A leaked password has been exposed in a breach or another compromise. Attackers may test stolen email-and-password combinations on other services, a technique called credential stuffing. If you reuse a password, several accounts may be at risk. Start with the security actions below, then review wider personal data exposure.
1. Check the breach
| Step | Action | Approximate time |
|---|---|---|
| 1 | Check your email address on Have I Been Pwned | One minute |
| 2 | Review the affected service, incident date and exposed data categories | One minute |
| 3 | If a password you still use may be compromised, replace it immediately | Act promptly |
An email appearing in a breach does not establish that your current password leaked. Read the incident's data categories and consider whether you have changed that password since. Do not enter credentials into an unfamiliar breach-checking website.
A free Data Knight scan combines supported known-breach checks with public-web and broker findings. It does not identify every possible breach or every leaked phone number.
See how to interpret HIBP results and checking whether your information leaked.
2. Change passwords in the right order
Prioritise an affected main email account and other sensitive accounts, then every service where you reused the compromised password. Your email often controls password recovery for other services.
- Create a unique, strong password for each service, preferably using a password manager or a long passphrase.
- Enable two-factor authentication where available, especially on email and financial accounts.
- Never reuse a password known to be compromised.
| Situation | Priority |
|---|---|
| Same password used on several sites | Replace it on every affected account |
| Password exposed in plain text | Change it immediately and enable stronger authentication |
| Old breach, password already changed | Confirm it is not reused elsewhere and review recovery details and sessions |
3. Other exposed data and GDPR rights
Breaches may expose more than passwords, including names, addresses, phone numbers, dates of birth and identifiers. Under applicable GDPR rights, you can act on information still held by legitimate controllers.
| Right | Possible use after a breach |
|---|---|
| Access, Article 15 | Find out what the affected service still holds about you |
| Erasure, Article 17 | Request deletion where the conditions apply, for example where data is no longer needed. See Article 17. |
| Rectification, Article 16 | Correct inaccurate contact details or other information |
You generally cannot retrieve every stolen copy of a leaked password. The priority is to make it unusable by changing it and securing accounts, then address unnecessary public information through the relevant sources.
4. Credential stuffing: why speed matters
Credential stuffing tests stolen login combinations across multiple websites. Reuse makes a breach of one service relevant to others.
- Use unique passwords, ideally managed securely with a password manager.
- Enable two-factor authentication where available.
- Review account sessions and recovery settings.
- Separately, reduce unnecessary information that brokers and public sites expose about you.
Advertising and browser opt-outs can support broader privacy, but they do not replace changing compromised credentials.
5. What Data Knight can help with
| Data Knight helps with | Outside its scope |
|---|---|
| Scanning covered public websites, brokers and known breaches | Recovering or erasing every password copy already stolen |
| Sending GDPR removal requests to selected eligible sites and brokers | Replacing a password manager |
| Tracking requests and relevant follow-up | Guaranteeing that no future breach will occur |
After reviewing your scan, you choose the targets and provide the required authorisation before requests are sent. Read our method and protecting yourself after breaches.
Summary
- Check the affected email and incident details through a trusted service.
- Change compromised and reused passwords promptly, then enable two-factor authentication.
- Review sessions and recovery settings on affected accounts.
- Address other exposed information through appropriate source-removal requests.
A password or email appears in a known breach? Start a free scan to review broader exposure, then act on removable sources.
See also: Check for a breach · Have I Been Pwned · Data broker removal · GDPR Article 17



