Was Your Email Hacked? Here's How To Check And What To Do

Affiliate disclosure: This article contains affiliate links. If you click a link and make a purchase, we may earn a commission at no extra cost to you. Our editorial recommendations are never influenced by commissions — read our full disclosure policy.
Start With the Address, Not the Inbox
There are two different questions people ask when they get worried about email, and they need different answers.
The first is whether your address has turned up in someone else's data breach. That is a question about a database somewhere on the internet, and you can answer it in about ninety seconds for free.
The second is whether your account is currently under someone else's control right now. That is a forensic question about sessions, forwarding rules and connected apps, and it is covered separately in how to check if you have been hacked.
This page is the first question. It is the one to start with, because an address in a breach is the raw material for almost every attack that leads to the second.
The Ninety-Second Check
Go to haveibeenpwned.com and enter your address. The site indexes breach data from a very large number of publicly known incidents, and it will tell you which of them contain your address.
On the question people always ask — what happens to the address you type in — the site's own FAQ says: "Nothing is explicitly logged by the website. The only logging of any kind is via Google Analytics, Application Insights performance monitoring…". That is the wording from the source rather than a paraphrase, and it is a fair reason to be comfortable running the check.
The name is a joke with a history. The FAQ explains that "the word 'pwned' has origins in video game culture and is a leetspeak derivation of the word 'owned', due to the proximity of the 'o' and 'p' keys. It's typically used to imply that someone has been controlled or compromised…".
Run the check for every address you use, not just the main one. That includes:
- The address you have had since school and still use for old accounts.
- Your work address, if you have ever used it for a personal signup.
- Any alias or forwarding address you set up and forgot about.
- The address on your domain, if you have one.
Reading the Result Honestly
The output is a list of breaches, each with a date and a list of what was exposed. That second part is the part that matters, and most people skim it.
| What was exposed | What it enables | What you should do |
|---|---|---|
| Email address only | Targeted phishing, spam | Nothing urgent. Be sceptical of mail referencing that service. |
| Email and password | Credential stuffing across every site | Change that password anywhere it was reused. Today. |
| Email, name, date of birth | Identity verification answers, SIM-swap groundwork | Harden the accounts that use those as recovery answers. |
| Email and phone number | SIM swap, smishing, account recovery abuse | Add a carrier port-out PIN. Move off SMS second factors. |
| Email and physical address | Physical-world fraud, convincing pretexting | Watch post for account confirmations you did not request. |
| Security questions | Direct account recovery bypass | Change the answers everywhere you reused them. |
A clean result is worth having and worth not over-reading. Not every breach becomes public, and not every public breach is indexed. "No results" means nothing has surfaced in the indexed set — it is a good sign, not a guarantee.
A result showing your address in a single breach from years ago, with the address alone exposed, is genuinely low-stakes. A result showing your address alongside a password in several incidents is a different situation, and the response below is not optional.
The One Response That Matters Most
If a password was exposed, the urgent question is not "was it this site's password" but "where else did I use it".
Attackers do not sit down and try to guess. They take a list of address-and-password pairs from one breach and replay it automatically against hundreds of other services, because password reuse is the default human behaviour and the technique works at scale. That is credential stuffing, and it is why one breach at a forum you have not visited since 2015 can end with someone in your bank.
So the response is: find every account where you used that password, or anything close to it, and change them all to something unique. If that sounds like an impossible amount of work, it is — by hand. It is the specific problem a password manager exists to make tractable, and the comparison of the good ones is the next step if you do not have one yet.
Prioritise in this order:
- The email account itself. Everything else resets through it.
- Banking, payment and brokerage accounts.
- Your password manager, if you already have one.
- Anything with a stored card or a saved address.
- Social accounts, because they are used to pivot into people who trust you.
Other Free Checks Worth Running
Your own providers know things about your account that no third-party index does, and looking is free.
Your email provider's security page. Gmail, Outlook and Proton all show recent activity, active sessions and the devices signed in. An unfamiliar city or a device you do not own is the single clearest signal that this has moved from question one to question two.
Your browser's password checker. Chrome, Firefox, Safari and Edge all compare your saved passwords against known breach corpora and flag reuse and weakness. It is imperfect and it is instant.
Your password manager's breach report. If you already use one, it does the same job across your whole vault rather than one browser.
Your bank's alerting. Turn on transaction notifications. Card fraud very often starts with a small test charge, and a push notification catches it in a way a monthly statement does not.
When Free Checks Stop Being Enough
Manual checking is a snapshot. If your address turns up in several breaches with meaningful data attached, the useful upgrade is something continuous — a service that watches breach corpora and the places stolen data is traded, and tells you when your details appear rather than waiting for you to think of checking. That category and what it does and does not deliver is covered in best identity theft protection 2026 and dark web monitoring explained.
Be realistic about what monitoring is for. It does not prevent a breach and it cannot remove your data from anywhere. What it buys is time — knowing early enough to change a password or freeze credit before someone else acts on the information.
Reducing the Surface Next Time
The address you hand out is the thing that gets breached. You can make that cost less.
- Use an alias service so each signup gets its own address. When one leaks, you know exactly which service leaked it, and you can switch that alias off without changing your real address.
- Keep a separate address for financial accounts and give it to nobody else.
- Do not use your work address for personal signups. You will lose access to it eventually.
- Unsubscribe from lists you do not read. Fewer senders means fewer databases holding you.
- Turn on a second factor everywhere it is offered, so an exposed password is not a complete key. The order to work through is in how to set up two-factor authentication.
What to Do in the Next Ten Minutes
Check your main address. Check your oldest address. If a password appears anywhere in the results, change it on your email account first and turn on a second factor while you are in there. Then work down the priority list above over the next few evenings.
That is genuinely the whole of it. The checking is fast and free; the changing is the part that takes time, and it is the part that actually closes the door.
The Honest Limits
A breach index can only tell you what has become known. Data traded privately, breaches never disclosed, and information scraped rather than stolen all sit outside it. Treating a clean result as proof of safety is the mistake to avoid.
The reverse is also worth saying: a long list of old breaches is not an emergency and it is not a verdict on you. Almost everyone with a decade of internet use is in several. What matters is whether a password was in them and whether you reused it — everything else on the list is context, not a crisis.
Covered in this guide
Reviewed by NorwegianSpark Editorial — written with AI assistance and reviewed by the NorwegianSpark SA editorial team · Last updated: 6 September 2026





