Skip to content
All guides

Password Security

How to Change Passwords in the Right Order After a Breach

After a breach, changing passwords randomly wastes energy and may leave the most important accounts exposed. This guide gives a practical order: email, password manager, financial accounts, cloud storage, phone carrier, work, then lower-risk services.

By the 4safer teamUpdated August 29, 20268 minutes read

Start with accounts that control other accounts

After a breach, change passwords first for your primary email, password manager, banking and payment accounts, cloud storage, phone carrier, work tools, and any account where the breached password was reused. These accounts control recovery, money, identity, or sensitive files.

Do not try to change every password at once with no order. Prioritization helps you protect the accounts that could cause the most harm if accessed.

If you know a specific password was exposed, change it everywhere it was reused. If you are unsure, focus on high-impact accounts and exposure signals.

Why order matters

Your email can reset other passwords. Your password manager stores credentials. Your bank and payment apps control money. Your cloud storage may hold documents. Your phone carrier can affect SMS codes and recovery.

Attackers often move through connected accounts. Securing the account chain matters more than fixing a low-value forum first.

NIST recommends unique passwords and password managers, while CISA recommends MFA as a key account protection.

  • Recovery control.
  • Financial impact.
  • Identity documents.
  • Stored payment methods.
  • Work access.
  • Public reputation.

Check what was actually exposed

Read breach notices carefully. Exposure involving email only is different from exposure involving passwords, phone numbers, addresses, or financial details. If the notice is suspicious, verify through the company's official website or app.

Use exposure checks only for identifiers you own or are authorized to manage. Never enter current passwords, codes, SSNs, card numbers, passport numbers, or bank details.

Priority order for most consumers

Begin with the accounts that can reset or unlock others. Then move to money, identity, communications, and stored personal data. Leave low-risk accounts for later unless they reused the exact exposed password.

For each account, create a unique password, enable MFA, and review recovery settings.

  • Primary email.
  • Password manager.
  • Banking and payment apps.
  • Cloud storage.
  • Phone carrier.
  • Work or school accounts.
  • Social media and shopping.
  • Lower-risk old accounts.

Use unique passwords, not variations

Do not replace a breached password with a close cousin. A new password should be unrelated to the old one and unique to that account.

A password manager makes this practical because you do not need to memorize every password.

Turn on MFA during the same session

When changing a high-value password, enable MFA before moving on. This reduces the chance that a later credential exposure becomes account takeover.

Prefer passkeys, security keys, or authenticator apps where possible.

Review account activity after changes

Changing the password is not the whole job. Check active sessions, devices, recovery email, recovery phone, connected apps, forwarding rules, and recent alerts.

Sign out unknown sessions and remove access you do not recognize.

Close forgotten accounts

After high-risk accounts are secured, delete unused accounts where practical. Remove payment methods and save records first.

Forgotten accounts often keep old passwords alive.

Frequently asked questions

Which password should I change first after a breach?

Start with your primary email, then password manager, banking, payments, cloud storage, phone carrier, and work accounts.

Should I change passwords that were not reused?

If a password was unique and not exposed, it may not be urgent. Focus on exposed, reused, weak, or high-value accounts.

Is MFA enough if my password was exposed?

No. Change exposed passwords and enable MFA. MFA is a second layer, not a reason to keep a known bad password.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.