What to do when your email shows up in a data leak
A practical order of operations for the hour after you learn your credentials were exposed, written for individuals and small IT teams.
Finding your email address in a leak does not mean someone is inside your accounts. It means the data needed to try is now easier to get. The goal of the next hour is to make that data useless.
1. Work out what leaked
Leaks are not all equal. An email address on its own enables phishing and spam. An email plus a password hash enables offline cracking. An email plus a plaintext password, or a session token, enables login attempts right now.
If the notice you received names the service and the fields involved, start there. If it does not, assume the worst case for that service: email and password.
2. Change the password on the leaked service, then everywhere you reused it
Reuse is what turns one leak into many compromised accounts. Attackers take leaked email and password pairs and try them against email providers, banks, marketplaces, and work systems. This is called credential stuffing, and it is automated and cheap.
Change the leaked password first, then every account that shared it. Use a password manager so each new password is unique and you do not have to remember it.
3. Turn on two-factor authentication on the accounts that matter most
Start with your primary email account, because it can reset every other password. Then banking, e-wallets, social media, and work accounts. An authenticator app or a hardware key is stronger than SMS codes, but SMS is still far better than nothing.
4. Check for signs that someone already got in
Look at recent login activity on your email account. Most providers show active sessions and recent sign-in locations. Sign out of sessions you do not recognise. Check mail forwarding rules and recovery email addresses, because attackers change these to keep access after you reset your password.
5. Expect better phishing for a while
Leaked data makes phishing more convincing. A message that knows your name, your phone number, and the service you use looks legitimate. For the next few months, treat unexpected messages about that service with extra suspicion, and open the app or website yourself instead of following links.
For IT teams
If the address belongs to your organisation, treat it as an incident rather than a personal task. Force a password reset, review sign-in logs for that account across your identity provider, and check whether the same credentials appear in other leaks. If several staff addresses appear in the same leak, check what they used that service for, since it may hold work data too.
We are building Breach Check to make the first step, knowing what leaked, easier for people and organisations in Indonesia.