Is your email in a data breach? A ten-minute check, and what to do next
How to check whether your email, username or phone number shows up in a leaked database — and the practical steps that actually reduce the damage.
Most people are in at least one breach. That is not alarmism, it is arithmetic: services get breached constantly, and the lists get passed around for years afterwards. The useful question is not “am I in one” but “which one, what leaked, and what should I do this afternoon”.
1. Search what is actually yours
Search the identifiers you use to sign up for things: your main email, your phone number, and any username you have reused. Ask the assistant in plain language — “check my email for leaks” — or use the structured search if you prefer.
2. Read the result properly
A useful answer names the services affected, roughly how many records, and which fields were exposed. The fields are what matter most:
- Email only — annoying: expect more spam and better-targeted phishing. No password panic.
- Email + password — the one to act on today. Assume the password is known.
- Password + address or phone — worse. Expect phishing that quotes your real details.
- Card or bank details — act immediately, starting with your bank.
3. Do these five things, in this order
- Change the password on the breached account, and on every other account where you reused it. Reuse is what turns one breach into fifteen.
- Move to a password manager. This is the single highest-value hour you will spend on your security this year.
- Turn on two-factor authentication — app or hardware key rather than SMS where the service allows it.
- Check your email forwarding rules and recovery addresses. Attackers add those first, and they survive a password change.
- Expect phishing that quotes the leaked data. Someone writing to you with your real name, address and old password is not proof they are legitimate.
4. What not to do
- Do not paste the leaked password back into random “check if you were hacked” sites to compare.
- Do not pay for an identity-monitoring subscription before doing the five steps above. The subscription does not fix a reused password.
- Do not assume a breach you found years ago is closed. Old lists are still used for credential stuffing today.
Why we let you do this yourself
This search runs against our own private collection of leaked databases rather than a third-party lookup service, so your query is not handed to another company. We do not keep your conversations, and you can wipe your history whenever you want.
A breach check is only useful if it ends in a to-do list. Ten minutes here beats a year of worrying.
Try it on your own question
Free account, no card. Chat, code, images, security and OSINT work in one interface.
Start for free