Do these three things in order
Change the password on the account named in the notice. Do it on the real site you type yourself, not from a link in the email if you can avoid it. Scammers piggyback on breach news.
Ask a blunt question: did I use that password anywhere else? If yes, change those too, starting with email. If no, you can stop the cascade here. That is the quiet reward of unique passwords.
Turn on extra sign-in protection if the site offers it. Watch the email on that account for resets you did not request.
What the company cannot undo
They can lock stolen passwords on their end. They cannot unspread a password you reused. They cannot see your other logins. That part is yours.
Encryption in your password manager also cannot unspread a password you already typed into the breached site. It can make the replacement unique and easy to store so the next notice is smaller.
If you do not remember what you used
That is common. Open the site, use forgot-password once, and save the new unique password in a manager as if you were setting the account up for the first time. Then assume the old one might have been a favorite, and change email if that favorite is still in use there.
Stax Pass is built so the new record is locked on your device before it syncs. The lock, XChaCha20-Poly1305, keeps the contents private and helps detect if protected data was altered. It is not a time machine. It is a better home for the password you are about to live with.
Is this worth paying for?
Breach response without a manager is a scavenger hunt through memory. With a manager it is a few minutes. That difference is the product. A dollar a month is easier to defend after you have lived through one notice. Use the 45-day trial if you are in the middle of one now.
Take this with you
- Change the named account on the real site, not a panic link.
- Change any other place that shared that password, email first.
- Save the replacement as a unique generated password.
Common questions
The email looks official. Should I click it?
Open the company by typing the address you already know. Breach week is a popular time to send fake “secure your account” pages.
They offered free credit monitoring. Is that enough?
It can help you watch for some fallout. It does not replace changing the password or stopping reuse.
How long do I need to be careful?
Watch the inbox and bank activity in the following weeks. Unique passwords keep “careful” from meaning “change everything forever.”