Respond to the affected account first.
Verify a breach notice through the service’s known website or app, rather than a link in an unexpected message. Review active sessions and account recovery settings, change exposed or reused credentials, and enable stronger authentication where the service supports it.
If a password was reused, update the other accounts that share it. Prioritize email and accounts that control recovery for other services. Use unique randomly generated passwords, and keep the updated values in a trusted manager.
A password absent from a known-breach database is not guaranteed safe. Vault currently has no built-in breach monitor; its proposed checks remain off and unimplemented. The future protocol must not send complete passwords or email addresses during a password-prefix check.
How the proposed password-prefix protocol works · Vault breach-check proposal