Mailfornet

How to know if your email was leaked in a data breach

Here's an uncomfortable fact to start with: if you've had the same email address for more than a few years, it has almost certainly been leaked at least once. Large, well-known companies have been breached, as well as thousands of small forums, shops and apps that most people have forgotten they ever signed up for.

That sounds alarming, but a leaked email address on its own is not a disaster. What matters is what else leaked with it, and whether you've left any doors open. This guide shows how to find out, and what to do about it.

What a data breach actually is

A data breach happens when someone gets unauthorised access to a company's user database and copies it. The stolen data usually includes email addresses, and often some combination of names, usernames, passwords, phone numbers, dates of birth and addresses.

The copied databases are then sold, traded or eventually dumped publicly. Over the years, many breaches have been combined into huge compilation lists with billions of entries. These lists are the raw material for spam, phishing and account takeover attacks.

How to check if your email was leaked

Have I Been Pwned

The best-known free tool is Have I Been Pwned (haveibeenpwned.com), run by security researcher Troy Hunt since 2013. Type in your email address and it lists every known breach that included it, with the date and the type of data exposed.

You can also sign up for free notifications, so you'll get an email if your address appears in a future breach. Many password managers and browsers use its data behind the scenes.

Your browser and password manager

  • Google Password Manager (in Chrome and Android) has a Password Checkup that flags saved passwords that appeared in breaches.
  • Apple's Passwords app on iPhone and Mac shows security recommendations for compromised passwords.
  • Mozilla Monitor from the makers of Firefox checks your email against known breaches.
  • Most dedicated password managers, like Bitwarden and 1Password, include a similar breach report.

Emails from the company itself

In many countries, companies must notify users after a serious breach. Take these emails seriously, but be careful: scammers send fake breach notifications too. Rather than clicking the link in the email, go to the company's website yourself to read their statement and change your password.

What your results mean

Most breach checkers tell you which types of data were exposed. That's what determines your risk:

What leakedThe riskWhat to do
Email address onlyMore spam and phishingBe alert to scam emails; nothing urgent
Email + passwordAccount takeover wherever you reused that passwordChange that password everywhere it was used, today
Name, phone, addressMore convincing, personalised scams, including by phone and textBe suspicious of anyone who "already knows" your details
Date of birth, security answersIdentity checks and account recovery can be abusedChange security questions; use made-up answers stored in a password manager
Payment or ID detailsFraud and identity theftContact your bank; consider a credit freeze where available

A word about "hashed" passwords

Breach reports sometimes say passwords were "hashed" or "encrypted". This means they weren't stored as plain text, which is good, but it isn't a guarantee. Weak or common passwords can often be cracked from their hashes within minutes. If a breach included your password in any form, change it.

What to do now: a practical plan

  1. Change any password that leaked, on every site where you used it. Password reuse is what turns a small forum's breach into your bank account being accessed.
  2. Start using a password manager. It creates and remembers a different strong password for every site, so one breach can never unlock another account.
  3. Turn on two-step verification, starting with your email account, then banking, shopping and social media. A leaked password is useless without the second step.
  4. Watch for targeted phishing. After a breach, expect emails that mention the breached company, or use your name and old password to seem credible. The "I hacked your camera" scam is built entirely on leaked passwords. Our guide to checking whether an email is real will help.
  5. Check your email account for signs of access, such as unknown sign-ins or forwarding rules. See signs your email has been hacked.
  6. Close accounts you no longer use. Every forgotten account is another database your details are sitting in.

Should I change my email address?

Usually, no. A leaked address mostly means more spam, and spam filters handle most of it. Changing your main address means updating every account, telling every contact, and losing years of history, and the new address will eventually appear in breaches too.

A new address makes sense in a few situations: if it's receiving so much spam that real mail gets lost, if you're being targeted personally, or if you simply want a fresh start with better habits.

How to leak less in the future

You can't stop companies from being breached. You can control how much of you is in their databases.

  • Use a temporary email for one-time sign-ups. Downloads, coupons, Wi-Fi portals and sites you're only trying out don't need your real address. A disposable address that deletes itself can't be leaked in a breach five years from now.
  • Use aliases for accounts you keep. With a Gmail alias like yourname+shopname@gmail.com, you can see exactly which company leaked or sold your address, and filter it.
  • Give less information. If a field is optional, leave it empty. If a site doesn't need your real birthday, it doesn't get it.
  • Delete old accounts once a year.

The bottom line

Finding your email in a breach feels personal, but it's close to universal, and on its own it isn't an emergency. Leaked passwords are what cause real damage, and they're easy to neutralise: a unique password for every site, two-step verification on the accounts that matter, and a healthy suspicion of emails that seem to know a little too much about you.