Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If your email address appears in a dark-web breach alert, that does not prove anyone has signed in to your account. If a password appears, change it immediately anywhere you used it, then secure your email and other important accounts. Verify alerts through the service’s official app or website, not through a link in an unexpected message.

First, verify the alert safely

A breach alert is evidence that information may have been exposed; it is not evidence that an attacker successfully accessed an account. Open the account provider’s known app or type its official website address yourself. Do not use a link or phone number in an unexpected message claiming to fix the problem. Microsoft advises pausing before acting on suspicious messages, especially those urging you to click, open an attachment, or call a number (Microsoft’s phishing guidance).

A breach lookup can tell you whether an address appears in breach data known to that service. Have I Been Pwned offers an email search (Have I Been Pwned), but a result does not tell you whether an account is currently accessible to someone else. A clean result cannot prove that no exposure exists.

If only your email address was exposed

You usually do not need to abandon or change an email address just because it appeared in a breach. An address is often an account identifier, so criminals may use it to attempt sign-ins, send phishing messages, impersonate you, or send spam. Check the accounts where you use it as a login; make sure each has a unique password and enable multi-factor authentication (MFA) where available. Be alert for unexpected password-reset requests and login notifications. Microsoft explains the risks of exposed email addresses and recommends checking accounts, changing weak or reused passwords, and enabling MFA (Microsoft’s guidance on exposed email addresses).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

If a password was exposed, change every reused copy

Change the password promptly on the service involved and on every other account where you used the same password or a close variation. Give priority to your primary email account, since access to its inbox may let someone reset passwords for other services. Use a different, strong password for every account. The Federal Trade Commission (FTC) recommends password-management software as one way to create and keep track of strong passwords (FTC advice on protecting personal information).

A password manager can help you maintain unique credentials, but it does not secure an account whose password has already been exposed; change that password and review the account’s access separately.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

If malware may be involved

If you suspect the device you use to sign in has malware, follow trusted security guidance and your account provider’s instructions. Microsoft’s compromised-account guidance recommends running a full, up-to-date scan before changing the password in the specific case of a potentially compromised Microsoft account (Microsoft’s compromised-account guide). That vendor-specific step is not a universal prerequisite for responding to every breach alert.

Secure your email account and remove unfamiliar access

If you see unfamiliar activity or think someone signed in, set a unique password, enable MFA, and review the account’s access and security settings. Check recent security events and signed-in devices; confirm recovery phone numbers and email addresses belong to you; and remove unfamiliar connected apps. For email, inspect forwarding rules and filters for anything you did not create—these settings can divert or hide messages even after a password change. Google’s compromised-account guidance covers reviewing security events, devices, recovery details, connected apps, and Gmail forwarding and filters (Google Account Help: Secure a hacked or compromised Google Account).

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

If you cannot sign in, or someone changed your recovery details, use the provider’s official recovery process rather than a third-party recovery offer. The FTC advises following the provider’s instructions when you cannot access an account (FTC advice on protecting personal information); Google and Microsoft also provide account-recovery guidance (Google; Microsoft).

Choose MFA you can use and recover

Enable MFA wherever the service offers it. When choosing among methods, consider whether the account supports the option, whether your devices are compatible, how resistant it is to phishing, and whether you can keep a backup recovery method. Google lists a security key as one possible second factor and says of its 2-Step Verification: “That way, if your password is stolen, your account is still secure.” That statement describes Google’s feature, not a guarantee against every threat (Google Account Help: Turn on 2-Step Verification).

For services and devices that support it, FIDO/WebAuthn security keys are a phishing-resistant option. CISA describes FIDO/WebAuthn as the only widely available phishing-resistant authentication method (CISA guidance on implementing phishing-resistant MFA). Check compatibility before relying on a key, and keep an account recovery option. A key does not replace changing an exposed password or reviewing account access.

Microsoft says MFA defeats 99% of the password attacks it sees; that figure is specific to Microsoft’s observed attacks and is not a universal effectiveness guarantee (Microsoft: What is multifactor authentication?).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Watch for financial or identity misuse

Look for messages you did not send, missing email, unfamiliar account changes, unexpected transactions, or signs that someone used your identity. If financial accounts or payment details may be involved, contact the relevant bank promptly. Google advises contacting a bank or local authorities when saved banking, tax, passport, or identity information may have been affected (Google Account Help: Secure a hacked or compromised Google Account). For suspected identity theft, use the relevant official reporting channel in your location.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.