Breaches and leaked data

How to check if your email or password has been leaked

How to check whether your email address or password appears in a known data breach, which checking tools cover what, how to test a password without ever sending it, and how to read the results.

Updated October 202611 min readFree to read, no signup

If you have used the same email address for more than a few years, the realistic assumption is that it appears in multiple breaches already. That is not alarmism — it is arithmetic, given how many companies have been breached. The useful questions are narrower: which breaches, whether a password came with it, and whether that password is still protecting anything. This guide answers all three, and shows you how to check a password without ever sending it to anyone.

Five different things get called a leak

The word covers very different events with very different consequences. Knowing which one you are looking at tells you how urgently to act.

TypeWhat happenedHow bad
Breach with credentialsA company was compromised and the attacker took the user table, including password hashes. If the hashing was weak, plaintext passwords follow.Highest. Change that password everywhere you used it, immediately.
Breach without credentialsPersonal data taken — name, address, phone, date of birth — but no passwords.Serious for identity fraud and phishing, not an account-takeover risk by itself.
CombolistA compiled file of email and password pairs assembled from many older breaches and recirculated under a new name.Treat as credentials exposed, but the underlying breach is usually old.
Infostealer logsMalware on someone device harvested saved passwords, cookies and session tokens straight from the browser.Highest, and distinct: session tokens let an attacker in without the password. Rotating the password is not enough — sign out all sessions too.
Scraped dataPublic profile fields collected in bulk from a platform. Nothing was hacked; the data was already visible.Low for takeover, real for phishing and doxxing, since it links your handle to your email or phone.

Where to check, and what each source actually covers

No single source has everything. Breach corpora are assembled from what has been published or traded, so coverage differs and none of them can see a breach that has not surfaced yet.

ToolChecksWorth knowing
Have I Been PwnedEmail address, phone number, and your whole domain if you own oneThe reference corpus for this whole field, run by Troy Hunt, and what most other tools query underneath. Free, no account needed to check an address.
Google Password CheckupEvery password saved in Chrome or Google Password ManagerAt passwords.google.com/checkup. Flags compromised, reused and weak passwords in one pass. Only covers what you saved to Google.
Apple Security RecommendationsEvery password in iCloud KeychainSettings, then Passwords, then Security Recommendations on iOS, or the Passwords app. Same idea, same limitation.
Your password managerYour whole vault1Password Watchtower, Bitwarden reports, Dashlane and Proton Pass all run breach checks against your saved entries. The most complete option if your vault is complete.
HIBP Pwned PasswordsA single password, without transmitting itSee the section below. This is the one to use if you want to test a password you are still relying on.

Check every address, not just the main one

the_check

  1. 01

    List every email address you have ever used

    Current personal, old personal, university, work addresses from previous jobs, the throwaway you used for one purchase, and any alias or plus-address. Breaches are tied to the address that was registered, so checking only your current one tells you almost nothing about fifteen years of signups.

  2. 02

    Check each one against Have I Been Pwned

    Enter the address, read the full list of breaches it appears in, and note the date and the data classes for each. Repeat for every address on your list. If you own a domain, the domain search covers every address on it at once.

  3. 03

    Check your phone number as well

    Several large incidents were phone-number-keyed rather than email-keyed. HIBP supports number lookups, and a hit here is why you suddenly started getting targeted SMS phishing.

  4. 04

    Run the password audit in whatever stores your passwords

    Google Password Checkup, Apple Security Recommendations, or your password manager report. This is the step that turns "my address is in a breach" into "this specific password is compromised and still in use on four sites".

  5. 05

    Write down which passwords need rotating

    Before you change anything, note every account that used a compromised password. Start the rotation with your email account, because it is the reset route for everything else, then anything financial, then the rest.

  6. 06

    Turn on notification for future breaches

    Subscribe to HIBP notifications for each of your addresses. You will be told when a new corpus containing one of them is loaded, which is considerably better than finding out from a password reset you did not request.

How to check a password without sending it anywhere

It sounds like a contradiction, and it is the most reassuring piece of engineering in this whole field. The HIBP Pwned Passwords API uses a technique called k-anonymity, and it means the service never learns your password or even its full hash.

  1. Your browser or password manager computes the SHA-1 hash of the password locally.
  2. It sends only the first five characters of that hash to the API.
  3. The API returns every hash in the corpus beginning with those five characters — typically a few hundred of them.
  4. Your device compares the rest of your hash against that list locally. If it matches, the password is in a known breach.

The service sees a five-character prefix shared by hundreds of thousands of passwords. It cannot tell which one was yours, and it never receives the password. This is why the breach checks built into Chrome, Apple Passwords and the major password managers are safe to use on passwords you are still relying on.

Reading the result properly

A breach listing tells you three things, and people usually only read the first.

  • Which company and when. A 2013 breach of a service you abandoned in 2014 is mostly a historical note. A breach dated last month at something you use daily is tonight problem.
  • The data classes. This is the part that matters. "Email addresses, passwords" is an urgent, specific instruction to rotate that credential. "Email addresses, names" is a phishing risk. "Email addresses, physical addresses, dates of birth, partial card numbers" is identity-fraud territory and worth a credit freeze.
  • Whether it is marked unverified or sensitive. Unverified means the corpus could not be confirmed as genuine — it may be recycled or fabricated. Sensitive breaches are excluded from public search precisely because mere membership is damaging, so they only appear for addresses you have verified you control.

What a listing never means is that the company lied to you or that your current password is broken. If you changed that password after the breach date, that particular exposure is already closed. The hours after you find something are covered in what to do after a data breach.

Why you can appear in a breach you never signed up for

  • A vendor, not the brand. Companies hand your details to payroll providers, email platforms, support desks and analytics firms. When one of those is breached, your data goes with it under a company name you have never dealt with.
  • An employer or school. Staff and student directories end up in breaches of the institution systems.
  • A data broker. Brokers assemble records on people who never interacted with them. When a broker is breached — and several large ones have been — everyone in their database is exposed. See the data broker opt-out list.
  • Someone else uploaded you. A contact list sync carries your name, number and email into a service you never touched.
  • Scraping, not hacking. Your public profile fields were collected in bulk. Nothing was compromised, but the result is a file linking your handle to your contact details.

What Tracebase adds to a breach check

If all you want is a breach check, go straight to Have I Been Pwned. It is free, it is the reference source, and we query the same corpus — there is no version of this where we tell you to pay us for something you can get for nothing.

What we add is the other half of the question. A breach check tells you a company you used was compromised. It cannot tell you which accounts you have, and that is usually the thing you actually need, because you cannot rotate a password on an account you have forgotten exists. Tracebase runs account discovery across supported platforms using your emails and usernames, and puts the breach records next to it, so one list answers both questions and carries the removal steps for the platforms we have documented.

One constraint to be aware of: we only run breach lookups against an email address after you have confirmed a six-digit code sent to it. We are not willing to report breach history for an address somebody has merely typed in. Usernames need no verification, because account discovery works from public profiles.

common_questions

Is Have I Been Pwned safe to use?

Yes. It is the long-standing reference source in this field, it is free, and it is what a great many commercial tools query underneath. Checking an email address reveals nothing an attacker does not already have, and the password check never transmits your password — only a five-character hash prefix.

My email is in a breach. Does that mean I was hacked?

No. It means a company holding your address was compromised. Your own accounts and devices may be perfectly fine. It becomes your problem specifically when the breach included a password you reused elsewhere, or when it exposed enough personal data to power convincing phishing or identity fraud.

How do I find out which password was leaked?

Breach listings do not show you the password — reputable sources deliberately never publish it. Use the password audit in your browser or password manager instead: it compares your actual saved passwords against the breached corpus and names the ones that match. That tells you which credential to rotate and where you reused it.

Should I change my email address after a breach?

Rarely worth it. Migrating every account and contact is a large job and the new address joins the next breach eventually. The thing that mattered was the password. If the address itself has become a spam magnet, the better move is aliases for new signups, so the next leak only burns one disposable address.

How often should I check?

Subscribe to notifications once and you will be told, rather than having to remember. Beyond that, a manual sweep of every address you own once a year is plenty — pair it with the signup audit in how to find every account linked to your email.

Can I get my data removed from a breach?

No. Breached data is copied, traded and archived by many parties within hours, and there is no mechanism to recall it. You can get the company to delete its live record of you going forward, which is worth doing, but the leaked copy is permanent. This is why rotating credentials beats trying to undo the exposure.

What is the difference between a breach and dark web monitoring?

A breach check matches your address against known, dated incidents and names them. Dark web monitoring is a marketing term for watching forums and paste sites for your details, and the quality varies enormously — some is genuine ongoing surveillance, some is a breach lookup with a more dramatic label. Ask any provider which corpora they actually search.

Keep reading

Rather not do this by hand?

Tracebase takes your email addresses and usernames, checks supported platforms for matching accounts, cross-references the public breach corpus, and hands you the removal steps for what it finds.

Start a scan

No account passwords needed · How Tracebase works →