Skip to content
Tuesday, September 8, 2026
BLOGDAILYGADGETS · APPS · REVIEWS
Home / Guides
Guides

How to Check if Your Data Was Exposed in a Breach — and What to Do Next

Your email address has almost certainly appeared in a breach — checking takes 30 seconds, and the fix list is short: passwords first, then 2FA, then card replays.

William Elliott, · March 22, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
Laptop showing breach-check result page at home desk
How to Check if Your Data Was Exposed in a Breach — and What to Do Next | AI-generated illustration

Check first, panic never: enter your email address at a breach-notification service — haveibeenpwned.com is the widely cited free option — and it lists every documented breach your address appears in, from mega-hacks like Collection #1 (773 million addresses) to single-site spills. If your address shows up, the response has a strict order: change that password where you used it (and everywhere you reused it), turn on two-factor authentication, watch the card you used there. The catch: past breaches can't be undone — the work is making the leaked data worthless.

How do these checkers know?

Breach databases come from publicly documented incidents — law-enforcement actions, security-researcher disclosures, and dumps posted by attackers themselves. Have I Been Pwned, run by security researcher Troy Hunt, documents its sources per breach on each listing page. It shows only breaches that are public; a site that's been breached quietly won't appear, which is why the checklist below matters even when the result is "no pwnage found."

What does exposure actually cost you?

Related stories: How to Tell if a Website Is Secure Before You Enter Your Card Details · How to Recycle Old Phones, Tablets and Cables the Right Way.

The response checklist, in order

  1. Change the breached password everywhere it was reused — a password manager makes "everywhere" one afternoon instead of one weekend (see password-manager coverage elsewhere on Blog Daily).
  2. Turn on 2FA for email, banking and shopping first — email above all, because email resets everything else.
  3. Check card statements for the payment method used with breached services; dispute anything unfamiliar — the FTC documents this reporting path.
  4. Expect targeted phishing: a breach that includes your order history will produce convincing fake emails quoting it. Verify by going to the site directly, never through the link.
  5. For SSN exposure: the documented Federal Trade Commission identity-theft page walks through credit freezes at the three bureaus — free, and stronger than monitoring.

Should you pay for breach-monitoring services?

The documented free tools cover most needs: breach lookups, your card issuers' own alerts, and free credit reports from the three bureaus via the government-authorized annualcreditreport.com. Paid identity-protection services add insurance and recovery help — reasonable if your exposure was severe (SSN, medical, financial accounts), documented overkill for a single forum password from 2017 that you've already changed.

The habit that beats every checker

Unique password per account in a manager, 2FA on everything that matters, quarterly breach check — fifteen minutes of maintenance that makes each new headline someone else's problem.

FAQ

Frequently Asked Questions

How do I check if my information was in a data breach?
Enter your email at a breach-notification service like haveibeenpwned.com, which lists the documented breaches containing your address, with sources per incident. It covers only public breaches — so practice good hygiene regardless of the result.
What should I do first after a breach?
Change the breached password everywhere you reused it, enable two-factor authentication starting with email, and monitor the card used with that service. Reused passwords are how one breach becomes many.
Is it worth paying for identity-theft protection?
For severe exposure (SSN, financial accounts), paid services' insurance and recovery help are documented value. For routine breaches, free tools — breach lookups, issuer alerts, annualcreditreport.com — cover the essentials.

Sources

  1. Federal Trade Commission identity theft guidanceFederal Trade Commission identity theft guidance