Rotate breached passwords and re-secure those accounts

    Change passwords on every breached service plus anywhere you reused them.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Once you know what leaked, the fix is straightforward: change anything reused, lock those accounts back down, and add a second factor so a stolen password alone isn't enough.

    Order of operations

      1. Email accounts first — they're the master key for password resets
      2. Banking and financial accounts next
      3. Anywhere you reused the breached password (this is usually most of your accounts)
      4. Lower-priority accounts (shopping, forums) last

    While you're in there

      • Remove old payment methods or shipping addresses you no longer use
      • Revoke 'connected apps' you don't recognise
      • Check recovery email and phone are still under your control

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Identity Recovery