Breach alerts, rotation, and stopping credential stuffing

Why monitoring matters

When a site leaks passwords, attackers try those email/password pairs elsewhere (credential stuffing). Unique passwords contain the blast radius. Monitoring tells you when to rotate.

What to do after a warning

  1. Change the password on the affected site — use a new random password.
  2. Change the same password anywhere else you reused it.
  3. Enable MFA; use OTP concepts as a complement, not a replacement for unique passwords.

On-site tools