You get an email that says “your data may have been exposed in a security incident.” Your stomach drops. Then the message is vague, the link looks odd, and you have no idea whether this is real or itself a scam. What do you actually do?
The good news is you can find out for yourself in about ten minutes, using free tools that security professionals trust. This is a calm, step-by-step way to check whether your email or passwords have shown up in a breach, and what to do the moment you find one.
Key takeaways
- Free, reputable services let you check your email against known breaches safely.
- Your browser or password manager may already be warning you about leaked passwords.
- Finding your data in a breach is common and not a personal failure; the response matters more.
- Reset the exposed password first, then anywhere you reused it, starting with email.
Step one: check your email address against known breaches
The most trusted place to start is Have I Been Pwned, a free service run by a respected security researcher. You type in your email address, and it tells you which known breaches included it.

Go to haveibeenpwned.com and enter your address. It will list any breaches your email appeared in, with the site name and what data was exposed, such as passwords, phone numbers, or addresses.
Do this for every email address you use, including old ones. People are often surprised to find an address in five or six breaches. That is normal given how many companies have been hacked over the years.
Entering your email on Have I Been Pwned is safe. The site does not store what you type as a password, and checking an email address only searches public breach records. It never asks for your actual password.
Step two: let your browser and password manager help
You may already own a breach detector without realizing it. Most modern tools watch for leaked credentials in the background.
Your web browser
Chrome, Edge, and Safari all check saved passwords against known leaks. In Chrome, go to Settings, then “Passwords,” and look for the “Password Checkup” or “Check passwords” option. It flags any saved password that has appeared in a breach or is reused or weak.
Your password manager
If you use a dedicated password manager, it almost certainly has a security dashboard. It will show you leaked, reused, and weak passwords in one list, sorted so you can fix the worst first. If you have not set one up yet, our guide to password security basics explains how it all fits together.
Step three: understand what the results mean
Seeing your email in a breach does not mean someone is in your account right now. It means the data existed in a leaked database somewhere, which raises the risk.
Pay attention to what was exposed. If only your email leaked, the risk is more spam and phishing. If a password leaked, especially one you reused, that is urgent and needs action today.
After a breach makes the news, scammers send fake “your account was hacked” emails to rush you into clicking a link. Never act through a link in an alarming email. Go directly to the website by typing its address yourself, then check and change your password there.
Step four: act on what you find
Finding a breach is only useful if you respond. Here is the order that limits the damage fastest.
First, change the password on the breached account itself. Make the new one long, random, and unique. Second, change it anywhere you reused that same password, because attackers will try it there. If reuse is a habit you are still breaking, our reader questions on password reuse danger show why that second step is so important.
Third, if your email account was involved, treat that as top priority, since email can reset every other login you own. Turn on two-factor authentication while you are there.
What if only other data leaked, not a password?
Sometimes a breach exposes your name, phone number, or address but no password. That still matters, just in a different way. It fuels targeted phishing and, in some cases, attempts to take over your accounts by convincing customer support they are you.
You do not need to reset passwords in that case, but stay alert for messages that reference details from the breach to seem trustworthy. If a phone number leaked, be extra wary of text-message scams and calls claiming to be your bank.
How the tools compare
Each checking tool has a slightly different job. This table shows what each one is best for.
| Tool | What it checks | Best for |
|---|---|---|
| Have I Been Pwned | Whether your email appeared in known breaches | A quick, one-time check of every email you own |
| Browser password checkup | Saved passwords that leaked, repeated, or are weak | People who save passwords in their browser |
| Password manager dashboard | All stored passwords, ranked by risk | Ongoing monitoring across every account |
Turn a one-time check into a habit
Checking once is good. A light ongoing habit is better, because new breaches happen constantly.
Have I Been Pwned offers a free notification service: enter your email and it will alert you if your address appears in a future breach. A password manager with breach monitoring does the same automatically. Either way, you get a heads-up instead of finding out months later.
When I signed my parents up for breach alerts, they got a notification within a few months about an old shopping site, changed one password, and moved on. That is the whole idea: small, calm actions instead of one big panic.
Once you have found what leaked, the next move is cleaning up properly. Our detailed breach cleanup checklist walks through every step in order so nothing gets missed.
Your afternoon checklist
- Enter every email address you own into Have I Been Pwned.
- Run your browser’s built-in password checkup.
- Open your password manager’s security dashboard if you have one.
- Note which passwords leaked and where else you reused them.
- Change the breached password first, then every reuse of it.
- Prioritize your email account and turn on two-factor there.
- Sign up for free breach notifications so future leaks reach you fast.
A breach notice feels scary, but checking is quick and the response is manageable. Look yourself up today, fix what needs fixing, and you will trade that vague dread for a clear, short to-do list. That trade is always worth making.