A leak is rarely about you personally. Usually a service you signed up for gets breached and the whole database of logins and password hashes goes out. Your password sits there among a million others. What happens next — cracking, or simply replaying it on other sites — is where the difference shows between people who reused passwords and people who did not.
Order matters more than speed
The common mistake is rushing to change passwords everywhere. If your mailbox is under someone else’s control, every reset email goes to them and you hand over what is left.
Step 1. Email. Change the mailbox password and end all sessions with “sign out of all devices”. Check that the linked phone number and recovery address were not changed — those go first. Look at forwarding rules: a silent copy of all mail survives a password change.
Step 2. Second factor. Turn on login confirmation if it was off. Without it a password change protects you only until the next leak.
Step 3. The breached service. A new unique password, a check of active sessions, revocation of third-party app access.
Step 4. Everywhere the password was reused. Be honest with yourself: email, banking, shops, social media, work systems. If a password was reused even twice, treat both places as compromised.
Step 5. Money. Check transaction history and linked cards. At the slightest doubt, call the bank and reissue the card.
Checklist: go through it in order
Why adding a character does not work
The temptation is obvious: turn “Summer2026!” into “Summer2026!!” and consider it handled. Almost everyone does that, and cracking tools are built for exactly this.
They carry ready rule sets: append a symbol, swap “o” for zero, add the current year, change the first letter’s case. Those rules are applied to every leaked password automatically, thousands of variants per second. A modified password falls almost as fast as the original — because the original is already known.
Only full replacement works: a fresh random password with no connection to the old one.
How to know a leak happened
Services are supposed to notify you, but they do not always do so promptly. Checking yourself is more practical: the breach check shows whether a specific password appears in collected databases. It is built so the password never leaves your browser — only the first five characters of its hash go out.
If the password is found, it is compromised regardless of whether you remember a breach. Even one hit means the combination sits in public databases and gets tried first.
If a combination already sits in public lists, it is tried first — before any brute force. You can check yours without sending the password: only five characters of its hash leave your browser.
Making the next leak irrelevant
There will be more leaks — that is a given, not a hypothesis. The question is how many of your accounts each one touches.
A unique password per service. Then a forum breach stays a forum breach. Keeping them in your head is impossible, which is what a password manager is for.
A second factor everywhere available. It turns a stolen password from a key into a useless string.
A separate mailbox for what matters. Banking and government services on an address you never leave in shops and forums.