Independent, practical guides for a better digital life.
Tech Tutorials

How to Check If Your Email Was in a Data Breach

Check whether your email appears in a known breach, understand what the result means, and secure affected accounts without sharing your password.

Paper-craft email breach check with an envelope, exposed database record, magnifier, and account shield

An unexpected password reset message or breach notice can make it feel as though your inbox has already been taken over. That is not always what happened. An email address may appear in a breached database even when the email account itself remains secure. The right response is to identify what was exposed, protect the affected accounts, and watch for follow-up scams.

This guide shows how to check if your email was in a known data breach without entering your password into a lookup site. It also explains what a positive result means, what a negative result cannot prove, and which recovery steps deserve priority.

Understand the three different problems

People often use "hacked email" to describe several events. They need different responses.

The first is an exposed address. A breached service may have leaked your email address along with a name, username, or other profile data. Criminals can use that address for phishing or credential-stuffing attempts, but the leak does not prove that they can open your inbox.

The second is an exposed password. If the affected service stored a password or password hash that was later cracked, any account where you reused that password is at risk. Changing only the breached service is not enough.

The third is an actively compromised inbox. Warning signs include messages you did not send, forwarding rules you did not create, recovery details you do not recognize, sign-ins from unfamiliar devices, missing email, or reset notices for other accounts. An inbox compromise is urgent because email is often the recovery route for banking, shopping, social, cloud, and work accounts.

Keep those distinctions in mind while you check the address.

Prepare before using a breach checker

Use a device and network you trust. Update the browser and operating system. If the device is behaving strangely, opening unknown pages, or showing repeated security warnings, first review how to check for signs of a compromised phone.

Never enter your email password into a public breach lookup form. A legitimate address search only needs the email address. Do not upload a password list, identity document, recovery code, or one-time verification code.

Open the service by typing its known address or following a trusted reference. Search ads and copied links can lead to lookalike pages. For this guide, the lookup service is Have I Been Pwned, commonly shortened to HIBP.

Check your address with Have I Been Pwned

Open the HIBP homepage and enter the email address you want to check. Select the search button. The result shows whether that address appears in breach datasets loaded into the service.

If the result is positive, read each listed incident instead of reacting only to the total. Note the breached organization, incident date, date added to HIBP, and the categories of exposed data. An incident may include only email addresses, or it may include passwords, phone numbers, physical addresses, security questions, purchase history, dates of birth, or other data.

The incident date and public disclosure date can be far apart. You may already have changed the password since the breach. Check your password manager or account records rather than assuming the current password was exposed.

HIBP also labels some sensitive breaches differently and may require address verification before showing them. Follow the service's current instructions. Do not use someone else's address to investigate private breach details without permission.

What a positive breach result means

A positive match means the address appeared in at least one dataset HIBP has loaded. It does not prove that your inbox is currently open to an attacker. It also does not identify who downloaded the data or whether every exposed field is still accurate.

Treat the listed data classes as a recovery map. If a password was involved, change the affected password and every place it was reused. If a phone number and name were involved, expect more convincing messages or calls. If security questions were exposed, replace those answers where services still use them.

If financial or identity information was exposed, follow the notification from the organization and current government guidance. The United States Federal Trade Commission provides a recovery process through IdentityTheft.gov. Readers in other countries should use their national consumer protection or cybercrime authority.

What a negative result does not mean

A negative HIBP result means the address was not found in the datasets available to that service at the time of the search. It does not prove the address has never appeared in a breach, private leak, malware log, phishing list, or dataset that has not been added.

Continue if you have direct signs of compromise. A legitimate sign-in alert, changed recovery address, unexplained forwarding rule, or message you did not send matters more than a negative public lookup.

Do not use repeated searches as a substitute for account security. Strong unique authentication and account monitoring protect you before a future dataset becomes public.

Change reused passwords first

Start with the affected service. Sign in through its official app or typed website address. Change the password, sign out other sessions if that option exists, and review the account's recovery email, phone number, connected apps, and recent activity.

Next, find every account where you used the same or a closely related password. Attackers test leaked credentials on popular email, shopping, social, gaming, and financial services. This is called credential stuffing.

Create a different password for each remaining password-based account. A reputable password manager can generate and store long random passwords. Do not make a family of predictable variations such as changing one number at the end.

Where supported, consider switching important accounts to passkeys. Our guide explains how to use passkeys safely, including recovery and device access considerations.

Secure the email account itself

Even if the breach involved another service, protect the inbox because it controls many password resets.

Change the email password if it was reused, weak, or entered on a suspicious page. Enable multifactor authentication or a passkey using the provider's official security settings. Prefer an authenticator app, passkey, or hardware security key when available. SMS is still better than no second factor, but phone-number takeover can affect SMS codes.

Review recent sign-ins and connected devices. Sign out sessions you do not recognize. Check recovery phone numbers and addresses. Remove old methods you no longer control, but keep at least one secure recovery route.

Inspect forwarding rules, filters, delegates, app passwords, and connected applications. An attacker may add a quiet forwarding rule and leave the main password unchanged. Remove anything unfamiliar and save a record before deletion if your organization needs evidence.

Check the Sent, Trash, Archive, and Spam folders for activity you did not initiate. Tell contacts if your account sent malicious messages, but do not forward the malicious link.

The FTC's hacked account recovery guidance recommends using the provider's recovery process, changing passwords, signing out other devices, enabling two-factor authentication, and checking recovery information.

Protect accounts connected to the inbox

Make a short list of high-impact accounts that use this address: banking, payments, government, work, cloud storage, shopping, social media, domain registration, and password management.

Do not reset all of them through links in an unexpected breach email. Open each important service independently. Review recent transactions, login activity, contact information, recovery settings, and authorized apps.

If the exposed information included payment data, contact the financial institution using the number on the card or its official app. If a government identifier or enough personal data for identity fraud was exposed, follow official identity-theft guidance. A credit freeze can be appropriate for identity exposure in some countries, but it is not a necessary response to every email-only leak.

Watch for breach-related phishing

After a public incident, scammers send messages that mention the breached company and create urgency. They may claim that you must verify a password, pay a fee, call a fake number, or open an attached report.

Treat the breach notice as information, then navigate to the company's official site yourself. Compare the sender's domain carefully, but remember that a familiar sender name can be forged. Do not share a one-time code with someone who contacts you.

Messaging accounts can also receive follow-up scams. Review the steps to secure messaging accounts from scams, especially unknown links and verification-code requests.

Set up breach notifications

HIBP offers verified notifications through its Notify Me service. Enter the address and complete the verification sent to that inbox. Notifications can alert you when the address appears in a newly loaded breach.

Use a notification as a starting point, not proof that every message mentioning a breach is genuine. Return to the known site or the affected organization's official notice. Check the data classes and incident date before deciding what to change.

Your email provider, password manager, browser, or security software may also offer breach monitoring. Understand what each service checks and where it stores the address. Avoid installing multiple unknown monitoring extensions.

Check devices and saved credentials

If you entered a password into a phishing page or installed an attachment, changing the password may not be enough. Update the device, run its built-in or trusted security scan, and remove software or browser extensions you do not recognize.

Review saved passwords for reused or compromised credentials. Major password managers and browsers can flag known exposures. Use the feature inside the manager or browser, not a pop-up that asks you to export all passwords.

On Android, review the privacy settings worth changing and check which apps can read notifications, accessibility data, files, and SMS. An app with broad access can capture information even after an account password changes.

A prioritized recovery checklist

Use this order when an email address appears in a breach:

  1. Read the incident details and exposed data classes.
  2. Open the affected service independently.
  3. Change an exposed or reused password.
  4. Change the same password everywhere else it was used.
  5. Enable a passkey or multifactor authentication.
  6. Review email sessions, forwarding rules, recovery methods, and connected apps.
  7. Review high-impact accounts linked to the inbox.
  8. Follow official identity or financial recovery guidance when sensitive data was exposed.
  9. Scan a device if a suspicious link, attachment, or app was involved.
  10. Enable verified breach notifications and watch for follow-up phishing.

Keep notes of what you changed and when. If you lose access during recovery, use the provider's official account-recovery page rather than paying a third party that promises access.

Keep the result in proportion

A breach result is useful because it replaces a vague fear with specific information. The listed incident and data classes tell you where to focus. A leaked address alone calls for caution around phishing. A reused password calls for immediate credential changes. An actively compromised inbox calls for full recovery and review of connected accounts.

The safest long-term setup is simple: unique authentication for every account, a strong recovery plan, a protected inbox, and alerts you can verify through official channels. Public breach searches are one part of that system, not a guarantee that an account is safe.

Reader answers

Frequently asked questions

Open a question to read the answer. Opening another answer closes the previous one.

How can I check if my email was in a data breach?

Open Have I Been Pwned by typing its official address, enter only the email address, and review each listed breach. Never provide the email password, recovery code, or one-time verification code to a lookup form.

Is Have I Been Pwned safe to use?

Its public email search requires an address, not a password. Use the official domain, read the listed data classes carefully, and remember that no public checker contains every private or undisclosed breach.

Should I enter my password into a breach checker?

No. A legitimate email-address breach search does not need your password. If a page requests a password, recovery code, identity document, or one-time code, leave it and open the known official service independently.

What does a positive breach result mean?

It means the address appears in a dataset loaded by the service. Read which organization and data classes were involved. The result alone does not prove that someone currently controls your inbox.

Does a negative result mean my email is completely safe?

No. It means the address was not found in the datasets available to that checker at that time. Private leaks, malware logs, recent incidents, and undisclosed breaches may not appear there.

Should I change every password after an email breach?

Change the affected password and every account that reused it. Unique passwords prevent one leaked credential from opening several services. Also review sessions, recovery details, forwarding rules, and multifactor authentication.

What if I reused the exposed password on other accounts?

Prioritize email, banking, payments, cloud storage, social accounts, and password management. Open each service directly, replace the reused password, sign out unfamiliar sessions, and review account recovery information.

Can I get alerts about future email breaches?

Yes. Have I Been Pwned offers verified notifications. Enter the address on its Notify Me page, open the verification message sent to that inbox, and complete the confirmation process.

What is the difference between a leaked email and a hacked inbox?

A leaked address appeared in another service's exposed data. A hacked inbox shows unauthorized access, such as unknown sign-ins, sent messages, forwarding rules, recovery changes, or password resets you did not request.

When should I freeze my credit after a data breach?

Consider a credit freeze when sensitive identity or financial information may have been exposed, not for every email-only leak. Follow the affected organization's notice and your country's official identity-theft guidance.