I put my old Gmail accounts on websites like haveibeenpwned.com osintleak.com pentester.com and osint.industries
And the results had a lot of personal info like old usernames I used, old passwords, IP addresses and other info
What can I do now?
I deleted all of my old Gmail accounts. I changed all of my usernames everywhere or deleted the accounts associated with them and changed all the passwords. I use Proton and Email aliases when signing up for services and random generated passwords with fake info everywhere(if possible) and I do use a VPN on all of my devices.
Is there anything more I can do?
Because those Emails had my full real name in them and I used them literally everywhere.
HTTPS with no VPN:
You trust the web site to encrypt your data if and only if the web site has properly implemented encryption along with encrypted DNS traffic. Sometimes you make a connection to HTTP before you’re redirected to HTTPS. Your ISP can see what web sites you visit, but the ISP can’t see what you’re doing because the traffic is encrypted so long as encryption is implemented correctly. ISP knows you went to https://www.website.com/.
Conclusion: Your ISP knows exactly what web sites you visit, but can’t see what you’re doing on the web site (if encryption is properly configured by the web site provider).
HTTP or HTTPS with trusted VPN (e.g., Mullvad):
You trust the VPN provider. Your connections are encrypted entirely. Your ISP can’t see what web sites you’re visiting nor can they interpret your traffic.
Conclusion: Your ISP is completely blind to what you’re doing and where you’re going.
ExpressVPN:
PureVPN:
Here are more sources I won’t quote, but you can read: