Work out what was actually exposed
Breach notices are deliberately vague. Start by reading the notice for the data categories named: email address only is a nuisance; password hashes or identity documents are a different matter. Check the company's own status page rather than acting on a forwarded email, which may itself be a scam riding the news.
The ordered checklist
- Change the password on the breached service, and on anywhere you reused it
- Turn on app-based or passkey two-factor authentication on that account
- Review active sessions and signed-in devices, and sign the unknown ones out
- Check recovery email and phone number are still yours
- Watch for targeted phishing referencing the breach for the next few weeks
- If financial or identity data was included, notify your bank and consider a credit freeze
What not to do
Do not buy a 'breach removal' service that promises to delete your data from the internet, and never pay anyone claiming to hold your records. Do not attempt to access the leaked dataset yourself — handling stolen credentials is unlawful in most jurisdictions regardless of intent.