What steps should I take after a data breach with reused passwords?
#1
I just got a notification that my password was in a data breach from a site I haven't used in years. I changed it there, but I’m worried because I know I reused that same password on a couple of other, more important accounts a long time ago. I'm not sure if I should just change those now or if there's something more I need to do since that old credential is already out there.
Reply
#2
That alert hits hard. I had something similar a while back. I changed the breached site and then started rotating all my major logins. I ended up using a password manager and generating random, unique credentials for each account. I also turned on two factor authentication wherever possible. It felt like a lot at first, but I slept better after a day or two.
Reply
#3
I moved fast on enabling 2FA for the big ones, then I went through a list of sites I’ve used with that same credential and swapped them one by one. It took a weekend, but I could tell the heat died down after a while.
Reply
#4
Maybe the bigger issue isn't that single leak, but whether those accounts still matter as much as we think. I keep circling back to the idea that I may be overreacting about sites I barely used years ago.
Reply
#5
I tried to do a sweep but hit snags with some sites' reset flows and I worried about getting locked out. So I paused, then started again later with a calmer plan. Not done yet.
Reply


[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Forum Jump: