Jump to content

Email has been exposed to data breach.

Hello!

 

According to "haveibeenpwned" site my email has been breached 21 times, and recently there was a paste found, and yes there is my email with password there. I was using same password for every site, and that is how i got there. Learned my lession. I'm scared, and dont know what else to do.

 

Things i did so far

- Changed all passwords and enabled 2 step authenticator where is that possible. 

- Enabled 2FA for sites that support it 

- Deleted accounts from breached sites and requested that they delete my data from database

- Migrated important accounts to another email

- Contacted email support, and asked them to secure my account as much as possible.

 

Yes 21 pastes is a lot, should i just make new email and delete all data?  But deleting would be stupid i think. What should i do? I really need help with this 

 

---

EDIT: Added 2fa in things i did so far

 

Edited by Evellence
Link to comment
Share on other sites

Link to post
Share on other sites

2FA will probably be enough to protect you from anybody trying to log into your account, especially if goes through your phone.

That's on top of changing your passwords.

 

I'd also make sure you have a good password and 2FA enabled on your other email. If you don't care about the breached email account, I'd say it's fine to nuke it.

Quote or tag me( @Crunchy Dragon) if you want me to see your reply

If a post solved your problem/answered your question, please consider marking it as "solved"

Community Standards // Join Floatplane!

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Evellence said:

Yes 21 pastes is a lot, should i just make new email and delete all data?  But deleting would be stupid i think. What should i do? I really need help with this

If it were me, an email address that compromised warrants dumping it for any use.

Link to comment
Share on other sites

Link to post
Share on other sites

Looks like you've already followed the sensible steps. 

Consider that email account burned. Even after changing your passwords once your email ends up on those lists it often ends up on spam mailing lists as well. Don't use it any more. Set up a new email account with all different passwords.

 

It can be a good idea to create multiple email addresses. One for important things, sites you trust. Then have a separate email address (or multiple) for random sites that require you to sign up. That way if some random website you signed up to a few years ago and forgot you even had an account on gets breached it's less likely to compromise the email you use for online banking.

 

I would also suggest ensuring you use different passwords on different sites, that way if your account is compromised on one service the other services remain relatively unaffected.

 

2FA everything you can. Most popular sites support 2FA in one form or another. Did you know the Linus Tech tips forum also supports 2FA? You can enable it in the account settings.

 

Also expect to receive a bunch of "we have hacked your system and we know your password is "whatever" and we have hacked your webcam and filmed you pleasuring yourself. If you don't send us Bitcoin we will release the video to your friends and family" type email scams. Just ignore them, don't reply. Seems to be a rather common tactic scammers have been using with recent beaches. (And don't worry, they didn't actually record you. It's just a lie to scam you.)

CPU: Intel i7 6700k  | Motherboard: Gigabyte Z170x Gaming 5 | RAM: 2x16GB 3000MHz Corsair Vengeance LPX | GPU: Gigabyte Aorus GTX 1080ti | PSU: Corsair RM750x (2018) | Case: BeQuiet SilentBase 800 | Cooler: Arctic Freezer 34 eSports | SSD: Samsung 970 Evo 500GB + Samsung 840 500GB + Crucial MX500 2TB | Monitor: Acer Predator XB271HU + Samsung BX2450

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, Spotty said:

Looks like you've already followed the sensible steps. 

Consider that email account burned. Even after changing your passwords once your email ends up on those lists it often ends up on spam mailing lists as well. Don't use it any more. Set up a new email account with all different passwords.

 

It can be a good idea to create multiple email addresses. One for important things, sites you trust. Then have a separate email address (or multiple) for random sites that require you to sign up. That way if some random website you signed up to a few years ago and forgot you even had an account on gets breached it's less likely to compromise the email you use for online banking.

 

I would also suggest ensuring you use different passwords on different sites, that way if your account is compromised on one service the other services remain relatively unaffected.

 

2FA everything you can. Most popular sites support 2FA in one form or another. Did you know the Linus Tech tips forum also supports 2FA? You can enable it in the account settings.

 

Also expect to receive a bunch of "we have hacked your system and we know your password is "whatever" and we have hacked your webcam and filmed you pleasuring yourself. If you don't send us Bitcoin we will release the video to your friends and family" type email scams. Just ignore them, don't reply. Seems to be a rather common tactic scammers have been using with recent beaches. (And don't worry, they didn't actually record you. It's just a lie to scam you.)

Yes, i enabled 2fa for most of the sites that support it. I'm already at process of making a new email and slowly migrating important accounts to that email. As for the spam, its true i am getting those "recorded you" emails like 2-5 a day. Alright, i will just burn it and just get another email

 

Thank you for your answer. I really appreciate it. 

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, Evellence said:

haveibeenpwned

 

Just a question, 

 

Can haveibeenpwned be trusted?

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Catchears said:

 

Just a question, 

 

Can haveibeenpwned be trusted?

With what? They don’t host anything, they just check known lists of compromised site to see if your email address shows up. 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, lloose said:

With what? They don’t host anything, they just check known lists of compromised site to see if your email address shows up. 

As in, do they keep email adresses? I would assume not but I thought I'd ask.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, lloose said:

With what? They don’t host anything, they just check known lists of compromised site to see if your email address shows up. 

I think was meant to ask along the lines of:

 

Does using that also sign entered email up for 5000 spamlists :) (like tge "unsubscribe" buttons in spam do ;) )

 

id also like to know..

Link to comment
Share on other sites

Link to post
Share on other sites

I’ve been checking it for years and never had an issue. Even on private email addresses which never get spam. 

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, lloose said:

I’ve been checking it for years and never had an issue. Even on private email addresses which never get spam. 

Thanks for the info!

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, lloose said:

I’ve been checking it for years and never had an issue. Even on private email addresses which never get spam. 

Thanks.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×