First, don’t panic
An email address appearing in a breach is very common. On its own it doesn’t mean your account was accessed. What matters is what else leaked with it, especially passwords, and whether you reused those passwords elsewhere.
Do these today
- Find out what leaked. Breach notification services such as Have I Been Pwned show which breaches include your address and which kinds of data were exposed.
- Change the password on the breached service. If you used the same password anywhere else, change those too, starting with email, banking and cloud storage.
- Turn on two-factor authentication for your email account first, then for other important accounts. It stops most attacks that rely on leaked passwords.
- Use a password manager so every account gets a unique password. That turns the next breach into a one-account problem.
Watch for these scams
Attackers use breach lists to send convincing messages, because they know which services you use.
- Emails claiming to be from the breached company asking you to “verify” your account.
- Fake security alerts urging you to click a link to reset your password.
- Messages quoting an old password as “proof” they’ve hacked you, demanding payment.
Go to the company’s site directly rather than following links in the email.
Reduce the damage next time
You can’t stop companies being breached, but you can control what they hold. If a service only ever had an alias:
- The leaked address can’t be used to find your other accounts.
- Phishing sent to it can be cut off by stopping the alias.
- Credential-stuffing lists built from the breach are far less useful, because the address doesn’t match your logins elsewhere.
With Hskky Plus you can give important services their own aliases, so a breach at one company stays contained to one address. See how aliases work.
