If you reuse one password, this is the order to replace it
Most people don't get hacked because of a genius attacker. They get hacked because the same password sits on email, shopping, and a forum that leaked last year.
Fix it in this order — highest blast radius first:
Email. If this goes, password resets for everything else go with it.
Bank / payroll / tax. Money and identity.
Work SSO or admin panels. One leak can take a whole company down.
Anything with saved cards.
Everything else, as you log in.
Rules that actually stick:
One unique password per site. No variants like
Summer2024!andSummer2025!.A password manager generates and stores them. You remember one master password.
2FA on email and money. App-based, not SMS if you can help it.
You don't need a weekend for this. You need 10 minutes and the three logins that would hurt the most if they leaked.
