Security × Privacy
Breach.
Not cyber theater. The stuff ordinary people can actually check, understand, and change.
New to this? Tap any highlighted tech term for the plain-English version, or visit Tech / Explain it simple →
Defense, not a playbook.
We explain attack paths far enough to protect yourself, not far enough to help somebody compromise another person.
Something feels off
Check my phone
Open →
I got a weird login
Secure my accounts
Open →
My data was exposed
What matters now?
Open →
I want better defaults
Lock it down
Open →
Phone Watch
Does your phone feel like your phone?
Battery drain, heat, or extra data use can have innocent explanations. The stronger signal is a pattern: somebody knows private details they should not know, your sharing settings changed, unfamiliar apps or devices appear, or permissions do not match what you remember granting.
iPhone: run Safety Check
Apple built-inOn iOS 16 or later: Settings → Privacy & Security → Safety Check. Review who has access to your information, connected devices, app privacy permissions, and account security. Emergency Reset can stop sharing quickly.
Apple Safety Check guide →Android: run Play Protect
Google built-inOpen the Play Store, tap your profile, then Play Protect. Google says Play Protect scans installed apps for harmful behavior and can warn, disable, or remove potentially harmful apps.
Google Play Protect guide →If this may involve an abusive partner or ex
Do not assume deleting an app or changing settings is the safest first move. Removing monitoring can alert the person doing it. The FTC recommends using another trusted device to seek help and thinking about safety planning before changing the monitored phone.
FTC stalkerware guidance →Account Takeover
Start with the account that resets the others.
For most people, that is email. Social accounts, shopping, banking alerts, cloud storage, and password resets often point back to it.
Words you may see here
A is different from your password. adds another check. A targets your phone number.
First 15 minutes
Use a trusted device
If you think the original device is compromised, make account changes from another device you trust.
Secure email first
Change the email password if needed, review recovery methods, and remove sessions you do not recognize.
Kill unknown sessions
Sign out unfamiliar browsers, phones, apps, and sessions on the affected service.
Fix the recovery path
Check recovery email addresses, phone numbers, backup codes, and connected apps.
Upgrade authentication
Add a passkey or strong MFA. Do not approve login prompts you did not initiate.
Check your carrier
If your phone suddenly loses service or you suspect a SIM swap, contact the carrier from a known number and lock the account down.
Account takeover stories
Data Breaches
The headline is not the risk assessment.
A is not one single kind of event. “Millions exposed” tells you almost nothing by itself. What matters is what data escaped and what somebody can do with it.
Passwords / hashes
Change reused credentials. If the same password exists elsewhere, those accounts matter too.
Session tokens
A stolen session can matter even when the password is still secret. Review active sessions and revoke them.
Identity documents
Passports, licenses, selfies, and tax identifiers can support impersonation and identity fraud.
Email + phone
Expect more convincing phishing, fake support calls, recovery attempts, and SIM-swap social engineering.
Financial data
Watch the affected accounts, enable alerts, and follow the institution’s breach-specific guidance.
Private messages / files
The risk may be reputational, personal, workplace-related, or safety-related — not just financial.
Current Breach files
Lock It Down
Do the boring stuff before you need it.
This checklist stays in your browser. Check things off as you harden your setup. A is one of the stronger upgrades you may see recommended below.
Progress
0 / 8