Lumoset

“This company was hacked” doesn’t have to mean “my accounts are next.” Here’s what to actually do.

You’ve probably seen the headline before: a company you have an account with was hacked, and your email and password may have been exposed. It’s alarming, but there’s a clear, calm sequence that closes the door before anyone can walk through it.

First, find out what was actually exposed

Most companies notify affected customers directly by email. If you’re not sure, checking whether your email address has appeared in a known breach is a normal, sensible step, similar to checking your credit report.

Then, change that password everywhere you reused it

This is the step that matters most. If you used that same password anywhere else, a criminal who has it from one breach will try it on your email, your bank, and every other account, a technique called “credential stuffing.” Change it everywhere it was reused, starting with email and banking.

Turn on 2FA if it isn’t already on

A second login step means a stolen password alone isn’t enough to get into your account. See our free article, Using 2FA the Right Way, for exactly how.

Watch for the follow-up scam

After a real breach, a second wave of scam emails often follows, some pretending to be the company offering “protection,” others pretending to be a security alert. The Federal Trade Commission’s guidance is consistent: never click a link in an unexpected email about a breach. Go to the company’s real website yourself, the way you normally would.

If your Social Security number or financial details were involved

Consider a free credit freeze with the three credit bureaus (Equifax, Experian, TransUnion), which stops anyone, including you, from opening new credit until you lift it. A fraud alert is a lighter option that asks lenders to verify your identity more carefully.

The habit that prevents most of this

A unique password for every account (using a password manager, see our free article on that) means one breach can only ever expose one account, never a chain of them.

Keep learning, free

Lumoset’s free course, Email & Online Accounts ยท Level 1: Getting Started Safely, and our free guide, Scammed? Your First 48 Hours, walk through every step here in more depth. No account needed, always free, at lumoset.org.

Sources: Federal Trade Commission, What To Do After a Data Breach.