Check for a data breach: am I affected?

Billions of login details from old hacks are in circulation. Here is how to find out in a few minutes whether your email or passwords are in a breach – and what the results actually mean.

Breaches are routine. When an online service gets hacked, email addresses and passwords end up in collections that circulate freely. The good news: you can check in minutes whether you are in one, and then act on facts instead of worrying.

The short version

  • Use an established checker: Have I Been Pwned.
  • Enter your email only, never your password.
  • A hit is not a crisis. What matters is whether you reused that password.
  • Change affected passwords and turn on two-factor authentication .
  • Set up ongoing monitoring through your password manager.

Which data can be exposed

Not every breach is equally serious. What matters is what leaked:

  • Email address: usually the starting point. On its own it is rarely dangerous, but it ties the rest of the data together.
  • Password: the biggest risk, especially if you use it in more than one place. Attackers then try it automatically on other services – this is called credential stuffing.
  • Phone number: used for spam calls, scam texts and SIM swapping.
  • Name, address, date of birth: building blocks for identity theft and contracts opened in your name.
  • Payment details: card or account numbers. This is the case where you act immediately.

The more of these appear together, the more valuable the set is to a criminal. If your name and address are out there in the open, identity theft becomes a real risk.

How to check, in three steps

A few minutes to a clear answer

  • 1. Check your email: enter your address at haveibeenpwned.com and see which breaches it appears in.
  • 2. Check every address you use, including old ones and any alias you have handed out.
  • 3. Review your passwords: look through your password manager for reused passwords and anything flagged as breached.
Never type in your password A legitimate checker only needs your email address. Any site asking for your password in plain text is either careless or an outright phishing page. Have I Been Pwned checks passwords using a method called k-anonymity, which never transmits the password itself.

What the results mean

  • No hit: a good sign, but not a guarantee. Keep using unique passwords.
  • A hit at an old service: your data leaked. It matters most if you reused that password somewhere else.
  • A hit with the password in plain text: change it right now, everywhere it was used.

Reacting the right way

If you are affected
  1. Change the exposed password – and every other place you used it.
  2. Turn on two-factor authentication for your important accounts: email, banking, shopping.
  3. Watch the account: check login alerts and active sessions.
  4. If it is your email address, follow the full recovery plan.

The full plan is in Your email is in a data breach – what now? . If an account has already been taken over, go to Account hacked – what to do first . If your name and address are openly searchable, see Remove your data from people-search sites .

Warning signs after a breach

Targeted scam attempts often pick up after a leak. Stay alert for a few weeks, especially for:

  • Phishing emails that use your name or quote real details about you. That is what makes them convincing.
  • Scam texts about packages, banks or a “locked account.”
  • Calls from fake support or from “your bank,” asking for codes or login details.
  • Login alerts and two-factor codes you did not request – a sign someone is testing your password.
  • Extortion emails quoting an old password of yours – almost always a bluff built on breach data.

Learn to spot the pattern: How to spot phishing .

Keeping an eye on it long term

  • Use a password manager with breach monitoring, and prefer it over your browser’s built-in store: Password managers explained .
  • Use a unique password per service, so one breach cannot reach your other accounts.
  • Turn on two-factor authentication as a second wall if a password does slip out.
Fifteen minutes to a solid baseline Want to set everything up properly in one go? Our 15-minute security check walks you through the steps that matter – including the breach check.

Common mistakes

  • Typing a password into a checker – never necessary, always a red flag.
  • Ignoring a hit because it was “years ago.” A reused password stays dangerous.
  • Changing one account only, when the password was used in several places.

More groundwork in the identity protection section .

Frequently asked questions

Which breach checkers can I trust?

Have I Been Pwned (haveibeenpwned.com) is the established, free and ad-free option. Most password managers also have breach monitoring built in, which checks your saved logins automatically.

Is it safe to type my email into a checker like that?

With an established service, yes. Never type your password into one. A legitimate checker only asks for your email address. Have I Been Pwned checks passwords in an anonymized way that never sends the password itself.

My account is in a breach – does that mean it is hacked?

Not necessarily. A hit means your data leaked from some provider. The real danger is reusing that password elsewhere. Change it everywhere you used it and turn on two-factor authentication.

Topics: Identity, Data Breach