I use strongbox.. I check my logins all the time. With password leaks I first make sure the account should still be active (that does happen). If it's a leak I change the password and email the member a simply email that says we changed the password, and here is the new login details.
If the account re-leaks (very low %) and the account is a fresh cancel, I kill the access. If it's an old account I select a new hard password, from here if a re-leak happens again I cancel and close the account.
I check all failed password logins, and email the member a notice on why they are having login problems. I email 80% to the 20% that ask for help.
From here I check every login that takes place, since I can see every country/ip, anyone that has more than 2 logins from a different country/isp/ip I email a new password.
|