Password breaches – What to do

With hundreds of millions of usernames and passwords exposed by breaches recently in the news, you may be wondering how to keep your information safe. Whether you’ve been part of a breach or not, it’s a good time to take steps to protect your usernames and passwords.

Here are some valuable reminders for everyone: 

  • Use multi-factor authentication, when it’s available. Multi-factor authentication adds another layer of protection against attacks. What’s multi-factor authentication? To log in, you must combine something you know (like a password), with an additional factor, which is usually something you have (like a code texted to a mobile phone) or something you are (like a fingerprint). More and more companies are offering it.
  • Make your password long, strong and complex. That means at least twelve characters, with three different “character classes” (uppercase, lowercase, numbers, symbols). It’s best to put non-lowercase letters in the middle of your password. Also, avoid common words, phrases or information in your passwords. And if you’re not sure if you’ve been affected by recent breaches (such as LinkedIn, Myspace and Tumblr), it’s safest to change your passwords.
  • Select security questions where only you know the answer. Don’t use questions whose answers can be found through online public records searches – like your birthplace or your mother’s maiden name. Don’t use questions with a limited number of responses that an attacker can easily guess – like the color of your first car.

If your username and password have been exposed in a breach, take these steps right away:

  • Change your password. If possible, also change your username. If you can’t login, contact the company. Ask them how you can recover or shut down the account.
  • If you use the same (or similar) password for other accounts, change them too.
  • Check your accounts. If the password and username were for a financial site – or even if a credit card number was stored on the site – look for charges you don’t recognize.

For more tips, check out the FTC’s advanced password tips and tricks and our guidance on computer security. If your personal information is misused, visit to report identity theft and get a personal recovery plan.


This FTC article explains your free annual credit reports and how to order them.

You can report identity theft and misuse of your personal information at You can get pre-filled letters and forms to send to businesses and creditors. You could contact the business or email service that gave you the accounts that have been hacked.

You may want to talk to a lawyer about your situation. To find a lawyer in your area, you could use this state-by-state list from the American Bar Association or visit this site from the State Bar Associations.

This FTC article has information about ways to block unwanted calls.

