Check for a data breach: am I affected?
Billions of login details from old hacks are in circulation. Here is how to find out in a few minutes whether your email or passwords are in a breach – and what the results actually mean.
Breaches are routine. When an online service gets hacked, email addresses and passwords end up in collections that circulate freely. The good news: you can check in minutes whether you are in one, and then act on facts instead of worrying.
The short version
- Use an established checker: Have I Been Pwned.
- Enter your email only, never your password.
- A hit is not a crisis. What matters is whether you reused that password.
- Change affected passwords and turn on two-factor authentication .
- Set up ongoing monitoring through your password manager.
Which data can be exposed
Not every breach is equally serious. What matters is what leaked:
- Email address: usually the starting point. On its own it is rarely dangerous, but it ties the rest of the data together.
- Password: the biggest risk, especially if you use it in more than one place. Attackers then try it automatically on other services – this is called credential stuffing.
- Phone number: used for spam calls, scam texts and SIM swapping.
- Name, address, date of birth: building blocks for identity theft and contracts opened in your name.
- Payment details: card or account numbers. This is the case where you act immediately.
The more of these appear together, the more valuable the set is to a criminal. If your name and address are out there in the open, identity theft becomes a real risk.
How to check, in three steps
A few minutes to a clear answer
- 1. Check your email: enter your address at haveibeenpwned.com and see which breaches it appears in.
- 2. Check every address you use, including old ones and any alias you have handed out.
- 3. Review your passwords: look through your password manager for reused passwords and anything flagged as breached.
What the results mean
- No hit: a good sign, but not a guarantee. Keep using unique passwords.
- A hit at an old service: your data leaked. It matters most if you reused that password somewhere else.
- A hit with the password in plain text: change it right now, everywhere it was used.
Reacting the right way
- Change the exposed password – and every other place you used it.
- Turn on two-factor authentication for your important accounts: email, banking, shopping.
- Watch the account: check login alerts and active sessions.
- If it is your email address, follow the full recovery plan.
The full plan is in Your email is in a data breach – what now? . If an account has already been taken over, go to Account hacked – what to do first . If your name and address are openly searchable, see Remove your data from people-search sites .
Warning signs after a breach
Targeted scam attempts often pick up after a leak. Stay alert for a few weeks, especially for:
- Phishing emails that use your name or quote real details about you. That is what makes them convincing.
- Scam texts about packages, banks or a “locked account.”
- Calls from fake support or from “your bank,” asking for codes or login details.
- Login alerts and two-factor codes you did not request – a sign someone is testing your password.
- Extortion emails quoting an old password of yours – almost always a bluff built on breach data.
Learn to spot the pattern: How to spot phishing .
Keeping an eye on it long term
- Use a password manager with breach monitoring, and prefer it over your browser’s built-in store: Password managers explained .
- Use a unique password per service, so one breach cannot reach your other accounts.
- Turn on two-factor authentication as a second wall if a password does slip out.
Common mistakes
- Typing a password into a checker – never necessary, always a red flag.
- Ignoring a hit because it was “years ago.” A reused password stays dangerous.
- Changing one account only, when the password was used in several places.
More groundwork in the identity protection section .
Frequently asked questions
Which breach checkers can I trust?
Have I Been Pwned (haveibeenpwned.com) is the established, free and ad-free option. Most password managers also have breach monitoring built in, which checks your saved logins automatically.
Is it safe to type my email into a checker like that?
With an established service, yes. Never type your password into one. A legitimate checker only asks for your email address. Have I Been Pwned checks passwords in an anonymized way that never sends the password itself.
My account is in a breach – does that mean it is hacked?
Not necessarily. A hit means your data leaked from some provider. The real danger is reusing that password elsewhere. Change it everywhere you used it and turn on two-factor authentication.
Topics: Identity, Data Breach