What to fix first after a breach

A breach notice tells you what leaked. It does not tell you that the leaked security answer matters more than the leaked password, or that the leaked phone number is a problem no password change will touch. Tick what was exposed and this ranks the work, with the reasoning for the order.

What this tool does, and what it will not do

Have I Been Pwned answers the first question: was my address in a breach, and which one. It does that better than we would, so we have not rebuilt it. This tool answers the second question, which almost nothing answers — given what that breach exposed, what is actually at risk now, and in what order should it be fixed.

Those are different questions. A breach notice lists what leaked. It does not tell you that the leaked security answer matters more than the leaked password, or that the leaked phone number is a problem no password change will touch.

How it decides the order

You tick what the breach exposed. Nothing you tick is a value — there is no field here for a password, an ID number or an address, because the ranking does not need one and we do not want one. From the ticks it builds an ordered list, and every entry says why it sits where it does. Three things set that order.

Whether the thing can be replaced. A password is a secret you chose, and you can choose another one in a minute. The answer to “your mother’s maiden name” is a fact about your life. You cannot change the fact, and the same answer usually sits behind the account-recovery flow at most of your other providers — so it is a back door that outlives every password you will ever set in front of it.

How much time a hash buys. A password stored as an unsalted MD5 is, for practical purposes, a password: a consumer graphics card tries billions of candidates a second, and with no salt a single pass cracks every account in the dump at once rather than one at a time. The same password behind bcrypt, scrypt or Argon2 is a different situation — the work factor is the whole point, and a long unique password behind one is not falling. Between those sit PBKDF2 and salted fast hashes, which buy hours rather than years. If the company never said which algorithm it used, assume the worst: disclosure there is usually good news, so silence is not neutral.

Which attack the thing actually enables. A leaked phone number is not a password problem. It is a SIM-swap problem — an attacker who talks your carrier into moving your number gets every SMS code and every “we have texted you a reset link” after it, and no password change touches that. The fix is a port-out PIN with the carrier and moving your second factor off SMS. A leaked government ID number is not a login problem either: it is new-account fraud, and the control is a credit freeze rather than a monitoring subscription.

Nothing leaves your browser

Every tick stays in the tab. There is no account, no upload, and no request carrying anything you selected — which is also why there is no save and no resume, so finish it in one sitting. Our analytics records that the tool was started, that it finished, and whether the result came out critical, high or moderate. It never sees what you ticked.

Start with how to check if your email was breached if you have not identified the breach yet, and passkeys vs passwords vs 2FA for what to move to once the rotation is done. This is a prioritisation aid, not legal or financial advice.