Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Guides

How to check if your email was in a data breach

Free tools like Have I Been Pwned show which breaches include your email or phone number. Here is how to use them and what to do next.

By · Published · Updated · 10 min read

How to check if your email was in a data breach

With breaches reported almost daily, it is worth checking which of them include your details.

Have I Been Pwned

Have I Been Pwned, run by security researcher Troy Hunt, is the best-known free breach checker. Type your email address and it lists every known breach that includes it, plus what types of data were exposed.

You can also:

  • Sign up for alerts so you are emailed when your address appears in a new breach.
  • Check passwords with its Pwned Passwords tool, which checks without sending your full password.

How big is Have I Been Pwned?

Have I Been Pwned has grown enormously since Troy Hunt launched it as what he has called "a little pet project" roughly a decade ago, starting with 154 million breached records loaded in (Troy Hunt). As of late September 2026, the service listed over 1,038 total breaches covering more than 17.8 billion pwned email addresses (Have I Been Pwned). Hunt passed the milestone of loading the service's 1,000th breach in 2026, reflecting on how, despite the rise of privacy regulations like GDPR, the service remains as necessary as ever — partly because, as he has written, disclosure lag between when a breach happens and when it becomes public has in some cases gotten worse, not better (Troy Hunt).

Other ways to check

  • Google Password Manager and Apple Passwords warn you when saved passwords appear in breaches.
  • Most password managers, such as Bitwarden and 1Password, include breach reports.
  • Some banks and email providers offer dark web monitoring.

What to do if you are listed

  1. Change the password for that site and anywhere you reused it.
  2. Turn on multi-factor authentication, or a passkey where available.
  3. If financial or ID data was exposed, freeze your credit — see our credit freeze guide.
  4. Watch for phishing that uses details from the breach.

A word of caution

Only enter your email into well-known services. Some fake "breach checkers" exist just to collect email addresses for spam and phishing.

Understanding your results

Seeing your email in a long list of breaches can be alarming, but not every entry carries the same risk. Pay attention to what was exposed:

  • Email only: expect more spam and phishing.
  • Passwords: urgent if you still use that password anywhere.
  • Phone numbers and addresses: raises the risk of targeted scams and SIM swap attempts.
  • ID numbers, financial or health data: the most serious — consider a credit freeze and extra monitoring.

Many breaches are years old. If you have changed your passwords since then, an old listing may matter less — but the personal details exposed in it do not expire.

Why disclosure can take so long

One of the lesser-known problems Troy Hunt has written about is how long it can take for a breach to become public knowledge even after attackers have already started exploiting it. He has pointed to cases where data stolen by extortion groups using "pay or leak" tactics — threatening to publish data unless a ransom is paid — sits in criminal hands for days before public disclosure, and even after a public leak, data may already have been copied and re-shared across hacking forums, Telegram channels and other platforms well before most victims learn anything happened (Troy Hunt). This is part of why regularly checking breach-notification services yourself, rather than waiting for a company's official notice, can help you react sooner.

Stopping the same problem next time

  • Use a password manager so every site gets a unique password. Then one breach cannot unlock your other accounts.
  • Use email aliases for shopping and newsletters, so breached addresses do not lead back to your main inbox.
  • Give companies the minimum details they need.

Breached data and data brokers

Details leaked in breaches often end up combined with information collected by data brokers, who build and sell profiles with your name, address, phone number and relatives. You can ask brokers to delete your data yourself, or use a data removal service to send requests on your behalf. Our guide to how data removal services work explains the options.

What readers should do

  1. Check all of your email addresses, not just your primary one — Have I Been Pwned lets you check as many as you like, and old addresses you no longer actively use may still be linked to active accounts.
  2. Sign up for free breach notifications on Have I Been Pwned so you learn about new incidents automatically, rather than relying on company notification emails that can arrive weeks or months after a breach is discovered.
  3. Prioritize action by data sensitivity, not by the number of breaches you appear in — one breach that exposed your ID number or password matters far more than ten breaches that exposed only your email address.
  4. Re-check periodically. New breaches, including old ones only recently discovered or disclosed, are added to breach-checking services on an ongoing basis, so a clean result today does not guarantee a clean result in six months.
  5. Treat any "breach checker" you have not heard of with suspicion — stick to well-known, established services rather than random sites that ask for personal details beyond your email address.

Sources

How Have I Been Pwned actually works

Have I Been Pwned does not scan the internet in real time when you type your address. Instead, Troy Hunt and his team ingest breach data — usually obtained from security researchers, journalists or the criminal forums where stolen databases get traded and dumped — and load it into a searchable index of email addresses tied to specific, named breaches. When you search your address, the site tells you which of those pre-loaded breaches include it and, crucially, what categories of data each breach exposed, from email addresses alone up to passwords, physical addresses or government ID numbers.

This design has two practical implications for readers. First, a breach has to be publicly known and processed before it shows up, so a brand-new or still-secret breach will not appear on the service immediately. Second, because the underlying data comes from so many different sources and incidents spanning over a decade, the site has become something close to a historical record of the data breach era rather than a single live monitoring tool — which is part of why Hunt has described hitting symbolic milestones, such as loading the service's 1,000th breach, as notable moments in its own right.

The scale problem regulators have not solved

Despite GDPR, US state breach-notification laws, and similar rules elsewhere requiring companies to disclose breaches, Troy Hunt has argued that the practical gap between when an intrusion happens and when the public learns about it has, if anything, worsened in some cases rather than improved. He attributes part of this to the rise of "pay or leak" extortion tactics, where criminal groups steal data and threaten publication unless paid, meaning the data may already be circulating in criminal circles — sometimes for weeks — well before any official notification reaches affected individuals (Troy Hunt). That dynamic is one of the clearest practical arguments for checking breach databases proactively yourself, rather than relying solely on companies to tell you when your information has been exposed.

Email aliases as an extra layer

Beyond password managers, many privacy-conscious users now rely on email aliasing services (built into some email providers, or offered by dedicated tools) that let you generate a unique, disposable email address for every website or service you sign up for. If one of those aliases later turns up in a breach, you immediately know which company leaked it, and you can simply disable that one alias without having to change your real email address everywhere else it is used. This also limits the ability of data brokers and marketers to link a single leaked address back to your full online identity.

Sources

Read next