Breaches & Passwords
How to Check if Your Email Was in a Data Breach
The short version
Type your email into Have I Been Pwned. It is free, needs no account, and does not log searches. If your address appears, look past the number of breaches to the list of data classes under each one, which tells you exactly what leaked. Passwords mean change them everywhere you reused them. Phone numbers and addresses mean expect phishing and check the data brokers. A clean result is good news, not proof.
What Have I Been Pwned actually is
Have I Been Pwned is a free search engine for leaked account data. You enter an email address and it lists the known breaches that address turned up in. As of July 27, 2026 it held 1,020 breached websites covering 17,764,052,966 account records. Searching one address costs nothing and requires no sign-up.
It was built and is still run by security researcher Troy Hunt, and it has become the reference database the rest of the industry checks against. It does not scan your computer, and there is nothing to buy. It indexes data that has already escaped and been published or traded.
The limitation is built into the design: it can only know about breaches that were discovered and released. Plenty of incidents are never detected at all.
How to check your email in under a minute
Go to haveibeenpwned.com, type the address into the search box, and press the button. You do not need an account, and there is nothing to download. Results appear immediately as a list of breaches, each with the site name, the date of the incident, and what was exposed.
- Check your main personal address first - the one attached to your bank, your email recovery, and your phone account.
- Then check the old addresses you barely use. Those are usually worse, because they were used to sign up for things a decade ago and you stopped watching them.
- Check any work address you have used for personal signups.
- Write down, for each hit, only one thing: which data classes were exposed.
Do the checks before you start fixing anything. Seeing the whole picture first stops you from spending an hour on a 2013 forum leak while a recent one with your phone number sits unaddressed.
What the result screen is telling you
Each entry is one breach, not one account of yours. It shows the breached company, the date the incident occurred, the date it was added to the database, a short description of what happened, and a list of the data classes exposed. Some entries are also flagged as unverified, meaning the data looks real but could not be confirmed.
Two dates matter for different reasons. The breach date tells you how old the exposed password probably is. The added date tells you when it became public, and therefore when attackers could start using it at scale.
Of the 1,020 breaches currently loaded, 42 carry the unverified flag. They are included because people would rather know than not, but treat them as a prompt to change a password rather than as confirmed fact.
Data classes: the part everyone skips
The data classes are the only part of the result that changes what you should do. A breach that exposed just email addresses is an annoyance. One that exposed passwords, your date of birth, and your home address is a different problem entirely. Across the whole database, some types show up far more often than others.
| Data class | Share of the 1,020 breaches | Why it matters |
|---|---|---|
| Email addresses | 99% | The index key; on its own, mostly spam risk |
| Passwords | 66% | Reuse turns one leak into many compromised accounts |
| Names | 53% | Makes phishing personal and credible |
| Usernames | 47% | Links your accounts across unrelated sites |
| IP addresses | 38% | Approximate location and household linkage |
| Phone numbers | 35% | Smishing, robocalls, and SIM-swap targeting |
| Physical addresses | 29% | Feeds people-search listings and mail fraud |
| Dates of birth | 27% | Half of most identity-verification questions |
| Government issued IDs | 3% | Rare, but the hardest damage to undo |
RedactZero analysis of all 1,020 breaches published in the Have I Been Pwned breach API, retrieved July 27, 2026.
The 673 breaches that exposed passwords account for 11.8 billion of the records in the database. Phone numbers appear in 362 breaches covering 5.3 billion records. If you have been breached at all, the odds are good that a password and a phone number were part of it.
What to do about each kind of leaked data
Match the fix to what actually leaked. Most people either panic at every result or ignore all of them, and both reactions cost you. The table below covers what to do about each data class, ordered by how much the work buys you.
| What leaked | The real risk | First move |
|---|---|---|
| Password | Credential stuffing on your other accounts | Change it on that site and everywhere you reused it |
| Phone number | SIM-swap and text-based scams | Add a carrier port-out PIN; move 2FA off SMS |
| Home address | Turns up in people-search profiles | File broker opt-outs |
| Date of birth | Identity verification bypass | Freeze your credit; stop using it as a security answer |
| Government ID | Account opening in your name | Freeze credit, then report at identitytheft.gov |
Response guidance based on the FTC's consumer advice on breaches and credit freezes.
Our step-by-step guide to the hours after a breach walks through the same fixes in order if you want the longer version.
Check the password, not just the email
The same site runs a second, separate tool called Pwned Passwords that tells you whether a specific password has appeared in breaches. This is more useful than the email search for one reason: it catches passwords that are compromised because someone else used them, not because you were personally breached.
It is safe to use. Your password is hashed in your browser and only the first five characters of that hash are sent to the server, which returns every matching suffix so the comparison finishes on your machine. The full password never leaves your device. The service handles over 18 billion requests a month, mostly from software checking passwords automatically.
If a password comes back as seen even once, it is on the lists attackers feed into automated login attempts. That is exactly how credential stuffing works, and it is why a unique password per site matters more than a clever one.
Some breaches will not show in a public search
If your result comes back clean, there is one gap worth knowing about. Breaches from sites where simply being a member could harm someone - dating, adult, and similarly sensitive services - are flagged as sensitive and removed from public search, so nobody can look up a stranger and find them there.
There are 85 sensitive breaches in the system. To see whether you appear in any of them, sign in to the site's dashboard, which verifies you can receive email at that address. It is the same search, restricted to the person who owns the inbox.
This is a deliberate trade-off, and a good one. It also means a clean public result is slightly less complete than it looks.
"Not found" is not the same as "not breached"
A clean result means your address is not in the breaches that were detected, published, and loaded into this one database. It does not mean no company has ever lost your data. The site's own FAQ puts it plainly: "Absence of evidence is not evidence of absence."
Many breaches are never disclosed. Others are traded privately for years before anyone posts them. Some companies discover an intrusion and genuinely cannot determine what was taken. None of those show up in any search you can run.
So treat a clean check as encouraging rather than final. The defences that actually protect you - unique passwords, a password manager, two-factor authentication that is not SMS - are worth having regardless of what the search returns.
Turn one check into an alert
Checking once tells you about the past. The value is in being told the next time, because the gap between a breach happening and you hearing about it is where the damage occurs. Have I Been Pwned has a free Notify Me option that emails you when your address appears in a future breach.
The pace justifies it: 85 new breaches were added in the first seven months of 2026, against 91 in all of 2025. Recent additions have ranged from a music service with 55 million records to a work platform whose exposed data classes included bank account numbers.
RedactZero's free exposure scan checks your email against the same breach data, plus the data brokers likely to list you, and can re-check monthly and email you only when something new shows up. Nothing you type into it is stored.
Where breach data ends up next
Breached records do not sit in one file. They get merged, cleaned, and cross-referenced with other leaks and with public records, which is how a single old forum password ends up next to your current address and phone number in someone's combined list. That merged profile is what makes the follow-up attacks work.
What follows is predictable: automated login attempts against your other accounts, and phishing that quotes real details so it reads as legitimate. If a phone number leaked alongside enough identifying data to pass a carrier's verification, SIM-swap attempts come next.
The overlap with people-search sites is the part most guides miss. Breach data and broker listings feed the same picture of you, so cleaning up one and ignoring the other leaves the profile mostly intact. Our opt-out guides cover the broker half.
If financial or identity data leaked, freeze first
When a breach exposed a date of birth, a government ID number, or financial details, the highest-value move is a credit freeze at all three bureaus. It blocks new accounts being opened in your name, and it has been free nationwide since September 21, 2018 under the Economic Growth, Regulatory Relief, and Consumer Protection Act.
A fraud alert is the lighter alternative: it requires businesses to verify your identity before extending credit, lasts one year, and you only need to contact one bureau because it notifies the other two. Identity theft victims can get an extended alert lasting seven years. A freeze is stronger; an alert is faster.
If money has already moved or accounts have been opened, report it at identitytheft.gov, the FTC's official reporting site, which generates a recovery plan and an affidavit you can give to creditors. If you are weighing paid monitoring, see dark web monitoring versus credit monitoring first.
See everything that is already exposed
Run a free exposure scan to check your email against known breaches and see which data brokers likely list you - no account, nothing stored.
Frequently asked questions
Is Have I Been Pwned safe to use?
Yes. The site's FAQ states that searches are not logged and are performed over an encrypted connection, so there is no collection of the addresses people look up. You are also only typing in an email address, which is not enough on its own to access your accounts.
Does it cost anything to check if my email was breached?
No. Searching a single email address on Have I Been Pwned is free and needs no account. Paid plans exist for organisations that want to monitor a whole domain, but an individual checking their own address never has to pay.
My email was not found. Does that mean I am safe?
Not quite. Have I Been Pwned only holds breaches that were detected and made public. As its FAQ puts it, absence of evidence is not evidence of absence. Treat a clean result as good news, not proof, and keep unique passwords on every account anyway.
What does "pwned" mean?
"Pwned" is internet slang, originally from video game culture, for being beaten or taken over. In this context it means an account of yours was included in a data breach that has since been published or traded.
What are data classes in a breach result?
Data classes are the categories of information the breach exposed, listed alphabetically for each incident: email addresses, passwords, phone numbers, physical addresses, dates of birth, and so on. They are the most useful part of the result because they tell you exactly what you need to fix.
Should I change my password if my email shows up in a breach?
Yes, if the breach lists passwords as an exposed data class. Change it on the breached site and anywhere you reused it, which is the part that actually matters. If passwords were not exposed, focus instead on phishing awareness and the other data that leaked.
Why can I not see some breaches in the public search?
Breaches from sites where mere membership could harm someone are flagged sensitive and hidden from public search. There are 85 of them. To see whether you appear in one, sign in to the site's dashboard, which verifies you can receive email at that address.
How often should I check my email for breaches?
Checking manually every few months is reasonable, but a notification is better than a habit. Have I Been Pwned can email you when your address turns up in a future breach, and 85 new breaches were added in the first seven months of 2026 alone.
Sources: Have I Been Pwned (haveibeenpwned.com) for breach counts, data classes, sensitive-breach handling, search logging, and the Pwned Passwords range model; RedactZero's own analysis of the public HIBP breach API, retrieved July 27, 2026, for the data-class frequencies; the US Federal Trade Commission for credit freeze and fraud alert rules under the Economic Growth, Regulatory Relief, and Consumer Protection Act, and for identitytheft.gov.