Data breaches happen constantly, at companies you've trusted with your information without ever hearing about it — until, sometimes, you do. Checking whether your own accounts show up in known breaches takes a couple of minutes and tells you exactly where you're exposed.
Use a reputable breach-checking site
Sites like Have I Been Pwned let you enter an email address and see which known data breaches included that address, along with what type of data was exposed (passwords, names, phone numbers, etc.) in each one. This is free, doesn't require creating an account, and covers a large, continuously updated database of breaches.
Check your passwords too, not just your email
Some breach-checking tools also let you check whether a specific password has appeared in known breach data, without sending your actual password anywhere insecurely — legitimate tools use techniques that check this without transmitting the raw password. If a password you're using shows up, treat it as compromised and change it everywhere you've reused it, immediately.
Built-in browser and password manager checks
Chrome, Safari, and Firefox all have a built-in "check passwords" or "breach alert" feature that compares your saved passwords against known leaked credential lists and flags matches automatically. If you use a dedicated password manager (see our guide on setting one up), most include this same kind of breach monitoring built in, often checking continuously rather than requiring you to check manually.
What to actually do if you're in a breach
- Change the password immediately — for the breached account and anywhere else you reused that same password.
- Turn on two-factor authentication if it isn't already enabled for that account — see our guide on setting up 2FA properly.
- Check what type of data was exposed — a breach exposing only email addresses is less urgent than one exposing passwords or financial details; breach-checking sites usually specify this.
- Watch for follow-up phishing — breached data is often used to craft more convincing phishing attempts referencing real account details; see our phishing guide for what to watch for.
Why reused passwords make one breach into many
The real danger of a breach usually isn't the breached account itself — it's that a leaked password gets tried against your other accounts automatically, a technique called credential stuffing. If you've reused a leaked password anywhere else, those accounts are now at risk too, even though they weren't part of the original breach at all. This is the single biggest reason unique passwords per account matter more than password complexity alone.
Quick checklist
- Check your email against a reputable breach database periodically.
- Check whether any current passwords appear in known breach data.
- Change compromised passwords immediately, everywhere they're reused.
- Enable two-factor authentication on any account involved in a breach.
- Stay alert for phishing attempts referencing details from a breach.