information was involved, and what the organization recommends.

Do not use links, phone numbers, attachments, or QR codes in an unexpected breach message. A fake notice can be a phishing attempt. The UK National Cyber Security Centre (NCSC) also notes that phone lines may be busy during a major breach, so checking the organization’s official website may be the easier first step.

2. Secure exposed passwords and recovery routes

Change exposed or reused passwords

If a password was exposed and you still use it, change it promptly on that service. Change it anywhere else you reused it, too: attackers may try the same credentials on other services. Give priority to email, banking, payment, and other accounts that can unlock or reset access to more important accounts.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Use a strong, unique password for each account, or a passkey if the service offers one. A password manager is an optional way to keep unique passwords manageable; you do not need to buy one to respond to a breach.

Secure email and account recovery

Email deserves particular attention because access to it can let someone request password-reset links for other accounts. Check that the recovery email addresses and phone numbers on important accounts are yours. Review active sessions, connected apps, and email forwarding rules for anything you do not recognize.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

If you think someone may have accessed an account, use its security settings to sign out other sessions and connected apps, then turn on two-step verification. If you are locked out, follow the provider’s account-recovery instructions from its official website or app.

3. Check for signs that an account was taken over

A notice that information was exposed does not prove an attacker logged in. Look for specific signs of access or misuse:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
  • Logins, login attempts, devices, or connected apps you do not recognize.
  • Changed passwords, security settings, recovery contacts, or forwarding rules.
  • Messages you did not send, or activity you cannot explain.
  • Purchases, transfers, or other transactions you did not make.

If you find unfamiliar activity, secure the affected account and contact the service through an official channel. For suspected account compromise, the FTC’s guidance on recovering hacked email or social media accounts and the NCSC’s hacked-accounts guidance provide further steps.

4. Match your response to the information exposed

If your Social Security number was exposed

For readers in the United States, the Federal Trade Commission (FTC) directs people whose Social Security number may have been exposed to IdentityTheft.gov for steps tailored to their situation. Its data-breach guidance also recommends ordering free credit reports and checking for accounts you do not recognize. A credit freeze or fraud alert can make it harder for someone to open new accounts in your name.

These are options to consider based on the data and circumstances; not every breach requires a credit freeze. Follow official agency guidance and the breach notice rather than assuming a paid service offered by the breached organization is necessary.

If bank, card, or payment information was exposed or misused

Contact your bank, card issuer, or payment provider promptly through its official app or website, or the number printed on your card. Ask whether to block or replace compromised account or card details and how to dispute any unauthorized transactions. What can be recovered depends on the payment type and institution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

If other personal information was exposed

Follow the organization’s verified notice and official guidance for the country and type of data involved. The steps for an exposed password, identity document, or payment credential are not interchangeable; choose actions that address the information actually exposed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Watch for follow-up scams

Scammers may use a public breach as context for convincing messages about password resets, compensation, device scans, or deliveries. The NCSC warns that suspicious messages can arrive some time after a breach becomes public. Treat unexpected contact cautiously, even if it refers to the organization or incident by name.

  • Do not share your password or a verification code with someone who contacts you unexpectedly.
  • Do not sign in, pay, or download software through an unsolicited link or attachment.
  • Verify claims by contacting the organization through a website, app, or number you find independently.

If you have lost money, contact your bank promptly. Reporting options depend on where you live; in the UK, readers can use Report Fraud, with separate reporting guidance for Scotland.

6. Choose stronger two-step verification for the future

After the urgent response, consider which second factor fits the accounts you use and how you will recover access if you lose it. The FTC describes security keys as the strongest two-factor method because they do not use credentials hackers can steal. A physical key is supported by some services, so check compatibility and recovery options before relying on one. An authenticator app or one-time code may be simpler to set up or available on more of your accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Option Compatibility Credential-theft resistance Recovery planning
Physical security key Supported by some services; check each account. The FTC says security keys are the strongest two-factor method because they do not use credentials hackers can steal. Check the service’s recovery methods and plan for a lost or unavailable key.
Authenticator app or one-time code May be easier to set up or more widely available; confirm the service’s options. Provides a second verification step; the FTC’s cited comparison does not rank these as stronger than security keys. Review the service’s recovery process before changing or losing access to the device used for codes.

A second factor is a preventive measure, not a replacement for changing an exposed password, checking for takeover, or responding to exposed financial or identity information.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.