You cannot stop a company from being breached, but you can find out what has leaked and clean up quietly behind it. This is a short check you can run today.
See what has leaked
Go to Have I Been Pwned, a free and well-known service, and enter your email address. It tells you which known breaches your email appears in and, roughly, what kind of data was exposed. Seeing your email listed is common and not a cause for panic. It is a prompt to act.
- Change the password on any breached account that still uses an old or reused password
- Make each new password unique, ideally stored in a password manager
- Turn on two-factor authentication (a second proof of identity after your password) while you are there
Check where you are signed in
Most big accounts keep a list of active sessions, often called Where you’re signed in, Active sessions, or Devices, in the security settings. Open it and look through the devices and locations.
- Sign out of anything you do not recognise, or use « sign out of all devices ».
- If you signed out something suspicious, change that account’s password straight after.
Check connected apps
Over the years you have probably clicked « sign in with » or given some app permission to your account. Find the list, often called Connected apps, Third-party access, or Apps and websites, and remove anything you no longer use or do not recognise. Each connection is a door you left open, and closing the unused ones costs you nothing.
None of this takes long, and doing it once every few months keeps small problems from growing.