If your email was found in a data breach, change reused passwords first, turn on two-factor authentication, then follow the playbook that matches what leaked: password, email-only or other personal details, or phone number. Use the first-hour list, then the 24-hour list. You cannot un-leak the file. Last updated: September 2026.
If your email was found in a data breach, do these five things in order: change the password on the affected account, change that same password everywhere you reused it, turn on two-factor authentication on important accounts, watch for phishing for the next 90 days, and read what else was exposed so you do not treat every leak like a password leak.
Jump to the playbook that matches your result:
- First hour
- First 24 hours
- Password exposed
- Email-only or other personal details, no password
- Phone number exposed
A match is a to-do list. It is not proof someone is inside your inbox right now. A clean check is a snapshot of industry-standard breach data sources, not a promise that nobody has a private copy.
What does it mean if your email was found in a data breach?
It means a company, app, or compiled list that held your email — and sometimes a password, name, phone number, or other details — was copied. Attackers, researchers, or both now have that row.
This does not automatically mean your email account itself was hacked. It often means someone else’s system failed, or your address was swept into a later compilation such as Collection #1. You still need to act, because reused logins are how an old shop leak becomes a 2026 inbox takeover.
The most urgent case is a password in the same record. The Verizon 2024 Data Breach Investigations Report again found stolen or guessed logins in a large share of web-application breaches. As of 2026, public checker catalogs cover on the order of a thousand named incidents and more than 12 billion compromised records. That is a lot of history. It is still not every private dump.
What should you do in the first hour after a data breach?
Stay on the sites you already use. Do not click “secure your account” links in a surprise email about the leak.
- Open the official site yourself. Type the address or use a bookmark. Change the password on the service named in the result, if it is a real company you can still log into. A compilation name is not a login page.
- Change that password everywhere you reused it. Start with email. Password resets go there. Then banking, then the social accounts you actually use.
- Turn on two-factor authentication on email first. An authenticator app is stronger than a text-message code.
- Write down what the result said was exposed. Password, email only, phone, address, or government ID. That line picks the playbook below.
- If you cannot get in, use the site’s own “forgot password” flow — not a link from an email that arrived today.
Do not spend the first hour deleting every old account, arguing with a company, or buying a “dark web removal” plan. Copies do not get recalled. You make the password useless.
What should you do in the first 24 hours after a data breach?
After the password and second-factor work, slow down and finish the list.
- Run a full email check so you see other named incidents, not just the one that scared you. If other people in the house use different inboxes, check those one at a time with their consent — check family emails for breaches.
- If a password might have leaked, use the password leak checker. It looks up a password without sending the full password to us.
- Review the account security checklist for recovery email, recovery phone, and leftover app access.
- If you need a password-change order a manager can finish, use password manager after a data breach.
- For authenticator app versus SMS, including SIM-swap when a phone leaked, use 2FA and passkeys after a data breach.
- Watch the inbox for urgent “verify now” mail. Go to the real site yourself.
- If a Social Security number or bank data was listed, call the bank and place a fraud alert or credit freeze. The official-source walkthrough is credit freeze after an SSN breach.
- If you are ready to retire a login you do not use, open the delete-account hub. For keep-versus-retire on the inbox itself, use email aliases after a data breach. That is day-one hygiene, not a substitute for unique passwords.
If Google used to mail you a Dark Web Report, that tool is gone. The replacement is a known-breach check plus this list — see what to use instead of Google Dark Web Report.
Check the address that was named. See if your email appears in known breaches → — free, no signup. We do not keep the address you type. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
What if a password was exposed in the breach?
Treat the password as public. Assume stuffing bots will try it on other sites.
Your new password should be long (16+ characters), random, and unique to that one site. Do not change Summer2024! into Summer2026!. NIST Special Publication 800-63B warns against those predictable tweaks and tells services to check new passwords against known leaked lists.
If you cannot log in because someone already changed it, use forgot-password through your email, then lock the email account too.
Then check every place you reused that string. Email, bank, social, shops with saved cards, work. The password leak checker is for the secret itself. The homepage checker is for the inbox. Use both if you reuse logins. The ordered change list — email, bank, reused sites, then 2FA — is the password-reuse change checklist.
A compilation match such as Collection #1 is this playbook even when no single company name feels “yours.” The file is a list of email-and-password pairs collected for stuffing. There is nothing to log into except the sites where you reused the password.
What if only your email or other personal details were scraped?
No password in the result is good news. It is not a free pass.
Email-only and profile scrapes are common. They confirm the address is real and often add a name, username, or date of birth. Attackers use that for phishing that mentions a service you recognise, or to stitch a people-search profile.
Do this:
- You do not need an emergency password reset on every site unless you reused the inbox password and are not sure it was ever leaked elsewhere. When in doubt, change the email password anyway. It is the master key.
- Turn on two-factor authentication on email if it is not on yet.
- Treat “we noticed a breach — click here” mail as hostile. Open the company site yourself.
- If a home address or government ID was listed, add the bank / credit-freeze steps from the 24-hour list. The longer official-source page is credit freeze after an SSN breach.
- Closing unused accounts still helps later. A leftover login with a weak password is how an email-only scrape becomes a takeover next year.
This is the quieter playbook. People skip it because it feels less dramatic. Phishing after a scrape is how quiet leaks get expensive.
What if your phone number was exposed?
A leaked phone number is a targeting tool. It is not the same as a stolen password, and it is not harmless.
Watch for smishing — texts that mimic a bank, delivery, or “your 2FA code.” Do not tap login links in texts. Do not read a code to anyone who called you.
Watch for SIM-swap signs: sudden loss of signal, a carrier text about a new SIM or a number transfer you did not request, or 2FA texts that stop arriving. Call the carrier from a number on your bill or the official app, not from a text.
Ask your carrier about a port freeze or account PIN. Move important accounts off SMS codes onto an authenticator app or a hardware key when the service allows it. The longer app-versus-SMS and passkey order is in 2FA and passkeys after a data breach.
If the same incident also listed a password, do the password playbook first. The phone steps are extra, not instead.
How long do you have before hackers use your data?
Not long for a fresh, reusable password. Stuffing tools test popular sites in hours after a dump becomes easy to download. In other cases the row is years old — Collection #1 still circulates in 2026 — and the risk is the password you never changed.
Speed still matters. The first-hour list is first for a reason. If you change a reused password before the next automated pass, the stolen string dies. Attackers move on.
Do not wait for a perfect understanding of the original hack. You rarely get one. You get a name, a date, and data types. That is enough to pick a playbook.
What information do hackers actually get?
Every incident is different. The line on your result matters more than the headline.
- Email addresses — almost every breach. Used for phishing and to join other lists.
- Passwords — sometimes plaintext, sometimes hashed. Weak or reused passwords get tested quickly.
- Names and dates of birth — identity and social-engineering fuel.
- Phone numbers — smishing and SIM-swap attempts.
- Home addresses — mail scams and identity-theft paperwork.
- Payment card details — financial fraud when they are actually in the file (often they are not).
- Security questions — used to bypass recovery on other sites.
The more fields you see, the more personal a phishing note can sound. An email-only row is still a reason to harden the inbox. A password row is a reason to cancel reuse today.
For a second free opinion after EmailLeaked, use the comparison in free data breach checkers. Different catalogs refresh on different days. If either tool finds you, follow the playbook. Browse the breach catalog when you want the story of a named incident, not just a row.
- First hour: official site, unique password, 2FA on email, note what leaked.
- First 24 hours: full email check, password check if needed, recovery settings, phishing watch.
- Password exposed: treat it as public; kill reuse; compilations are not a company login.
- Email-only or PII scrape: phishing risk; still lock the inbox; no fake “removal.”
- Phone exposed: smishing and SIM-swap watch; prefer app-based 2FA.
Want the list applied to your inbox? Check if your email was exposed →