Your email appeared in a breach: what next?
Work out whether the report involves contact details, a password, or access to your account.

An address is not an inbox
A company can lose a customer email address without exposing the password to that email provider. Read the field list before assuming your inbox was accessed. Check the provider’s own activity page if you see unfamiliar sign-ins or changes.
Check passwords and recovery access
If a password was involved and you still use it, replace it wherever it is shared. Give your main email a unique password and an additional sign-in factor where supported. Keep recovery contact details under your control.
Expect more convincing messages
A sender may know a real service you used or a former username. Verify the request by opening the known website yourself. Do not give a caller a code because they can quote a detail from your account history.
Decide what to retain
You do not automatically need to abandon an address because it appears in a report. Consider which accounts depend on it and whether you can maintain secure recovery access. Close unused accounts through their actual providers, keeping any records you need.
