Reviewed September 2026.
Data breaches dump emails, password hashes, phone numbers, and sometimes more into criminal markets. A breach lookup tells you whether a specific address showed up in known public dumps. One widely used free lookup is Have I Been Pwned (haveibeenpwned.com), run by Troy Hunt. Other reputable password managers (1Password Watchtower, Bitwarden breach reports) and some browsers surface similar alerts. This page is how to check safely and what to do with a hit.
How to check without creating a new problem
- Type the lookup site URL yourself or use a bookmark. Do not tap a “check your breach status” link in a cold email.
- Enter one email address you control. Start with the inbox that receives bank resets.
- Read the result list: site names, breach dates, and data classes (password, phone, geolocation, etc.).
- If you use a password manager’s built-in monitor, review its alerts in the app you already installed.
- Optional: repeat for old Yahoo, AOL, school, and work addresses still tied to shopping accounts.
A clean result means “not in this database,” not “you are safe forever.” New breaches appear later.
What a hit actually means
| Result | Likely next risk | First move |
|---|---|---|
| Email only | Spear-phishing using your address | Expect fake “reset” mail; use bookmarks (Phishing) |
| Email + password | Credential stuffing on reused logins | Change that password everywhere it was reused |
| Email + phone | SIM-swap / SMS MFA targeting | Carrier PIN + port freeze (SIM-swap defense) |
| Email + password + other PII | Broader account takeover | Full containment checklist (ATO after a breach) |
Worked example: LinkedIn-era password still in use
Casey checks Have I Been Pwned for casey.mail@example.com. Hits include a 2012 breach with passwords and a 2024 retailer breach with emails and hashed passwords. Casey still used CaseySummer2012! on an old forum and a store card login.
- Casey changes the store card and forum passwords to unique 20+ character manager-generated secrets.
- Turns on app-based MFA on Gmail and the store card.
- Scans the password manager for other reuse of
CaseySummer2012!and rotates those too. - Skips a $29.99/month “dark web concierge” upsell; schedules a free AnnualCreditReport.com pull instead.
Next steps after any password-class breach
- Change the breached account password from a device you trust.
- Change every reused password (password managers make this realistic).
- Enable MFA on email first, then banks and brokerages; prefer app or hardware over SMS when offered.
- Turn on login alerts for email and money apps.
- If SSN or driver’s license data may be out, freeze Equifax, Experian, and TransUnion (Credit freezes).
- Treat follow-up “we will clean the dark web for a fee” calls as scams.
Paid monitoring vs DIY freezes: When should I get an identity theft protection service. Alert triage: Credit monitoring alerts without panic.
Checklist
- Look up your primary email on a known breach site you typed yourself.
- Rotate breached and reused passwords; unique password per site.
- Put MFA on email and financial accounts.
- Freeze credit if identity data classes were included.
- Ignore paid “dark web removal” cold outreach.
Educational only. Breach databases are incomplete; official issuer and bureau tools still matter. Have I Been Pwned is a common free lookup example.