54
submitted 3 months ago by A9b382ks@lemmy.world to c/privacy@lemmy.ml

I put my old Gmail accounts on websites like haveibeenpwned.com osintleak.com pentester.com and osint.industries

And the results had a lot of personal info like old usernames I used, old passwords, IP addresses and other info

What can I do now?

I deleted all of my old Gmail accounts. I changed all of my usernames everywhere or deleted the accounts associated with them and changed all the passwords. I use Proton and Email aliases when signing up for services and random generated passwords with fake info everywhere(if possible) and I do use a VPN on all of my devices.

Is there anything more I can do?

Because those Emails had my full real name in them and I used them literally everywhere.

all 11 comments
sorted by: hot top controversial new old
[-] CatZoomies@lemmy.world 27 points 3 months ago* (last edited 3 months ago)

Nothing much you can do except make it harder for nefarious parties to get your information. If you’re in the U.S. most of your information is public. With two pieces of info about you, you’re one Google search away from your name, physical address, schools you went to, where you’re employed, etc. You can’t stop this, so just make it harder when your data does get leaked.

Here are my best practices:

  • Own my email domain name and use it for generating unlimited random aliases.
  • Update old accounts using a random alias.
  • Generate random usernames using a proper username generator. Unique username per account.
  • If an old account email can’t be updated, changed, or deleted, spoil the information in their system by using fake info and then abandon the account (Anon O’Moose, 1234 Fake Street, Beverly Hills, CA 90210).
  • One email alias per account - never shared.
  • Unique passwords via a password manager (e.g., passwords like ‘Obtuse4-Entangle-Matrix’).
  • Enable TOTP multi-factor authentication wherever possible.
  • For legacy security questions, always use a passphrase generator for the answer, and save both the question and answer into your password manager. “In what city did you go to school?”Answer: “Bandit4-Topic-Guardian”.
  • Save recovery codes for your accounts into your password manager.
  • Leverage virtual credit card numbers if your provider offers it. One virtual card per account - never shared.
  • Create accounts only if you have no choice.
  • Submit your formal request in Opt Out Prescreen to minimise the sale of your info.
  • Delete all centralised social media accounts. Instruct people to text or call you.
  • Switch to Linux completely if you can. Get off Windows and Mac where possible.
  • Get off iOS if you can and try to run a proper trusted degoogled OS where possible. You can experiment with Linux phones in the future, but right now it’s not mature enough yet nor is it as secure as something like Graphene OS on Pixel phones.
  • Get all your data on prem only. If you choose to backup some data for safeguarding online, encrypt it before you upload it.
  • If your phone number has been leaked and you’re getting multi factor code requests, excessive spam, etc. consider setting up a new phone line with new number. Then update all your accounts, employer, government records, etc. to point to the new phone number. Let your contacts know. Once satisfied, deactivate your old phone number.
  • Minimise posting any personal details about yourself online. Never identify physical locations. Make up fake details about yourself, your employment, etc. Make yourself a little more anonymous by providing fake information. One day you have a pet, another day you’ve never had pets, one day you’re divorced, another day you’re 18 years old, etc. Strive to be consistently inconsistent with the data you post about yourself online. Lots of things I’ve said on Lemmy about myself are untrue, while some things are true. It’s important to not reveal personal identifiers as it is trivial for a determined actor to correlate data and pinpoint who you are.
  • Never, ever have any usernames, passwords, email addresses, or security questions that have any meaningful information related to you. ALWAYS use random generators. There is only one password you need to remember, and that is the one password to your password manager. Write it down on paper using pencil (graphite lasts longer than ink) and stick it in a safe.
  • Use a VPN properly and with discretion, based on your privacy threat model.
[-] suicidaleggroll@lemm.ee 13 points 3 months ago* (last edited 3 months ago)

Something I haven't seen mentioned yet - if you're in the US, lock down your credit at all 3 agencies. It takes 10-15 minutes and is free, it's easy to do.

The issue is that many of these leaks include things like your full legal name, phone number, parents' full legal names, your social security number, and your entire address history. This makes it trivially easy for somebody to steal your identity and start opening up credit accounts in your name. You need to lock down your credit before that happens. If you need your credit run in the future (opening a bank account, getting a credit card or loan), just ask them which agency they pull the report from and temporarily unfreeze it so they can run the report, then re-freeze it when they're done. It adds 5 minutes of work once or twice a decade, but could be priceless later on when someone tries to steal your identity.

Be as uninteresting as possible. Millions if not billions of people's information of this sort is out there.

[-] thesohoriots@lemmy.world 7 points 3 months ago

Cash in your free two years of identityworks from whichever company leaked it, wait a while, cash in another two years from the next company that leaks it, wait a while, cash in another two years from the next company — you get the idea

[-] catloaf@lemm.ee 3 points 3 months ago

You could change your name. Otherwise, not really.

[-] eldereko@lemmy.dbzer0.com 1 points 3 months ago

delete all your social medias and online accounts

[-] autonomoususer@lemmy.world 1 points 2 months ago* (last edited 2 months ago)

Nothing will bring your data back. Use libre software, not services.

this post was submitted on 29 Apr 2025
54 points (100.0% liked)

Privacy

40253 readers
577 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS