Breaches & Passwords

What Hackers Actually Do With Your Leaked Data

By the RedactZero Team · August 12, 2026 · 9 min read

The short version

Almost nobody targets you personally. Your record joins a pile, gets cleaned and merged with older leaks, and is then run through automated attacks: passwords tried on other sites, phishing messages built from your real details, carrier calls to steal your phone number, and credit applications in your name. The FBI's complaint center logged 1,008,597 reports and $20.877 billion in losses in 2025. The defenses are unglamorous and they work: unique passwords, two-factor authentication, a credit freeze, and a smaller public footprint.

What actually leaks when a company is breached

Breaches rarely spill just passwords. Have I Been Pwned catalogues 1,026 breached sites holding 17,777,846,158 accounts, and each record is tagged with the data types it exposed. Counting those tags shows what a typical leak really contains, and passwords are only the second most common item.

Data type exposedBreaches containing itShare of all breaches
Email addresses1,01999%
Passwords67366%
Names54653%
Usernames48147%
IP addresses38638%
Phone numbers36736%
Physical addresses29629%
Dates of birth28227%

Counted across all 1,026 breaches listed in the Have I Been Pwned public breach dataset, checked August 12, 2026.

That mix matters. A password can be changed in a minute. Your date of birth, your name, and the address you lived at in 2019 cannot be changed at all, and those are precisely the details used to prove you are you. Our guide to reading a breach report explains how to check which types applied to you.

Step one: your data is sorted, merged, and resold

The first thing that happens to a fresh breach is housekeeping. Raw files are deduplicated, cleaned, and matched against older leaks using your email address as the common key. The output is a searchable list, and lists are what get traded, sold, and eventually dumped in public.

The clearest documented example is Collection #1, added to Have I Been Pwned in January 2019. HIBP describes it as a large collection of credential stuffing lists distributed on a hacking forum, containing almost 2.7 billion records that condensed down to 773 million unique email addresses alongside passwords those addresses had used on other breached services.

Six of the breaches in that same dataset are flagged as stealer logs - data harvested directly from infected computers rather than from a company. The largest, ALIEN TXTBASE, covers 284,132,969 accounts. The point is that your record is a line item in someone's inventory long before anyone tries to use it.

Credential stuffing: your old password, tried everywhere

The cheapest attack is also the most common outcome of a leak. Software takes the email and password pairs from a list and tries them automatically against hundreds of unrelated sites: banks, email providers, retailers, streaming services. Nobody researches you. The list runs, and whatever opens, opens.

This only works because passwords get reused. If the password leaked from a hobby forum is also the password on your email account, the forum breach is now an email breach. We wrote a full explainer on how credential stuffing works, but the short version is that reuse is the vulnerability, not the original breach.

Verizon's 2026 Data Breach Investigations Report, covering incidents from November 2024 through October 2025, found that software vulnerability exploitation has now overtaken stolen passwords as the leading way breaches begin, at 31%. Stolen passwords slipping to second place is not the same as harmless - it reflects attackers adding a faster route, not abandoning the old one.

Phishing built from your real details

The second use of leaked data is making a fake message believable. IC3 defines phishing and spoofing as unsolicited emails, texts, or calls posing as a legitimate company to request personal, financial, or login credentials. A message that knows your name, your bank, and your last four digits clears the suspicion bar that a generic one never would.

Phishing and spoofing were the most reported crime type in the FBI's 2025 figures at 191,561 complaints, roughly double the next category. The reported dollar losses look modest at $215.8 million, but that undercounts badly: phishing is usually the first step, and the loss gets recorded later under whatever the credentials were used for.

The FTC's 2025 data shows where that ends up. Consumers reported about $16 billion lost to fraud, the highest on record and up roughly 25% from 2024, with $3.5 billion of it to imposter scams. Nearly one in three fraud reports involved someone pretending to be a business or agency - almost $1 billion to business impersonators, with bank impersonators the costliest, and about $920 million to government impersonators.

Account takeover and the SIM-swap shortcut

Once an attacker has one working login, the goal is your phone number, because the number receives the codes that reset everything else. SIM swapping is social engineering aimed at your mobile carrier: someone calls, poses as you, answers the identity questions with leaked details, and moves your number to their device.

IC3 logged 971 SIM swap complaints and $17.4 million in reported losses in 2025. The complaint count is small next to phishing, but the per-victim damage is severe, because control of the number usually means control of email, banking, and any account that texts you a code. Our SIM-swap defense guide covers the carrier settings that block it.

Regulators have partly closed this door. In its November 2023 SIM Swap and Port-Out Fraud Order, the FCC required wireless providers to authenticate customers securely before moving a number, to notify you immediately when a SIM change or port-out is requested, and to offer an account lock that blocks those changes outright. That lock is free and worth turning on today.

New accounts opened in your name

Where the leak includes name, address, birth date, and especially a Social Security number, the play shifts from stealing your accounts to creating new ones. Credit cards, loans, phone contracts, and utility accounts get opened under your identity, and the first you hear of it is a collections call or a credit denial.

The FBI recorded 31,675 identity theft complaints and $185.8 million in reported losses in 2025. That figure sits well below the true scale because most victims report to the FTC, to their bank, or to nobody at all. Our post on the early signs of identity theft lists the symptoms that show up first.

This is the attack a credit freeze stops cold. The FTC is explicit: while a freeze is in place, nobody can open a new credit account in your name, it costs nothing to place or lift, and it does not affect your credit score. You place it separately at Equifax, Experian, and TransUnion, and it lasts until you lift it.

Extortion emails that quote a real password

A fourth use is pure intimidation. You get an email claiming your device was hacked and your browsing was recorded, and to prove it the sender quotes a password you recognise. The proof is theatre. The password came from a public breach list, and the sender has never touched your computer.

Extortion was the second most reported crime type in the FBI's 2025 figures, at 89,129 complaints and $122.5 million in losses. These messages are sent in bulk to entire leaked lists on the assumption that a small fraction will pay. Do not pay and do not reply, since replying confirms the address is live.

One caveat: if the quoted password is one you still use anywhere, the threat in the email is worthless but the password is not. Change it everywhere before you delete the message. The same logic applies to any detail the sender quotes correctly - a real address or phone number in a threatening email tells you which leak they are working from, not that they have access to your devices.

What the reported losses actually look like

Volume and damage do not line up, and that mismatch is useful for deciding what to worry about. The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025 with $20.877 billion in reported losses, a 26% rise over 2024 and an average loss of $20,699 per complaint.

Crime type2025 complaintsReported losses
Phishing / spoofing191,561$215.8 million
Personal data breach67,456$1.31 billion
Identity theft31,675$185.8 million
Business email compromise24,768$3.05 billion
SIM swap971$17.4 million

FBI Internet Crime Complaint Center, 2025 IC3 Annual Report, crime types by complaint count and by complaint loss.

Read it as two different risks. Phishing is the one you will meet constantly and should expect in your inbox this week. SIM swap is rare but catastrophic when it lands, which is why a five-minute carrier lock is worth more than its complaint count suggests.

Why data brokers make every one of these easier

Breach data answers "what is this person's password." Data brokers answer everything else. People-search sites publish your full name, age, current and past addresses, phone numbers, and relatives, all legally assembled from public records - and they publish it to anyone who searches, at no cost and with no account.

That is the missing half of most of these attacks. It is how a carrier's security questions get answered, how a phishing email names your street, and how a fraudulent credit application matches your address history. Our data broker coverage goes into how these profiles get built.

Every major people-search site has a free opt-out, and we publish dated, verified step-by-step removal guides for the big ones. Expect to repeat it: listings commonly reappear within three to six months as brokers re-ingest public records, so treat removal as maintenance rather than a one-time job.

Removing yourself does not undo a breach. What it does is strip away the corroborating detail that turns a leaked email address into a convincing impersonation, which lowers the success rate of every attack above.

What actually stops each of these

Each attack in this article has one defense that blunts it more than anything else, and none of them cost money. Doing all five takes an evening, and the first two are the ones that matter most because they break the automated attacks that everything else builds on.

AttackThe defense that works
Credential stuffingA unique password per site, kept in a password manager
Account takeoverTwo-factor authentication, ideally an app rather than SMS
SIM swapThe carrier account lock the FCC requires providers to offer
New-account fraudA free credit freeze at all three bureaus
Targeted phishingOpt out of people-search sites so the lures have less to work with

Defenses per the FTC (credit freezes and fraud alerts), the FCC SIM Swap and Port-Out Fraud Order, and the brokers' own opt-out pages.

If you are working through this after a specific breach notice, follow the ordered checklist in what to do right after a data breach, and see our password manager and 2FA guide for the setup steps.

Find out what is already out there

Run a free exposure scan to see which breaches include your email and which data brokers likely list you - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

What do hackers do with stolen data first?

They sort it. Raw breach files get cleaned, merged with older leaks, and turned into searchable lists that are traded or sold. Have I Been Pwned's Collection #1, added in January 2019, was exactly that: almost 2.7 billion records boiled down to 773 million unique email addresses with the passwords those addresses had used elsewhere.

What can someone do with just my email address?

Your email is the join key. It links your record in one breach to your record in every other breach, which is how a leaked shopping account and a leaked forum password end up in the same profile. On its own an email address is low risk; combined with a password, a phone number, or a home address, it becomes an account-takeover kit.

Can hackers still use my leaked password if I changed it?

Not on that account, but the old password still has value if you reused it or built variations on it. Credential stuffing works because people repeat passwords across sites, so an attacker tries the leaked pair on banks, email, and retailers. Change it everywhere you used it, not just where it leaked.

Why do I get phishing emails that know real details about me?

Because the details came from a breach or a people-search profile. The FBI's IC3 defines phishing as unsolicited email, texts, or calls that pose as a legitimate company to request personal, financial, or login information, and leaked data is what makes the pose convincing. Phishing and spoofing drew 191,561 complaints in 2025, more than any other crime type IC3 tracks.

What is a SIM swap and how does leaked data enable it?

A SIM swap is social engineering against your mobile carrier to move your phone number to a device the attacker controls, which hands them your SMS codes. IC3 recorded 971 SIM swap complaints and $17.4 million in reported losses in 2025. Leaked personal details are what let the attacker answer the carrier's identity questions.

Should I worry if only my name and address leaked, with no password?

Yes, but for a different reason. Name, address, birth date, and phone number are not login credentials, they are identity-proofing answers. They are the raw material for opening accounts in your name, passing a support agent's verification questions, and writing phishing messages that sound legitimate.

How would I know my leaked data is actually being used?

Watch for login alerts you did not trigger, password reset emails you did not request, a phone that suddenly loses service, mail that stops arriving, and unfamiliar accounts on your credit report. Any one of those deserves a same-day check of your credit report and your account security settings.

What single step protects me most after a breach?

Unique passwords on every account, stored in a password manager, with two-factor authentication on email and banking. That combination breaks credential stuffing, which is the attack that turns one leaked password into many compromised accounts. A free credit freeze at all three bureaus is the strongest second step.

Sources: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report (complaint counts, losses, and crime-type definitions); Federal Trade Commission press release, "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025," June 15, 2026, and FTC consumer guidance on credit freezes and fraud alerts; Have I Been Pwned public breach dataset and its Collection #1 record, counted August 12, 2026; Verizon 2026 Data Breach Investigations Report; FCC Report and Order FCC 23-95, Protecting Consumers from SIM Swap and Port-Out Fraud (WC Docket 21-341), adopted November 15, 2023, and Wireline Competition Bureau order DA 24-649.