SOCLYDE logo
Current languageEN
Cybersecurity newsData breachPasswordsCyber Month

Data breach: which passwords should you change first?

The 2026 Cyber Month survey tracks the rise in people notified of a data breach. Learn how to verify an alert and prioritise password changes.

By Soclyde Team

A customer verifies an unexpected contact with her bank

In summary

  • The Cybermalveillance.gouv.fr / Ipsos survey found that 45% of respondents had been told about a personal data breach in the previous 12 months; it does not measure the number of breaches or resulting fraud.
  • Verify an alert through the organisation’s official website or app, then change the exposed password and any identical or reused passwords.
  • Prioritise email, financial and work accounts, enable multi-factor authentication, and watch for personalised messages.

Explore next

Soclyde resources

Article contents

Ahead of Cyber Month 2026, Cybermalveillance.gouv.fr published its third survey on how people in France perceive cyber risks, conducted with Ipsos bva. Among respondents, 45% say they were informed of a personal data breach in the previous 12 months, up from 30% in the 2025 edition. The finding points to a practical need: knowing what to do when an organisation tells you some of your information may have been exposed.

The figure describes notifications reported in an online survey of 2,000 people aged 18 to 75, conducted from May 13 to 18, 2026. It does not mean that 45% of people suffered fraud, nor that every breach was independently confirmed. The same survey found that 53% of people informed of a breach say they changed their passwords. The next question is which passwords to change and how to avoid a follow-up scam.

What the Cyber Month figure measures

The survey measures respondents’ perceptions and reported experiences. The increase from 30% to 45% concerns people who say they received information about a personal data breach in the previous 12 months. It is not a count of incidents reported to authorities or an estimate of compromised accounts.

That distinction matters when an alarming message arrives. A notification may concern different categories of data depending on the organisation and incident. Contact details can make phishing more convincing; an exposed or reused password may also lead to sign-in attempts on other services. Verify what was actually affected before deciding what to do.

Verify the alert and identify the exposed data

Do not click a link in an unexpected message to “secure” your account. Open the organisation’s official website or app yourself, or find its contact details from a trusted source. If the message appears legitimate, look for information about the incident, the data involved and the recommended actions. When in doubt, contact the organisation through a channel listed on its official website.

This check can separate a real notification from phishing that exploits news about data breaches. It also helps avoid applying the same remedy to every situation: exposure of an email address does not automatically call for the same steps as exposure of a password or bank details. Cybermalveillance.gouv.fr’s response guide describes recommended actions for different situations.

A checklist published on October 1, 2026 by Cybermalveillance.gouv.fr and the CNIL also organises actions over time: act promptly without panic, stay alert over the following weeks and strengthen everyday practices. See their three-step checklist for the detailed sequence.

Which passwords should you change first?

If the notification says a password was exposed, change it on the affected service. Replace it anywhere else you used the same password, because one shared secret can put several accounts at risk. Use a unique password for every service and enable multi-factor authentication wherever it is available.

If the organisation does not say that a password was involved, ask it directly instead of assuming. If you cannot determine this, start with your primary email account, which is often used to recover other accounts, followed by financial services and work accounts. The CNIL also recommends changing reused passwords and enabling multi-factor authentication. A password manager can help you find accounts and keep their credentials distinct. To create a new secret, use Soclyde’s secure password generator guide.

Prepare for personalised scams

After a breach, a message may include an accurate name, phone number or reference to appear credible. The Cybermalveillance.gouv.fr survey found that 59% of people notified say they became more alert to unfamiliar emails, texts and calls. That vigilance is useful in the days after an alert and over time: exposed information may be reused later.

Do not give a password, verification code or bank details to someone who contacts you. To verify an urgent request, end the conversation and call the organisation using the number on its official website. If bank data may be involved, contact your bank through its app or official contact details and monitor transactions.

How Soclyde can help

Soclyde cannot prevent a breach at a third-party organisation or secure the affected account by itself. It can help you manage access after an alert: each service can have a different password, credentials are kept in an encrypted vault, and you can find the secret that needs replacing without relying on a scattered list.

This organisation reduces password reuse and makes necessary changes easier. It complements the steps required with the affected service, multi-factor authentication and vigilance against phishing. To get started, create a unique password with Soclyde’s generator.

Takeaway

The Cyber Month survey indicates that more respondents say they have been informed of a breach; it does not show that the same share experienced fraud. When a notification arrives, first verify its source and the data involved. Change the exposed password and every reused copy, prioritise email and sensitive accounts, then watch for messages that use accurate personal information to gain your trust.

To organise your credentials, read Soclyde’s guide to password manager security.

Frequently asked questions

Does 45% mean that nearly half of French people were hacked?

No. The survey reports the share of respondents who say they were informed of a personal data breach in the previous 12 months. It does not independently verify every notification or measure fraud resulting from a breach.

Should I change all my passwords after a breach notification?

Start with the password for the affected service and change it anywhere else you reused it. If you do not know whether it was exposed, verify the notification with the organisation and prioritise your email, financial and work accounts. Use a different password for every service.

How can I avoid a fake data breach alert?

Do not sign in through a link in an unexpected text or email. Open the organisation’s official app or website yourself, or call the number listed on its website. A data breach can make a scam more convincing even when a message contains accurate personal information.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading