Your Password Was Leaked: What to Do Right Now (Step by Step)

Reviewed by India Varga
Your Password Leaked: padlock icon on a purple background
Updated September 2026

Change the leaked password right now, then change it on every other account where you used the same one, starting with your email. If the password was unique to the breached site, that’s a five-minute fix. If you reused it, you’ve got real work ahead, and the order you do it in matters. This guide gives you the exact sequence, explains why email comes first, and shows you how to make sure one breach can never ripple across your accounts again.

Key Takeaways

  • If the leaked password was unique to one site, change it there and you’re done. If you reused it anywhere, treat every account that shares it as exposed.
  • Change passwords in this order: breached site first, then email, then banking, then CRA My Account, then everything else. Email first because it controls password resets on almost every other account.
  • Turn on two-factor authentication (2FA) or passkeys on your email and bank accounts. A stolen password with 2FA enabled is mostly useless to an attacker.
  • Attackers don’t guess passwords manually. They use automated credential stuffing, which tests leaked email-and-password pairs across hundreds of sites in seconds. In Canada, CRA My Account has been a documented target (Office of the Privacy Commissioner).
  • Get a password manager so every account has a different random password. That turns any future breach into a one-site problem instead of an everything problem.

This guide reflects September 2026. Security best practices, tool availability, and breach timelines can change. Check each service’s current recommendations.

What Someone Actually Does With a Leaked Password

A leaked password rarely gets used by a person sitting at a keyboard guessing at your accounts. What happens instead is automated. Attackers take large lists of email-and-password pairs from old breaches and feed them into software that tries each pair on hundreds of other sites: banks, email providers, retailers, streaming services, and government portals like CRA My Account. This is called credential stuffing, and it’s the real reason a leaked password matters.

Think of the password as a key. The breach didn’t just show someone the key to one door. It handed them a copy, and now a machine is walking down the street trying that key in every door it can find. Most doors won’t open. But if you used the same key for your inbox or your bank, the machine finds that out in seconds, and it never gets tired or gives up.

This isn’t hypothetical. In 2020, credential stuffing attacks hit CRA accounts directly, with the Privacy Commissioner confirming 42,755 individual breaches tied to stolen credentials from other sites. Attackers used the access to redirect government benefit payments and file fraudulent claims.

This is why the breach itself is usually not the main danger. The breached site will typically force a password reset on its own. The danger is everywhere else that password still works.

The Real Question: Did You Reuse It?

Be honest with yourself here, because the answer changes your whole to-do list. If the leaked password was unique to that one site, change it there, turn on two-factor authentication if the site offers it, and you’re done. Five minutes. The stolen password is now a key to a lock that no longer exists.

If you reused it, even in slight variations like adding a number or an exclamation mark at the end, treat every account that shares it as exposed. Attackers know the variation tricks too, and stuffing tools test them automatically.

History shows how long these lists stay dangerous. Adobe’s October 2013 breach exposed 152,445,165 records, and it leaked password hints along with the encrypted passwords. Hints like “dog’s name” or “usual one” turned into a target list that helped attackers crack accounts for years afterward. The LinkedIn breach from May 2012 exposed 164,611,595 accounts, and Dropbox’s July 2012 breach exposed 68,648,009. Those three sets became the raw material for credential stuffing attacks that are still running today, more than a decade later. A reused password from 2012 can unlock an account you opened last month.

Was it only the password?

A password on its own is a five minute fix. Paired with your email, security questions or personal details, it enables different attacks. Tick what your breach exposed in our free data breach risk checker and see what that combination actually allows, and what to do first.

Check what your leaked data enables →

Fix It in an Afternoon: The Exact Order

Order matters more than speed. Work through this list from the top, because each step protects the ones below it.

  1. Change the password on the breached site. Make the new one long, random, and used nowhere else. This closes the original door and takes a minute or two.
  2. Change it everywhere you reused it, starting with your email account. Email first, always, for reasons covered in the next section. Then your banking and any investment accounts. Then CRA My Account, since it holds your tax history, direct deposit details, and benefit payments. Then shopping accounts with saved cards, like Amazon or anywhere with one-click checkout. Everything else can wait until last.
  3. Turn on two-factor authentication or passkeys on your email and banking. Two-factor authentication means the password alone is not enough to get in; a code or a prompt on your phone is also required. Passkeys go one better and replace the password entirely. Either one turns a stolen password from a working key into a useless piece of metal.
  4. Get a password manager so this never happens again. A password manager creates and remembers a different random password for every site, so one breach can never spill into your other accounts. Most browsers have a basic one built in, and dedicated free options exist. This is the step that turns today’s afternoon of work into a five-minute fix next time.
  5. Watch for the phishing second wave. After a breach, scammers send fake “security alert” emails pretending to be the breached company or your bank, hoping you will type your new password into their copy of the login page. Go to sites directly instead of clicking email links, and read how to tell whether a breach email is real before acting on one.
  6. Check your credit report. If the breach exposed more than just a password, pull your free credit report to make sure no one has opened accounts in your name. You can request one from Equifax and TransUnion at no cost.

Why Email Is the Account That Matters Most

It can feel strange to protect your inbox before your bank, but there’s a simple reason. Nearly every “forgot password” button on the internet sends a reset link to your email. Whoever controls the inbox can reset your passwords on banking, shopping, social media, and government portals, one by one, without ever needing the original passwords at all.

That makes your email account the master key to your digital life. If an attacker gets in, they can also read years of messages to learn where you bank, where you shop, and who you talk to, then delete the reset confirmations so you never see them. Your bank has fraud departments and call centres watching for trouble. Your inbox has only its password and whatever second factor you’ve set up. Give it the strongest, most unique password you own, and turn on two-factor authentication there before anywhere else.

When a Leaked Password Isn’t the Whole Story

Before you close the tab, check what else the same breach exposed. A password can be changed in a minute. Some other data types cannot be changed at all, and they call for different steps. If the breach included your social insurance number, read what to do when your SIN is leaked, because that involves credit monitoring and a call to Service Canada rather than a password reset. If it included payment card details, see what to do when your credit card is leaked, since the fix there runs through your card issuer. You can also report the incident to the Canadian Anti-Fraud Centre, which tracks these patterns nationally.

Not sure what a particular breach actually exposed? Our list of data breaches affecting Canadians breaks down each major incident by the exact data types involved, so you can match your response to what actually got out instead of guessing. And to find out which breaches include you in the first place, NotchUp Shield checks your email address against the verified dataset free, and keeps watching after you close this tab.

Frequently Asked Questions

Should I change my password after a data breach?

Yes, on the breached site right away, even if the company says the passwords were encrypted. Encryption slows attackers down but doesn’t always stop them, as the Adobe breach showed when password hints helped crack encrypted credentials for years. Then change it on any other site where you used the same or a similar password. If the password was unique to the breached site, changing it there is the whole job.

What is credential stuffing?

Credential stuffing is when attackers take email-and-password pairs from one breach and automatically try them on many other sites, including Canadian banks, email providers, retailers, and CRA My Account. The software can test thousands of accounts per minute. It only works when people reuse passwords, which is exactly why reuse is the real risk after a breach.

Is a leaked password dangerous if I use two-factor authentication?

Much less dangerous. With two-factor authentication on, a stolen password alone can’t open the account, because the attacker also needs the code or approval from your device. Still change the password, since attackers sometimes trick people into sharing codes through fake login pages, and a password they don’t have is one they can’t try to pair with a stolen code.

How do I know which sites I reused a password on?

Check your browser’s saved passwords list, which most browsers can sort or flag by reuse. Chrome, Safari, Edge, and Firefox all have a built-in password checkup that highlights reused and compromised entries. If you don’t have saved passwords, work from memory through the accounts that matter most: email, banking, CRA, and shopping, and assume the worst where you’re unsure.

Do I need to change my email address?

No. Your email address is public-facing information, like your street address, and it appears in many breaches without causing harm on its own. What needs protecting is access to the account behind it. A strong unique password plus two-factor authentication on your inbox does far more good than starting over with a new address ever would.

How do I check if my password was leaked in a data breach?

NotchUp Shield checks your email address against verified breach datasets for free and monitors for future breaches automatically. You can also use Have I Been Pwned, which maintains one of the largest databases of breached credentials. Both services tell you which breaches your email appeared in and what data was exposed. If your email shows up, treat any password you were using at the time of that breach as compromised.

Can someone access my bank account with a leaked password?

Only if you used the same password for your bank as for the breached site. Canadian banks use additional security layers, but credential stuffing tools try banking sites automatically alongside everything else. If your bank password matches the leaked one, change it immediately and turn on two-factor authentication. If you notice unauthorized transactions, contact your bank’s fraud department right away and report it to the Canadian Anti-Fraud Centre.

How long do leaked passwords stay dangerous?

Indefinitely. Breach data from 2012 is still circulating and still being used in credential stuffing attacks today. The Adobe breach from 2013, the LinkedIn breach from 2012, and the Dropbox breach from 2012 collectively exposed hundreds of millions of credentials that remain in active use by attackers more than a decade later. A reused password never expires from an attacker’s perspective. The only way to neutralize it is to change it everywhere it was used and switch to a password manager so you never reuse one again.


This article is for informational purposes only and does not constitute professional cybersecurity or legal advice. If you believe you’re the victim of identity theft or fraud, contact the Canadian Anti-Fraud Centre and your local police.

Related Reading

Changing passwords blind is guesswork. You can see which breaches your own email address actually appears in, free, with no account, at NotchUp Shield, and fix only what needs fixing.

Breach figures from Have I Been Pwned, licensed CC BY 4.0.

How Much Credit Card Debt Do Canadians Actually Have? (2026)

How Much Credit Card Debt Do Canadians Actually Have? (2026)

NotchUp Editorial TeamSep 8, 2026
How to Pay Off Credit Card Debt on a Low Income in Canada

How to Pay Off Credit Card Debt on a Low Income in Canada

NotchUp Editorial TeamSep 8, 2026
How Long Does It Really Take to Pay Off a Credit Card in Canada?

How Long Does It Really Take to Pay Off a Credit Card in Canada?

NotchUp Editorial TeamSep 8, 2026
India Varga, reviewer at NotchUp

Written by the NotchUp Editorial Team. Reviewed by

India Varga

Operations and Content Specialist at NotchUp

India Varga is an operations and content specialist at NotchUp with more than nine years of experience across fintech and digital operations. She reviews every article on the blog for accuracy, clarity, and relevance so Canadians can make informed borrowing decisions.

Get up to $1,500 Apply Now