About this tool
Weighted response plan for an email address caught in a data breach: password resets on every linked account, 2FA, and breach-themed phishing watch.
The Email Data Breach Response Checklist scores your response to a leaked email address across 16 weighted steps, grouped by the window each one belongs in — first 24 hours, first week, first month, and ongoing. An email address is not just a contact detail; it is the username, and often the recovery contact, for every account tied to it, so the score is weighted towards the two things that actually close off access: resetting the email account and any reused password first, then locking the accounts it protects with a second factor. Enter the date you found out and the tool flags which steps have already slipped past their window.
Open Email Data Breach Response Checklist on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Every step carries a 24-hour, one-week, one-month or ongoing deadline, and overdue items are surfaced separately.
Resetting the email account and any reused password score far higher than phishing awareness, so effort lands on the steps that actually close off account access.
The email address itself is never entered — you tick steps, and the tool stores no personal data at all.
Search it at a reputable breach-lookup service such as Have I Been Pwned. It lists which known breaches include the address and, where the service shows it, which data types were part of each one — that list decides how far the rest of the response needs to go.
The email account itself, before any other account. It can approve password resets for almost everything else you own, so leaving its old password in place undoes the value of resetting the accounts that come after it.
It is better than no second factor, but an authenticator app or a passkey is stronger. SMS codes can be intercepted through SIM-swap fraud, which becomes easier once an attacker already has your email and phone number from the same leak.
Because a public breach gives scammers a real company name and date to cite, which makes a fake follow-up message far more convincing than generic phishing. Type the site's address in directly rather than clicking a link in any message that references the breach, and never read a one-time code to someone who calls you.