Data breaches have become an unavoidable reality of digital life. As of 2026, Have I Been Pwned’s database contains over 13 billion account records from more than 700 known breach events. This means that if your email address exists on the internet, there is a strong chance it has appeared in a compromised service at some point.
The problem is that most people have no idea they have been affected. A breach from 2015 remains a genuine threat today if you never changed your password. Attackers use a technique called “credential stuffing,” where email and password combinations leaked from one service are automatically tested against dozens of others—because over 65% of people reuse the same password across multiple platforms.
The good news is that checking whether your email or password has been compromised is not complicated. Several free, secure tools can give you an answer in minutes. This guide walks you through exactly how to check your credentials, what warning signs to watch for, and what to do immediately if your data has been exposed.
Step 1: Check if Your Email Address Appears in a Breach
This is the most important first step. Your primary email address is usually your username for other services and the destination for password reset emails. If an attacker controls it, they can potentially take over almost every account you own.
Use Have I Been Pwned to Search
Have I Been Pwned (HIBP) is the most authoritative and comprehensive free breach-checking tool available, run by Australian security researcher Troy Hunt. Simply enter your email address at haveibeenpwned.com, and it will tell you:
- Whether the address appears in any known breach
- Which specific breach events are involved
- What types of data were exposed (passwords, phone numbers, addresses, etc.)
The check is completely free, and your email address is not stored.
How to Interpret the Results
If you see “Oh no — pwned!” it means your email appears in at least one known breach. Review the specific services involved and assess what data was exposed. If passwords were included, you need to act immediately.
If you see “Good news — no pwnage found!” this is a positive signal, but it does not guarantee your account is safe. HIBP only indexes known breaches, and undisclosed leaks may exist. You should still use strong passwords and enable two-factor authentication.
Enable Continuous Monitoring
HIBP offers a free notification service. Once you register, you will automatically receive an alert if your email address appears in a future breach. This is a “set it once and forget it” action that every user should complete.
Check Every Email Address You Own
Most people have multiple email addresses—work, personal, and various backup accounts used for signups. Each one needs to be checked separately. Attackers often start with an old, forgotten email address and work their way toward your primary accounts.
Step 2: Check if Your Password Has Been Leaked
Knowing whether your email was breached is only half the picture. What actually allows attackers to log into your accounts is the password.
Use Pwned Passwords to Check Individual Passwords
HIBP’s Pwned Passwords database contains over 850 million passwords exposed in data breaches. Visit haveibeenpwned.com/passwords to check whether a specific password appears in that database.
The privacy mechanism behind this check is worth understanding. It uses a technique called k-anonymity: your password is hashed locally in your browser using SHA-1, and only the first five characters of the hash are sent to the server. The server returns all hash suffixes matching that prefix, and your browser completes the comparison locally. Your full password never leaves your device.
If the result shows the password has been “seen N times,” that password must be retired immediately. The higher the number, the more people have used it, and the more likely it appears in attacker dictionaries.
Use Your Password Manager’s Built-In Breach Detection
Checking passwords one by one is inefficient. If you use a password manager, it likely has built-in bulk breach detection:
- 1Password: Watchtower scans all saved passwords and flags those found in breaches, reused passwords, and sites without 2FA enabled
- Bitwarden: Run a check under Reports → Exposed Passwords
- iOS/macOS Passwords: Settings → Passwords → Security Recommendations automatically flags passwords matching known breach data
- Google Password Manager: Android users can run Password Checkup in settings
The advantage of these built-in checks is that they also identify password reuse—the single biggest risk amplifier in any breach. If you used the same password on a shopping site as you did for your email, an attacker who obtained that password from the shopping site’s breach could try it against your email, even if your email provider itself was never compromised.
Step 3: Watch for Warning Signs of Account Compromise
Even if you have not actively checked a breach database, your accounts themselves may be sending warning signals. The following symptoms deserve immediate attention:
Suspicious Login Attempt Notifications
If you receive a login alert from your email or social platform for a time or location you do not recognize, someone is likely attempting to access your account. Do not click links in the notification email—the notification itself may be a phishing attempt. Instead, log in to your account manually and review your security settings.
Your Password Has Been Changed
If you find you cannot log in with your existing password, and repeated attempts fail, someone may have taken over your account and changed the password. In this case, immediately use the “Forgot Password” function to attempt recovery and contact the service provider.
Emails You Never Sent Appear in “Sent”
When contacts tell you they received spam from your address, check your “Sent” folder first. If you see messages you do not recognize, someone is using your account to send spam. If those messages do not appear in “Sent,” the sender address may simply be spoofed—an attacker using your name without actually controlling your mailbox.
Read Markers on Unopened Emails
You may notice emails you never opened are marked as “read.” Attackers sometimes quickly scan inboxes looking for password reset emails or sensitive information, which changes the read status of messages.
Your Contacts Have Been Deleted or Modified
Some attackers export or delete contact lists after gaining access, to use later for “friend impersonation” scams. If your contact list shows unexpected changes, this is a strong signal of compromise.
What to Do Immediately If Your Data Has Been Leaked
Once a breach is confirmed, delay means continued risk. Work through the following in priority order:
Step 1: Change High-Value Account Passwords First
Start with email, online banking, and cloud storage. Access to these accounts unlocks everything else. If your email is compromised, an attacker can use “Forgot Password” to reset nearly every other account you own.
New password requirements: at least 12 characters, a mix of uppercase, lowercase, numbers, and symbols, and not reused on any other account.
Step 2: Enable Two-Factor Authentication (2FA)
Even if your password is leaked, 2FA stops the vast majority of attackers. They would need physical access to your phone or authenticator app to obtain the verification code.
Enable 2FA first for email, banking, and primary social accounts. Authenticator apps (such as Google Authenticator or Microsoft Authenticator) are more secure than SMS codes, which can be intercepted through SIM-swapping attacks.
Step 3: Audit All Reused Passwords
If you used the same password across multiple services, every account using that password is at risk. Change them one by one. A password manager makes this process dramatically easier.
Step 4: Run a Full Antivirus Scan
If you suspect your device may have been compromised—for example, you clicked a suspicious link or downloaded an unknown attachment—run a full antivirus scan on all devices, not just a quick scan.
Step 5: Review Logged-In Devices
Most major services (Google, Microsoft, Apple, Facebook, LinkedIn) provide a list of currently logged-in devices. Check for any device you do not recognize and sign it out.
Conclusion
Determining whether your email or password has been compromised does not require professional security knowledge or paid tools. Have I Been Pwned’s email search and password check are free, secure, and take seconds to complete. Password managers’ built-in monitoring features provide continuous automated protection.
The core sequence is simple: check first, fix second, then set up ongoing monitoring. If your data appears in a breach, do not panic—but do not delay either. Change the passwords on your priority accounts immediately, enable two-factor authentication, and eliminate every instance of password reuse.
Data breaches are unavoidable in 2026. Account takeover is not. By following the steps above, you can keep the real-world impact of any breach to a minimum.
