How to Check If Your Email Was in a Data Breach
If you have used the same email address for more than a year or two, the odds are high that it appears in at least one data breach. That is not a reason to panic — but it is a reason to check, and to know what to do next.
What a data breach actually is
A data breach happens when information a company stored about its users is exposed to people who were not supposed to see it. This can be the result of hacking, a misconfigured database left open on the internet, a malicious insider, or a third-party supplier being compromised. When it happens, the stolen data — often millions of records — is frequently traded or dumped publicly.
The records usually contain an email address as the primary identifier, alongside whatever else the service held: a password (sometimes as plain text, sometimes hashed), a username, a phone number, an IP address, a date of birth, or a physical address. Once a dataset like this is circulating, it does not disappear — copies persist indefinitely.
Why it matters even if "it's just an old account"
The single biggest risk from breaches is password reuse. If your email and password leaked from a forum you forgot about in 2016, and you used that same password on your email or bank, attackers can try those exact credentials everywhere else. This automated technique is called credential stuffing, and it works because most people reuse passwords.
Beyond passwords, exposed data fuels targeted phishing. An attacker who knows your name, the services you use, and your phone number can craft a message that looks convincingly real. The more of your data is out there, the easier you are to impersonate or deceive.
How to check your exposure
You can check whether your email appears in known breaches using free, reputable breach-notification services. MyRecon's email tool queries public breach databases and shows you how many breaches your address appears in, along with the categories of data that were exposed (passwords, phone numbers, and so on).
Do this safely. Only ever check your own email addresses, and only use services that look up an address against known breaches — never a site that asks you to enter your current password to "test" it. A legitimate checker never needs your password.
When you run a check, focus on two things: how recent the breaches are, and whether any of them exposed passwords. A recent breach that leaked passwords is far more urgent than a decade-old one that only exposed email addresses.
What to do if your email was breached
- Change the password on the breached service — and on any other account where you used the same or a similar password. This is the most important step.
- Use a password manager so every account gets a long, unique password you never have to remember. This single change eliminates the credential-stuffing risk entirely.
- Turn on two-factor authentication (2FA) everywhere it is offered, especially on your email, banking, and primary social accounts. Prefer an authenticator app or a hardware key over SMS.
- Watch for phishing in the weeks after a breach. Be sceptical of unexpected messages that reference real details about you or create urgency.
- Consider a fresh email for sensitive accounts (banking, government) that is different from the one you hand out publicly.
How to reduce future exposure
You cannot un-leak data that is already out, but you can limit how much new data accumulates. Use unique passwords, delete accounts you no longer need, and think twice before handing your real email to every website that asks. Email aliases and "plus addressing" (for example, you+shop@gmail.com) can help you compartmentalise and even trace which service leaked or sold your address.
Want the full routine? Read our guide on how to reduce your digital footprint, or run a quick self-check with the MyRecon email tool.