Short answer: Search your email addresses on Have I Been Pwned (haveibeenpwned.com) to see which breaches you appear in. Then check your browser’s or password manager’s built-in breach monitor — Chrome, Safari, Firefox, Bitwarden and 1Password all flag compromised and reused passwords automatically. If something turns up, change that password everywhere you reused it and turn on 2FA, in that order.

Almost everyone with an email address older than a few years is in at least one breach. It is not a judgement on your habits — it is arithmetic.

Where to check

Have I Been Pwned

The standard tool, run by security researcher Troy Hunt and used by governments and browser vendors. Enter an email address and it lists the known breaches containing it, with dates and what data was exposed.

Two things worth using beyond the basic search:

Check every address you have used, including old ones. Old addresses are often where the worst reuse lives.

Your browser

All the major browsers now check saved passwords against breach databases automatically:

These catch leaks passively, which matters because most people will never manually check anything.

Your password manager

Bitwarden, 1Password, Proton Pass, Dashlane and Keeper all include a health report that flags breached, reused and weak passwords in one list. If you already use one, this is the most actionable view — it tells you not just what leaked but everywhere else you reused it.

Reading the results without panicking

A result tells you which breach, what year, and what data was included. That last part is what matters:

A breach from 2013 on a forum you abandoned matters less than one from last year on a service you still use with a password you still use. Judge by reuse, not by drama.

What to do, in order

  1. Change the password on the breached account — or delete the account if you no longer need it. Dormant accounts are liabilities.
  2. Change it everywhere you reused it. This is the step that actually matters. Attackers replay leaked pairs across hundreds of sites — see what is credential stuffing.
  3. Turn on 2FA on the accounts that matter, starting with email. A leaked password stops being useful the moment a second factor is required — Google, Microsoft.
  4. Check for hidden changes on any account you suspect: forwarding rules on email, altered recovery addresses, unfamiliar sessions, new payment methods.
  5. Start using a password manager so every password becomes unique. This removes the root cause rather than treating symptoms.
  6. Add passkeys where offered. There is no password to leak. See passkeys vs 2FA.

Tools to be careful with

Not every “check if you’ve been hacked” site is legitimate. Some are ad farms, some are lead generators for security products, and a few are collecting the addresses you type.

Rules of thumb: never enter a password into a site that does not explain how it protects it, be sceptical of anything demanding payment to “see full results”, and prefer tools that are widely referenced by browsers and security professionals. The same reasoning applies to browser-based security tools generally — we cover how to judge them in is an online 2FA code generator safe?

Dark web monitoring: worth it?

Banks, antivirus vendors and credit agencies all sell “dark web monitoring”. Most of it is checking the same public breach corpora that free tools use, wrapped in a subscription.

It is not fraudulent, but it is rarely worth paying for on its own. Free breach notification plus a password manager’s health report covers the same ground. Spend the money on a password manager instead — it fixes something rather than reporting on it.

Frequently asked questions

Is it safe to type my email into a breach checker?

On a reputable service, yes — the address is already in the breach data. Be more cautious about entering passwords, and only on tools that use partial-hash checking.

My email is in twelve breaches. Is that bad?

It is normal for an address more than a few years old. What matters is whether the passwords involved are still in use anywhere. Twelve breaches with twelve unique passwords is a non-event.

The site was breached but says passwords were encrypted. Am I fine?

Probably, if they used modern hashing. But “encrypted” in breach announcements covers a wide range, and companies rarely volunteer details. Change it anyway — it costs two minutes.

How often should I check?

Set up notifications and let them come to you. A manual check once a year is plenty on top of that.

Can I remove my data from a breach?

No. Once a database is circulating it cannot be recalled. You can only change what is changeable — passwords, and the security around them.

What if my password manager itself is breached?

Vaults are encrypted with your master password, which the provider does not hold. A strong unique master password plus 2FA on the vault keeps it secure even if the provider’s servers are compromised. More: do password managers get hacked?

The bottom line

Check your addresses, expect to find something, and let the results tell you where you reused passwords. Then fix the reuse and turn on 2FA — because a leaked password that opens only one account, and needs a second factor to do even that, is a footnote rather than a problem.

Ready to add the second factor? Start with our complete 2FA guide, or test a code with our free browser-based generator.

Leave a Reply

Your email address will not be published. Required fields are marked *