How to Check if Your Email Has Been in a Data Breach
There are 14+ billion compromised accounts in public breach databases. If you have used the internet for more than a few years, your email is in at least one of them — probably several. A breached email is not automatically an emergency, but it is a clock: whoever holds that data now has a piece of your identity, and what you do in the next hour decides how much it is worth to them.
Step 1: Check the damage safely
Use a reputable breach lookup — Have I Been Pwned for the free check, or the exposure scanner on this site, which cross-references breach databases and OSINT sources in one pass. Do not paste your password into any site that claims to "check if your password leaked." Legitimate services ask for your email; a site asking for the password itself is the scam it warns you about.
The report will list which services leaked you and what leaked: passwords, password hashes, names, dates of birth, phone numbers, addresses, or partial payment data. That distinction drives everything below.
Step 2: Rotate passwords — breach site first, then every reuse
Change the password on the breached service first. Then the uncomfortable part: every other account where you reused that password. Attackers do not try your email on one site — they run credential stuffing against hundreds of services automatically, because password reuse turns one breach into a skeleton key. If you do not know where you reused it, that is your sign to move every account into a password manager (Bitwarden is free and audited) and generate a unique password for each.
Step 3: Lock the account itself
- Turn on MFA — an authenticator app at minimum; a hardware key like a YubiKey for email, banking, and anything that can reset other accounts.
- Kill SMS-based 2FA where an app or key is offered — SIM-swapping makes SMS the weakest option.
- Review active sessions and app passwords — sign out everything, then re-authenticate.
- Check recovery email and phone — attackers who have your data will try the "forgot password" path first.
Step 4: Match your response to what actually leaked
A leaked password hash from a forum is a nuisance. A leaked full name plus date of birth plus physical address is a phishing kit. Leaked partial card data or an SSN is an identity-theft launchpad:
- SSN in the dump — freeze your credit at all three bureaus, file for an IRS IP PIN, and watch for tax-refund fraud in the filing season after the breach.
- Card data — the bank almost always reissues on report; set transaction alerts while you wait.
- Security question answers — treat them as burned. Replace pet names and streets with generated strings in the password manager.
A breach does not hurt you when it happens. It hurts you when you are still reusing the password two years later.
Step 5: Expect the phishing wave — it is aimed at you now
Within weeks of a serious breach, the affected users get phishing emails that reference the breach itself: "your account was compromised, click here to secure it." The most dangerous email you will receive after a breach is the one pretending to fix the breach. Verify by navigating to the service directly, never through the link. If your company's domain was breached, tell your team before the phishers do — I cover that playbook in the data broker removal guide and the business security piece.
Then make the next breach boring
After the fire is out: email aliases per service, a password manager, MFA everywhere, and a standing check every few months. The goal is not zero breaches — nobody gets that. The goal is that the next breach is a one-line note in your password manager instead of a weekend of emergency rotation.
// check_now
Which breaches are you in?
One scan cross-references your email, domain, or username against known breach databases and OSINT sources.
Run the $1.99 Exposure Scan →