Yes. Please change it now, and change it anywhere else you have used the same or a similar password.
The steps are here: How do I change my Quarterdeck account password?
What was taken
Quarterdeck account passwords were among the records copied. They were not stored in a readable form, but the method protecting them is outdated by current standards and can be reversed with the computing power available today. Treat your old password as known to someone else.
A small number of accounts were affected differently. Where that applies, we wrote to those people separately and their notice says so. Your own notice is the accurate account of what applies to you.
Password-recovery codes
Recovery codes were also among the records copied. Every code taken had already expired before the intrusion ended, so none of them could be used to reset an account. We have since replaced how those codes are generated.
Why it matters most somewhere else
Changing your Quarterdeck password closes the smallest part of the risk. The larger risk is any other service where you used the same password, because whoever holds this data also holds your email address. That combination is what makes an attempt on your other accounts worth trying.
If you reuse a password anywhere that matters — email, banking, cloud storage — change it there first, then come back to your Quarterdeck account.
How we will never contact you
We will never email you an unsolicited password reset link, and we will never ask you for your password, card details or bank details. If a message claiming to be from us does either of those things, it is not from us. Do not reply to it and do not click anything in it.
Expect more convincing attempts than usual, because whoever holds this data knows real details of your work with us. See also Can I speak to someone on the phone? — we are not making outbound calls, so any call claiming to be us is not us.
