Skip to content
Wednesday, August 26, 2026
BLOGDAILYGADGETS · APPS · REVIEWS
Home / Guides
Guides

How to Check if Your Data Was Exposed in a Breach — and What to Do Next

Your email address has almost certainly appeared in a breach — checking takes 30 seconds, and the fix list is short: passwords first, then 2FA, then card replays.

William Elliott, · March 22, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
Laptop showing breach-check result page at home desk

Check first, panic never: enter your email address at a breach-notification service — haveibeenpwned.com is the widely cited free option — and it lists every documented breach your address appears in, from mega-hacks like Collection #1 (773 million addresses) to single-site spills. If your address shows up, the response has a strict order: change that password where you used it (and everywhere you reused it), turn on two-factor authentication, watch the card you used there. The catch: past breaches can't be undone — the work is making the leaked data worthless.

How do these checkers know?

Breach databases come from publicly documented incidents — law-enforcement actions, security-researcher disclosures, and dumps posted by attackers themselves. Have I Been Pwned, run by security researcher Troy Hunt, documents its sources per breach on each listing page. It shows only breaches that are public; a site that's been breached quietly won't appear, which is why the checklist below matters even when the result is "no pwnage found."

What does exposure actually cost you?

The response checklist, in order

  1. Change the breached password everywhere it was reused — a password manager makes "everywhere" one afternoon instead of one weekend (see password-manager coverage elsewhere on Blog Daily).
  2. Turn on 2FA for email, banking and shopping first — email above all, because email resets everything else.
  3. Check card statements for the payment method used with breached services; dispute anything unfamiliar — the FTC documents this reporting path.
  4. Expect targeted phishing: a breach that includes your order history will produce convincing fake emails quoting it. Verify by going to the site directly, never through the link.
  5. For SSN exposure: the documented Federal Trade Commission identity-theft page walks through credit freezes at the three bureaus — free, and stronger than monitoring.

Should you pay for breach-monitoring services?

The documented free tools cover most needs: breach lookups, your card issuers' own alerts, and free credit reports from the three bureaus via the government-authorized annualcreditreport.com. Paid identity-protection services add insurance and recovery help — reasonable if your exposure was severe (SSN, medical, financial accounts), documented overkill for a single forum password from 2017 that you've already changed.

The habit that beats every checker

Unique password per account in a manager, 2FA on everything that matters, quarterly breach check — fifteen minutes of maintenance that makes each new headline someone else's problem.

FAQ

Frequently Asked Questions

How do I check if my information was in a data breach?
Enter your email at a breach-notification service like haveibeenpwned.com, which lists the documented breaches containing your address, with sources per incident. It covers only public breaches — so practice good hygiene regardless of the result.
What should I do first after a breach?
Change the breached password everywhere you reused it, enable two-factor authentication starting with email, and monitor the card used with that service. Reused passwords are how one breach becomes many.
Is it worth paying for identity-theft protection?
For severe exposure (SSN, financial accounts), paid services' insurance and recovery help are documented value. For routine breaches, free tools — breach lookups, issuer alerts, annualcreditreport.com — cover the essentials.

Sources

  1. Federal Trade Commission identity theft guidanceFederal Trade Commission identity theft guidance