Breach · guides

Data breach: what to close first, and in what order

By Alberto Gulotta · Updated · 5 min read

This is the entrance to the data breach tower. Almost everybody arrives here on the same day: a company has written to say something happened, or a browser has put a warning next to a password, and the question is how worried to be.

The honest headline is that this is survivable and mostly free to fix, and that the order you do things in matters far more than which product you buy. Check what is actually out, understand what that particular kind of data is worth to somebody, close the doors that are open, and only then decide whether any monitoring service is worth a subscription — a decision that has published numbers behind it, on whether identity theft protection is worth it.

The second thing worth knowing is that a breach is rarely about you. Your details were sitting in a company’s database alongside several million other people’s, and that company was the target. Nothing you did caused it and no password of yours was guessed. What you control is entirely on the other side of the event: whether the password that leaked was used anywhere else, and how fast you close that off.

What this building will hold is mostly still to be written, so this page names what already exists for the first hour. The password that leaked is the first door to close, and the password manager pages are where that is done; if somebody is already using the details, the deadlines are on the identity theft page; and if the message that told you about the breach might itself be fake, how to tell a phishing message from a real one comes before anything else. And if what arrives instead is a verification code you never asked for, from digits rather than a name, that is what somebody trying a leaked login looks like from the receiving end.

One more thing before you climb, because it changes how the whole building reads. There is a difference between your data being in a breach and your accounts being at risk, and the two are constantly presented as the same thing by companies with something to sell. Being in a breach is nearly universal: if you have used the internet for a decade, you are in several, and finding out is useful rather than alarming. Being at risk is a narrower and more answerable question — it depends on what leaked, whether that password protects anything else, and whether a second factor stands behind it. This building exists to move you from the first question to the second as quickly as possible, because the second is the one you can actually do something about.

Where to start

Five questions that already have a page on this island. If you only have five minutes, take the first and then the second.

“What do I do right now?”
Close the reused password first, with Password manager, and the second factor
“Somebody is already using my details.”
That is a different problem, with deadlines: Identity theft
“Was the email telling me this even real?”
How to tell is in Phishing and scam calls
“The passwords are saved on my phone and I cannot see them.”
They are there: How to see saved passwords on iPhone
“What of me is public without any breach at all?”
Start at Digital footprint

Getting back in

The two accounts everything else recovers through, and therefore the two to get back into before any of the rest. Written, open, and free.

Not covered here. It will not frighten you into a subscription. Fear is the entire marketing engine of this category, and most of what those services do — telling you that you appear in a leak — is available free and takes thirty seconds. What is written here says clearly which parts are genuinely worth money and for whom.

It will not tell you to change every password you own every few months. That advice makes passwords weaker rather than stronger, and the standards bodies dropped it deliberately; what replaced it is on the password pages.

And it will not pretend a breach can be undone. Once data is out it is out, copies exist, and no service can retrieve them. What can be changed is what that data still unlocks, which is almost always more than it looks and entirely within your control.

A note on sourcing, because this subject is full of confident numbers with no origin. Where a page here says what a checking service does with your address, that is quoted from the service’s own documentation with the date we read it. Where it describes what a company owes you after losing your data, it points at the regulation rather than paraphrasing it. And where the honest answer is that nobody knows — how many copies of a given dump exist, for instance — it says that instead of inventing a figure. What holds instead is simple: nearly every step in this tower costs nothing at all, and no floor carries an affiliate link.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 20 August 2026 · last checked 10 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.