How to know if your email was leaked in a data breach
Here's an uncomfortable fact to start with: if you've had the same email address for more than a few years, it has almost certainly been leaked at least once. Large, well-known companies have been breached, as well as thousands of small forums, shops and apps that most people have forgotten they ever signed up for.
That sounds alarming, but a leaked email address on its own is not a disaster. What matters is what else leaked with it, and whether you've left any doors open. This guide shows how to find out, and what to do about it.
What a data breach actually is
A data breach happens when someone gets unauthorised access to a company's user database and copies it. The stolen data usually includes email addresses, and often some combination of names, usernames, passwords, phone numbers, dates of birth and addresses.
The copied databases are then sold, traded or eventually dumped publicly. Over the years, many breaches have been combined into huge compilation lists with billions of entries. These lists are the raw material for spam, phishing and account takeover attacks.
How to check if your email was leaked
Have I Been Pwned
The best-known free tool is Have I Been Pwned (haveibeenpwned.com), run by security researcher Troy Hunt since 2013. Type in your email address and it lists every known breach that included it, with the date and the type of data exposed.
You can also sign up for free notifications, so you'll get an email if your address appears in a future breach. Many password managers and browsers use its data behind the scenes.
Your browser and password manager
- Google Password Manager (in Chrome and Android) has a Password Checkup that flags saved passwords that appeared in breaches.
- Apple's Passwords app on iPhone and Mac shows security recommendations for compromised passwords.
- Mozilla Monitor from the makers of Firefox checks your email against known breaches.
- Most dedicated password managers, like Bitwarden and 1Password, include a similar breach report.
Emails from the company itself
In many countries, companies must notify users after a serious breach. Take these emails seriously, but be careful: scammers send fake breach notifications too. Rather than clicking the link in the email, go to the company's website yourself to read their statement and change your password.
What your results mean
Most breach checkers tell you which types of data were exposed. That's what determines your risk:
| What leaked | The risk | What to do |
|---|---|---|
| Email address only | More spam and phishing | Be alert to scam emails; nothing urgent |
| Email + password | Account takeover wherever you reused that password | Change that password everywhere it was used, today |
| Name, phone, address | More convincing, personalised scams, including by phone and text | Be suspicious of anyone who "already knows" your details |
| Date of birth, security answers | Identity checks and account recovery can be abused | Change security questions; use made-up answers stored in a password manager |
| Payment or ID details | Fraud and identity theft | Contact your bank; consider a credit freeze where available |
A word about "hashed" passwords
Breach reports sometimes say passwords were "hashed" or "encrypted". This means they weren't stored as plain text, which is good, but it isn't a guarantee. Weak or common passwords can often be cracked from their hashes within minutes. If a breach included your password in any form, change it.
What to do now: a practical plan
- Change any password that leaked, on every site where you used it. Password reuse is what turns a small forum's breach into your bank account being accessed.
- Start using a password manager. It creates and remembers a different strong password for every site, so one breach can never unlock another account.
- Turn on two-step verification, starting with your email account, then banking, shopping and social media. A leaked password is useless without the second step.
- Watch for targeted phishing. After a breach, expect emails that mention the breached company, or use your name and old password to seem credible. The "I hacked your camera" scam is built entirely on leaked passwords. Our guide to checking whether an email is real will help.
- Check your email account for signs of access, such as unknown sign-ins or forwarding rules. See signs your email has been hacked.
- Close accounts you no longer use. Every forgotten account is another database your details are sitting in.
Should I change my email address?
Usually, no. A leaked address mostly means more spam, and spam filters handle most of it. Changing your main address means updating every account, telling every contact, and losing years of history, and the new address will eventually appear in breaches too.
A new address makes sense in a few situations: if it's receiving so much spam that real mail gets lost, if you're being targeted personally, or if you simply want a fresh start with better habits.
How to leak less in the future
You can't stop companies from being breached. You can control how much of you is in their databases.
- Use a temporary email for one-time sign-ups. Downloads, coupons, Wi-Fi portals and sites you're only trying out don't need your real address. A disposable address that deletes itself can't be leaked in a breach five years from now.
- Use aliases for accounts you keep. With a Gmail alias like
yourname+shopname@gmail.com, you can see exactly which company leaked or sold your address, and filter it. - Give less information. If a field is optional, leave it empty. If a site doesn't need your real birthday, it doesn't get it.
- Delete old accounts once a year.
The bottom line
Finding your email in a breach feels personal, but it's close to universal, and on its own it isn't an emergency. Leaked passwords are what cause real damage, and they're easy to neutralise: a unique password for every site, two-step verification on the accounts that matter, and a healthy suspicion of emails that seem to know a little too much about you.