Breaches & Passwords

How to Check If Your SSN Was Leaked

By the RedactZero Team · August 24, 2026 · 9 min read

The short version

There is no safe website where you type in your Social Security number and get a yes or no. After the 2024 National Public Data breach - researchers counted about 272 million unique SSNs in the leaked files - the realistic assumption for a US adult is that your number is out there. The checks that actually work are free and indirect: breach alerts tied to your email, your credit reports, and your Social Security earnings record. Then block misuse with three free locks: a credit freeze, an IRS IP PIN, and E-Verify Self Lock.

The honest answer: you cannot look up an SSN directly

No legitimate public tool lets you enter your nine digits and get a definitive answer about whether they leaked. Real checks work indirectly: breach notices tied to your email address, unfamiliar accounts on your credit report, and wages on your Social Security record that you never earned. Anything else is guesswork or marketing.

That constraint is also a safety rule. A website offering to "check" your SSN if you type it in is asking you to hand the most sensitive identifier you own to a stranger. Even if the site is well-intentioned, you have widened your exposure to check on your exposure. Legitimate breach checkers do not work that way, and the good news is they do not need to.

Assume it leaked: the National Public Data breach

Since 2024, "was my SSN leaked" has a blunt practical answer: for most US adults, treat it as yes. A background-check company called National Public Data was breached, and the stolen files circulated widely. Researchers who analyzed them counted roughly 272 million unique Social Security numbers, per reporting by KrebsOnSecurity.

The headline numbers were widely garbled, which is worth untangling because it shows how breach hype works. The seller advertised 2.9 billion rows of data, and many outlets reported that as 2.9 billion people. Security researcher Troy Hunt, who loaded the data into Have I Been Pwned, found massive duplication - the same people repeated across rows - and far fewer unique records.

Reported figureWhat it actually counted
2.9 billionRows in the leaked files - the seller's own claim, widely misreported as people
272 millionUnique SSNs researchers counted across the full record set
134 millionUnique email addresses in the files, stored separately from the SSN records

Figures from KrebsOnSecurity's reporting and Troy Hunt's analysis of the leaked National Public Data files, 2024.

The company's parent, Jerico Pictures, filed for bankruptcy in October 2024, citing regulatory action by the FTC and more than 20 states. The data, of course, did not go bankrupt with it. Once a file like that circulates, it never comes back - which is why the useful response is locking down, not looking up.

What a leaked SSN actually enables

An SSN on its own opens fewer doors than people fear, but combined with your name, address, and date of birth - exactly what breach files bundle together - it becomes a skeleton key for new-account fraud. The FTC logged more than 1.1 million identity theft reports in 2024, with reported fraud losses above $12.5 billion, up 25 percent in a year.

The main abuses fall into four buckets: opening credit cards or loans in your name, filing a tax return to steal your refund, working under your number, and using your SSN as the seed for a synthetic identity that borrows your credit history. Each has a different early-warning sign, which is why the checks below look in different places. If you want the broader list of red flags, see our guide to the early signs of identity theft.

Check 1: breach alerts tied to your email

The closest thing to a direct check is searching your email address against known breaches. Have I Been Pwned, the standard public breach database, indexes billions of leaked records and tells you which breaches included your address - and its breach descriptions note when Social Security numbers were among the exposed data, as with National Public Data and AT&T.

Note what this does and does not prove. You search by email, never by SSN, so a match tells you that a breach containing SSNs included your email - strong evidence, not certainty. And the National Public Data SSN files mostly did not contain email addresses at all, so a clean result there proves nothing. RedactZero's free exposure scan runs this breach check for you, along with a data-broker exposure check, and stores nothing you type.

Check 2: read your credit reports

Your credit report is where a misused SSN shows up first and most concretely: accounts you never opened and hard inquiries you never triggered. Since October 2023, the three national bureaus offer free reports weekly - permanently - through AnnualCreditReport.com, per the FTC. That is the only official source; lookalike sites want to sell you monitoring.

Pull all three reports, because lenders do not report to every bureau. Read the accounts list and the inquiries section line by line. An address you never lived at, an employer you never had, or a card you never applied for are each worth investigating, not shrugging off as a paperwork error.

Check 3: review your Social Security earnings record

Employment fraud - someone working under your number - does not appear on any credit report. The place it surfaces is your Social Security earnings record, which you can review free through a my Social Security account at ssa.gov. Wages posted for years or employers you do not recognize are the signature of this fraud.

The SSA recommends reviewing your statement annually, and the stakes are real: your future benefits are calculated from that record, and someone else's wages tangled into it can also generate surprise IRS bills for income you never saw. The SSA directs misuse victims to IdentityTheft.gov, and tax-related cases to the IRS Identity Protection unit.

Check 4: your LexisNexis consumer file

Beyond the three credit bureaus, specialty consumer reporting agencies keep SSN-linked files on you that feed insurance, tenant, and risk decisions. The biggest is LexisNexis Risk Solutions. Under the FACT Act you can request a free copy of your LexisNexis consumer file once every 12 months, and it also offers a free security freeze.

Your file shows what the risk industry has tied to your identity - address history, aliases, claims - and, like a credit report, it can reveal an identity thief's activity. If you spot problems, or want the file locked, our LexisNexis opt-out guide walks through the freeze, the disclosure request, and the narrower suppression option, which identity-theft victims with documentation qualify for.

Found something? Report it, then add a fraud alert

If any check surfaces real misuse, go straight to IdentityTheft.gov, the FTC's official identity-theft site. It asks what happened, builds a personal recovery plan, and pre-fills the dispute letters and affidavits you will need. That FTC report is also the document banks and bureaus expect when you dispute fraudulent accounts.

Then place a fraud alert. One call does it: the bureau you contact must notify the other two. An initial alert is free, lasts one year, and is renewable; confirmed identity-theft victims can get an extended seven-year alert. An alert tells lenders to verify identity before opening accounts - useful, but weaker than the freeze below, so treat it as a supplement.

Lock it down: three free locks that block misuse

Whatever the checks show, the same three locks neutralize most of what a leaked SSN enables, and all three are free. They attack the three big fraud channels directly: new credit, fraudulent tax filings, and employment misuse. Set aside an hour and do all three rather than debating which one matters most.

First, freeze your credit at Equifax, Experian, and TransUnion - separately, since a freeze does not propagate. Free under federal law since September 2018, a freeze blocks new-account fraud outright; online requests take effect within one business day and unfreezing online takes about an hour. Our credit freeze guide has the steps.

Second, get an IRS Identity Protection PIN at irs.gov. It is a six-digit code, available to anyone with an SSN who can verify their identity, and a tax return filed without it is rejected - which closes the refund-fraud channel. Third, lock your number in E-Verify with Self Lock, a free feature of a myE-Verify account that blocks your SSN from passing employment verification; it lasts a year and is renewable.

Why "we scan the whole dark web" is marketing

Plenty of services sell SSN scanning with the promise that they search the dark web for your number. Be skeptical of the framing. No scanner sees more than a slice of where stolen data actually trades - private forums, invite-only markets, closed chat groups - and much of it changes hands on the ordinary web anyway.

Troy Hunt, who runs Have I Been Pwned, has spent years puncturing this exact pitch, arguing that "dark web" is largely a term marketing teams reach for because fear sells. That does not make monitoring useless: an alert that your SSN appeared in a known dump is a genuine signal to check your reports and tighten the locks. But silence from a scanner is not safety, and a subscription is not protection - the freeze, the IP PIN, and Self Lock are. We cover the trade-offs in whether dark web monitoring is worth paying for.

See what is already exposed

Run a free scan to see which breaches include your email and which data brokers likely list you - no account, and nothing you scan is stored.

Run a free exposure scan

Frequently asked questions

Can I check if my SSN was leaked for free?

Yes. Every legitimate check is free: breach notifications tied to your email, weekly credit reports at AnnualCreditReport.com, your Social Security earnings record at ssa.gov, and your LexisNexis consumer file. Be wary of any service that charges money just to tell you whether you were exposed.

Is there a website where I can type in my SSN to check it?

No, and you should not type your SSN into one. Legitimate breach checkers like Have I Been Pwned search by email address, not SSN. A form that asks for your nine digits to run a free check is a bigger risk than the leak it claims to detect.

Was my SSN in the 2024 National Public Data breach?

Quite possibly. Researchers who analyzed the leaked files counted about 272 million unique Social Security numbers, mostly belonging to US adults. There is no official lookup tool, so the practical response is to assume exposure and freeze your credit rather than chase a definitive answer.

What should I do first if my SSN was leaked?

Freeze your credit at Equifax, Experian, and TransUnion. It is free under federal law, and it blocks the most damaging misuse - new credit accounts opened in your name. Then add an IRS IP PIN so nobody can file a tax return with your number.

How can I tell if someone is using my SSN to work?

Open a my Social Security account at ssa.gov and review your earnings record. Wages you do not recognize are the signature of employment fraud. You can also lock your number in E-Verify with the free Self Lock feature so it cannot be used to pass an employment check.

Which protects me better, a fraud alert or a credit freeze?

A freeze is stronger. It blocks access to your credit file until you lift it, and it is free at all three bureaus. A fraud alert only tells lenders to take extra verification steps; it lasts one year and is renewable. Many people use both.

Do dark web scans of my SSN actually work?

Only partially. A scan can confirm your data appeared in specific known dumps, which is useful, but no service can see every private forum, market, or trade. Treat a dark web alert as a signal to lock down, and treat silence as no guarantee of safety.

Where do I report identity theft involving my SSN?

Use IdentityTheft.gov, the FTC's official reporting site. It builds a personal recovery plan and pre-fills the letters and forms you need. For tax-related misuse, contact the IRS; for Social Security benefit fraud, report to the Social Security Administration.

Sources: KrebsOnSecurity and Troy Hunt's analyses of the National Public Data breach (2024); TechCrunch on the National Public Data bankruptcy; FTC Consumer Sentinel 2024 figures and IdentityTheft.gov; CFPB and FTC guidance on free credit freezes and fraud alerts; AnnualCreditReport.com weekly report program (FTC, 2023); IRS Identity Protection PIN pages; Social Security Administration (my Social Security); E-Verify Self Lock pages; LexisNexis Risk Solutions consumer portal.