“We found your email in a breach.” Your stomach drops — then the dangerous part starts: panic-changing one password while twelve reused siblings stay live. Breach response has a correct order, and order matters more than speed. This data breach checklist gives the 7 steps in priority sequence, tested against CISA and NIST compromise guidance.
Part of the password generator guide. Generate replacements in the password generator; unique OTPs for resets via the OTP tool; fingerprint public keys with the hash generator where applicable.
The 7 steps, in order (do not skip ahead)
- Contain the breached account: change its password immediately — generated, unique, 16+ — from a clean device. If malware is suspected, clean the device first or the new secret is compromised at birth.
- Rotate every reuse: list all sites sharing the password or its pattern, change each to unique generated secrets, email and bank first. This step — not step 1 — stops the spread.
- Enable MFA everywhere it matters: authenticator app on email, bank, cloud storage and socials. Attackers holding old session tokens get locked out at next challenge.
- Kill sessions and keys: “log out all devices” on email/socials, revoke app passwords and API tokens minted under the old credential, re-issue where needed.
- Check exposure scope: breach-notification details (what fields leaked: passwords only, or IDs, cards, addresses?) set steps 6–7. Screenshot the notice for records.
- Watch money and identity: bank alerts on, statements scanned 60 days, credit freeze or fraud alert if IDs leaked. India: report at cybercrime.gov.in + 1930 helpline promptly.
- Do NOT calendar-rotate everything else: clean unique passwords stay. Mass rotation wastes the window where steps 1–6 matter and breeds weaker replacements.
Aftermath: the week after (lock in the lesson)
- Audit with a manager report: most managers flag reused/weak/compromised vault entries — clear every flag within 7 days while motivation is hot.
- Upgrade email to hardware-grade: breach survivors should move email MFA to the strongest available option (passkey or hardware key) — your inbox is the recovery path for everything.
- Document what leaked where: one note (offline) mapping breached service → data types → actions taken. Future-you triages the next notice in minutes.
- India specifics: UPI-linked email breaches deserve same-day bank notification; SIM-swap symptoms (sudden no-signal) mean call the carrier and bank immediately, then the cyber helpline.
Small-business breach drill (quarterly, 30 minutes)
Five-person shops face the same ransomware and stuffing attacks with no SOC. Quarterly drill: verify backups restore (actually restore one file), confirm MFA on email/cloud/bank for every staffer, rotate the three shared credentials (Wi-Fi, socials, vendor portals), and check haveibeenpwned-style exposure for company domains. Assign one owner per item — shared responsibility means no responsibility. Log date + findings on one page; cyber-insurance applications and client security questionnaires accept documented drills as evidence. When a real notice lands, the team runs the 7-step order above instead of improvising — drills convert panic into procedure. Cost: two working hours per quarter for the whole company.
General information only, not security advice. Generate offline, store in a manager, enable MFA on email/bank. If you lose your master password it cannot be recovered by us.