Digital Checkmark single post

Your Password Is Already Leaked: What to Do in the 95 Days Before It Matters

A single key lying on a dark keyboard under a shaft of light

When a password of yours turns up in a breach dump, it does not feel like an emergency. Nothing breaks. No alert fires. The account still works. That is exactly what makes it dangerous, and there is now a number that shows why.

In the 2026 Verizon Data Breach Investigations Report, researchers took organisations that were later published as ransomware victims and looked backwards. 73% of them had a credential leak or infostealer event in the year before the attack. Of those, half had it within 95 days of being hit.

A leaked credential is not the end of an incident. It is the start of a countdown.

How your password ends up for sale

Three routes, and only one of them is your fault:

Why attackers wait

They usually are not the same people. Credentials get harvested by one group, packaged, and sold to another that does the intrusion. That handover is what puts weeks or months between the leak and the attack, and it is the window you get for free if you are watching.

It also explains why the leak feels harmless. Nothing happens for a while precisely because the person who took it has not decided what to do with it yet.

What to do, in order

  1. Find out. Check whether your address appears in known breaches. Ours is free and does not ask you to register: check for leaked credentials. Do it for your work address and for the staff who handle payments.
  2. Change the password that matters most first. Your email account, not the site that leaked. Whoever controls your inbox can reset everything else.
  3. Kill the sessions, not just the password. This is the step most people skip. Changing a password does not always log out an attacker who holds a live session cookie. In Microsoft 365 and Google Workspace there is a “sign out everywhere” action. Use it.
  4. Turn on multifactor everywhere it is offered, starting with email, remote access and anything that touches money. An app code beats an SMS code.
  5. Stop reusing. A password manager is not about strong passwords, it is about different ones, so that one leak stays one leak.
  6. Assume the machine, not just the account. If the credential came from an infostealer, the password was taken off a computer, and that computer is still there. Scan it or rebuild it.

What “monitoring” should actually mean

Checking once is a snapshot. The leak that matters is the one that happens next March. Continuous monitoring means somebody watches for your domain appearing in new dumps and tells you which account to change, which is what our exposure and dark web work covers.

And because that credential is often the first step of a ransomware chain, the other half of the answer is being able to recover if it goes all the way: copies an attacker cannot reach and a restore that has actually been tested. That is continuity and recovery. If you want to see who is being hit right now, our ransomware tracker is public and free to search by industry.

The honest summary

You cannot stop other companies from leaking your data. You can find out quickly, close the door properly rather than half way, and make sure one exposed password does not become an encrypted business.

Ninety five days is not a long warning. It is enough, if somebody is looking.

Sources: Verizon 2026 Data Breach Investigations Report.