> ## Documentation Index
> Fetch the complete documentation index at: https://kb.hosting.com/llms.txt
> Use this file to discover all available pages before exploring further.

# I Received a Security Alert — What Should I Do?

> A Security & Dark Web Monitoring alert means information associated with one of your monitored email addresses was found in known leaked or breached data.

This does **not** necessarily mean your [Hosting.com](http://Hosting.com) account, website, or email account was hacked.

## 1. Review the alert

Sign in to your **Hosting Panel** and open **Security & Dark Web Monitoring** to review the finding.

The report may show information such as:

* The affected email address
* The breach or service where the information was found
* The type of information exposed
* Whether a password was included in the exposed data

For more information about the details in your report, see **\[[How to Read Your Security & Dark Web Monitoring Report](/how-to-read-your-security-and-dark-web-monitoring-report)]**.

## 2. Change the exposed password

If the alert shows that a password was exposed, change it as soon as possible.

If you used the same password on other websites or services, change it there too.

> **Important:** Use a different, unique password for each account.

## 3. Turn on two-factor authentication

Enable **two-factor authentication (2FA)** on the affected account whenever it is available.

2FA adds another verification step when signing in, making it harder for someone to access the account using a stolen password.

## 4. Be careful with suspicious messages

After a breach, you may receive more spam or phishing messages.

Be cautious with unexpected:

* Emails
* Links
* Attachments
* Password reset requests
* Messages asking for personal or account information

Check where a message came from before clicking links or providing information.

## What if my password isn't shown?

Security & Dark Web Monitoring does not display exposed passwords in the report.

If the report indicates that a password was exposed, change it anywhere you may have reused it and enable 2FA where possible.

If no password was exposed, continue to watch for suspicious activity and keep 2FA enabled on your important accounts.

## Can the leaked information be removed?

Security & Dark Web Monitoring can alert you when your information appears in known breach data, but it does not remove the information from the internet.

The most useful steps are to secure the affected accounts, change reused passwords, and enable 2FA.

## What if I don't recognize the breach?

A breach may involve a website or service you used in the past, even if you no longer use it.

If you don't recognize the service, review the information in the report and consider whether the affected email address may have been used there previously.

## Need help?

For an overview of Security & Dark Web Monitoring, see **\[[Security & Dark Web Monitoring](/security-and-dark-web-monitoring)]**.

To understand the information shown in your alert, see **\[[How to Read Your Security & Dark Web Monitoring Report](/how-to-read-your-security-and-dark-web-monitoring-report)]**.
