What to Do If One of Your Passwords Has Been Stolen
Changing the stolen password is only the first step — the one most people skip is changing it everywhere else they reused it, and checking for hidden email forwarding rules.
Act in this order, without delay
- Change the password immediately on the affected service — do it from a different device if you suspect the current one may be compromised.
- Change that same password everywhere else you reused it — this is the step most people skip, and the most important one if you were reusing passwords.
- Turn on two-step verification if you did not have it yet, on that account and on the most important ones you use.
- Review the account's recent activity — look for sign-ins or changes you do not recognise.
Check your email forwarding rules if the affected account is your email — some attacks set up a hidden automatic forward so the attacker keeps seeing your messages even after you change the main password.
If the affected account is your main email
This is especially critical, because it is usually the recovery route for your other accounts — if you have to choose where to start, secure this one first.
Tip: once the immediate situation is under control, consider moving all your passwords to a password manager with a unique password per site — it drastically reduces the impact if this ever happens again.
Frequently asked questions
Why is it so important to change the password on other sites too?
Because if you reused the stolen password on several sites, every one of them is equally exposed — it is the step most people skip after a password theft.
Why should I check my email forwarding rules?
Some attacks set up a hidden automatic forward so the attacker keeps receiving your messages even after you change the main password — a form of persistent access many people overlook.