A password-reuse change checklist is the order of work after a credential match: email, then bank, then every reused site, then 2FA. Print or copy the numbered list. This is not the password leak checker — that tool only looks up a secret. Last updated: September 2026.
A password-reuse change checklist is the human workflow after a credential match — not another lookup tool. Change the email password first. Then banking and payment apps. Then every site that still accepts the leaked string. Then turn on two-factor authentication, starting with email. Print the numbered list. Tick lines as you finish them.
This page is that list. It is not the password leak checker, which only answers whether a secret already appears in known leak data. It is not a brand-by-brand vault review. For why a manager shrinks the blast radius, use password manager after a data breach. For the first-hour playbook that includes email-only and phone rows, use what to do after a data breach.
What is a password-reuse change checklist?
It is a change order, written so you can print it or keep it in another tab while you work.
A credential match means an email-and-password pair — or a password hash tied to you — appeared in collected leak records. Credential stuffing takes that pair and tries it on other sites. The work is not “understand the hack.” The work is kill reuse before the next automated pass.
As of 2026, public catalogs still describe on the order of a thousand named incidents and more than 12 billion compromised records. The Verizon 2024 Data Breach Investigations Report again found stolen or guessed logins in a large share of web-application breaches. Old files stay useful. Collection #1 is still a 2019 compilation circulating in 2026. Age does not retire a password you never changed.
This checklist assumes the result listed a password, credentials, or a combo / stuffing file. If the row is email-only or phone-only, you are on a different playbook. Do not invent a twenty-site reset from a scrape.
- One reused password turns one leak into many logins.
- Unique passwords confine the damage to the named site.
- Close variations such as
Summer2024!toSummer2026!still count as reuse. - A compilation name is not a company login.
Why change email before banking and reused sites?
Because password resets land in email.
If the inbox still accepts the leaked string, an attacker who tries that pair on Gmail, Outlook, or Apple ID can start resets on the bank next. Changing the bank first while the inbox is still weak is a temporary win.
The same logic puts the vault login — the Apple ID, Google account, or password-manager master — high on the list once email is unique. If that unlock still shares the leaked string, autofill becomes a gift to whoever has the old password.
Banking is second because it is direct money. Shops with saved cards, cloud storage, social accounts you still use, and work logins are the reuse hunt. Streaming you barely open can wait an hour. It should not wait a month if it still shares the string.
NIST Special Publication 800-63B warns against predictable tweaks and tells services to check new passwords against known leaked lists. Do not “update the year” on the old password. Generate a new one, or use a long passphrase you have never used anywhere.
Open official sites yourself. Type the address or use a bookmark. Do not tap “secure your account” links in a surprise email about the leak.
What is the printable password-reuse change checklist?
Copy this block, print the page, or tick in a notes app. One line at a time. Do not start line 6 until line 1 is done.
Password-reuse change checklist
- Email password changed to a unique string and saved (vault or locked paper).
- Other email sessions signed out / “sign out everywhere” if the site offers it.
- Bank, card, and payment-app passwords changed to unique strings.
- Every reused-password site changed: shops with saved cards, cloud, social you still use, work.
- Vault / Apple ID / Google login changed if it shared the leaked string.
- Old password checked in the password leak checker if you still remember it — confirmation, not the whole job.
- 2FA or a passkey turned on for email, then bank, then the vault. Authenticator app over SMS.
- Backup codes saved in the vault or on paper — not in the same unlocked Notes app as the password.
- Recovery email and recovery phone reviewed on the account security checklist.
- Phishing watch for the next 90 days. Type real sites yourself.
Print extras that help and are optional on night one:
- Close leftover logins from the delete-account hub once the important passwords are unique.
- Recheck the email checker so you see other named incidents, not just the one that scared you.
A named company in the result is a login you can open. A compilation name is not. For Collection #1 and similar lists, skip “log into the breached site” and start at line 1.
Confirm which incidents named this inbox. Check if your email was exposed → — free, no signup. We do not keep the address you type. Then use the password leak checker if the secret itself might have travelled.
When should you use the password leak checker instead of this checklist?
Use both. They are not the same page.
The password leak checker is a lookup. Your browser hashes the password and sends only a short prefix (k-anonymity). The full secret never leaves the device. A hit means treat that string as public. A miss is a snapshot of the lists that tool can search, not a lifetime all-clear.
This checklist is the change workflow. You can run it after a company notice, after an email-checker row that listed passwords, or after the password tool returns a hit. You do not need the password tool to start line 1 if you already know you reused a string.
Do not paste a password into the email checker. Do not treat a password-tool miss as permission to keep one password on email and banking.
Industry-standard breach data sources are large. They are not every private sale. That is why a clean lookup is not the end of the list.
What comes after the password changes?
The second lock.
Turn on two-factor authentication after the password on that site is unique and other sessions are signed out. Adding a second factor to an account the attacker already holds can lock you out together, or leave their session running. The order and the app-versus-SMS choice are in 2FA and passkeys after a data breach.
Prefer an authenticator app or a passkey on email and banking. SMS is better than nothing and weaker when a phone number leaked. If the same incident listed a phone, add the phone playbook.
A password manager is how most people finish lines 3–5 without inventing cousins of the old string. Categories, not a shopping list, live on the after-breach manager guide. You can follow this checklist on paper. A vault makes the rest finishable.
If you cannot get into a site, use that site’s own forgot-password flow through the inbox you just locked — typed by you.
Browse the breach catalog when you want the story of a named incident, not just a row. Confused by compiler names? Types of data breaches separates stealer logs, combo lists, and scrapes.
What should you skip on day one?
Do not spend the first hour on these. They feel productive. They do not kill reuse.
- Deleting every old account before email and bank are unique
- Arguing with the company that leaked
- Buying a “dark web removal” plan. Copies do not get recalled. You make the password useless.
- Ranking password-manager brands
- Resetting sites that never shared the leaked string because a headline was loud
- Adding 2FA before you change the password, if you can still get in
Close unused logins later. Freeze credit if a government ID was listed — that is a different job, on credit freeze after an SSN breach. This page stays on reused passwords.
If the match was email-only, you do not need this full ten-line reset. Lock the inbox anyway. Then use the quieter playbook on the after-breach page.
- Order: email → bank → reused sites → vault login → 2FA.
- This is a printable change list. The password leak checker is a lookup, not this workflow.
- A compilation match still uses the same order. There is no company to call.
- Change the password, sign out, then add an authenticator app or passkey.
- Skip removal products and account-deletion marathons until reuse is dead.
Want the list applied to your address? Check if your email was exposed, then test the old password if you still remember it.