Check first, panic never: enter your email address at a breach-notification service — haveibeenpwned.com is the widely cited free option — and it lists every documented breach your address appears in, from mega-hacks like Collection #1 (773 million addresses) to single-site spills. If your address shows up, the response has a strict order: change that password where you used it (and everywhere you reused it), turn on two-factor authentication, watch the card you used there. The catch: past breaches can't be undone — the work is making the leaked data worthless.
How do these checkers know?
Breach databases come from publicly documented incidents — law-enforcement actions, security-researcher disclosures, and dumps posted by attackers themselves. Have I Been Pwned, run by security researcher Troy Hunt, documents its sources per breach on each listing page. It shows only breaches that are public; a site that's been breached quietly won't appear, which is why the checklist below matters even when the result is "no pwnage found."
What does exposure actually cost you?
- Password reuse is the real damage: attackers feed leaked email-password pairs into banks, email providers and retailers automatically — documented as "credential stuffing." One reused password turns a forum breach into a bank problem.
- Personal data doesn't expire: addresses, birthdates and partial card data from old breaches fuel phishing that knows your name, your bank and your last four digits.
- Card data usually gets rotated: networks detect and replace cards proactively; the FTC documents that liability protections on credit cards remain your backstop.
The response checklist, in order
- Change the breached password everywhere it was reused — a password manager makes "everywhere" one afternoon instead of one weekend (see password-manager coverage elsewhere on Blog Daily).
- Turn on 2FA for email, banking and shopping first — email above all, because email resets everything else.
- Check card statements for the payment method used with breached services; dispute anything unfamiliar — the FTC documents this reporting path.
- Expect targeted phishing: a breach that includes your order history will produce convincing fake emails quoting it. Verify by going to the site directly, never through the link.
- For SSN exposure: the documented Federal Trade Commission identity-theft page walks through credit freezes at the three bureaus — free, and stronger than monitoring.
Should you pay for breach-monitoring services?
The documented free tools cover most needs: breach lookups, your card issuers' own alerts, and free credit reports from the three bureaus via the government-authorized annualcreditreport.com. Paid identity-protection services add insurance and recovery help — reasonable if your exposure was severe (SSN, medical, financial accounts), documented overkill for a single forum password from 2017 that you've already changed.
The habit that beats every checker
Unique password per account in a manager, 2FA on everything that matters, quarterly breach check — fifteen minutes of maintenance that makes each new headline someone else's problem.
FAQ
For more context, read How to Declutter Your Digital Life in One Weekend.
For more context, read strong passphrase examples.
For more context, read is this website safe to buy from.

