Tutorials
9 min read

How to Check if Your Data Was Leaked in a Breach (2026 Guide)

Learn how to check if your data leaked in a breach using free tools, what a hit really means, and the exact fix order to secure your accounts fast.

Share:
How to Check if Your Data Was Leaked in a Breach (2026 Guide)

Every few months, some company you signed up with years ago loses control of its user database, and sooner or later that database turns up on a hacking forum or a file-sharing site. If you want to check if your data leaked in a breach, the tools to do it are free, take about two minutes, and are mostly built into software you already use. The results are usually less dramatic than people fear and more actionable than they realise.

This guide explains how breach-notification services actually work, what “your email was found in a breach” really means, and the exact order in which to fix things when you get a hit. It also covers why the paid dark web monitoring add-ons that antivirus companies, banks and card issuers keep pushing rarely justify the money. At TechLein we treat this as routine hygiene rather than an emergency: check once, fix what needs fixing, then set your accounts up so the next leak barely touches you.

Key takeaways

  • Free breach checkers tell you which services leaked your data, not that your account is currently hacked.
  • The real risk is password reuse, because attackers replay leaked email and password pairs across other sites.
  • Fix in order: change the password, sign out other sessions, turn on 2FA, then check recovery settings.
  • Paid dark web monitoring mostly repackages the same free data with alerts you can get for nothing.

What actually happens in a data breach

A breach is simply unauthorised access to a company’s stored data. That might be a misconfigured cloud storage bucket left open to the internet, an SQL injection flaw in an old web app, a stolen employee login, or a vendor with access to the main database. The attacker copies whatever tables they can reach, and those tables end up traded, sold, or eventually dumped publicly.

What leaks depends entirely on what the company stored. A shopping site might expose names, email addresses, phone numbers, delivery addresses and order history. A forum might expose usernames and password hashes. A poorly built service might expose passwords in plain text. Payment card numbers are less common in modern breaches because most merchants no longer store full card details, but it does still happen.

Crucially, a breach is a historical event. When a checker tells you your address appeared in a 2021 leak, it is describing something that already happened years ago. Panic is not the useful response; a methodical cleanup is.

How breach-notification services work

Services like Have I Been Pwned collect leaked databases as they surface, verify that they are genuine and not recycled fakes, then index the email addresses they contain. When you type in your address, the service simply looks up which indexed dumps contain it and tells you which company and what categories of data were involved. It does not show you your actual password, and a reputable service will never ask for one.

The password-checking features built into Google Chrome, Android, Apple’s Passwords app and Microsoft Edge work differently and more cleverly. They compare the credentials in your saved password vault against known leaked credential lists without ever sending your password anywhere. The usual technique sends only a short fragment of a cryptographic hash of the password, gets back a batch of candidate matches, and finishes the comparison on your device. That is why your browser can warn you that a specific saved password has appeared in a breach without your browser maker ever learning what it is.

The difference between the two checks

Email-based checkers answer “which companies leaked data about me”. Vault-based checkers answer “which of my current passwords are known to attackers”. The second is far more urgent. An old leak from a defunct shopping site matters very little if the password you used there is unique and retired. It matters a great deal if you still use that password on your bank and your email.

Where to check: tools worth using

ToolWhat it checksCostBest for
Have I Been PwnedEmail address against indexed breach dumpsFreeSeeing which services leaked your data, and subscribing to future alerts
Google Password Manager checkupSaved passwords for reuse, weakness and known leaksFreeAnyone who saves passwords in Chrome or on Android
Apple Passwords security recommendationsSaved passwords on iPhone, iPad and MacFreeApple users with iCloud Keychain enabled
Edge and Firefox built-in monitorsSaved passwords and, for Mozilla, email exposureFreeDesktop users who stay inside one browser
Dedicated password manager auditWhole vault: reuse, age, weak entries, breach matchesFree tier or paidPeople who want one audit covering every device

If you are choosing where your passwords should live in the first place, our comparison of what to look for in a password manager for Indian users goes through the trade-offs between browser-built-in storage and a dedicated app.

How to run the check, step by step

  1. List every email address you have ever used to sign up for things, including the old college address and the one you keep for junk mail.
  2. Search each address on a reputable breach-notification service and note which companies come up and what data types were involved.
  3. Subscribe that address to future notifications so you hear about the next leak without checking manually.
  4. Open your browser or phone password checkup and read the three lists it produces: compromised, reused, and weak.
  5. Sort the compromised list by how much damage the account could do. Email first, then banking and payments, then anything storing your address or documents, then everything else.
  6. Work down that list one account at a time rather than trying to fix forty logins in an evening and abandoning it halfway.

The real danger is credential stuffing

Attackers rarely bother trying to crack your specific account. They take millions of email and password pairs from old leaks and feed them into automated tools that try each pair against banks, email providers, shopping sites and social networks. If you used the same password on a hobby forum in 2019 that you use on your email today, that reuse is the entire attack. No malware, no phishing, no skill required.

This is why the single highest-value change is making every important password unique. It is also why a leak that exposed only your email address and a hashed password can still lead to a hijacked account years later. The same logic drives most of the advice in our broader online safety guide for India.

What to do after a hit, in the right order

  1. Change the password on the breached service to something long and unique. If you no longer use the service, change it anyway before you delete the account, since deletion is not always immediate.
  2. Change that password everywhere else you reused it. This is the step people skip and the one that matters most.
  3. Sign out all other sessions. Most major services have a “devices” or “where you are signed in” screen that ends every session except your current one. Changing a password does not always do this automatically.
  4. Turn on two-factor authentication, preferring an authenticator app or a passkey over SMS codes. Our two-factor authentication setup guide walks through doing this on Google, WhatsApp and banking apps.
  5. Check the recovery settings. Look at the recovery email address and phone number, any backup codes, and any security questions. Attackers who get in briefly often change these so they can return later.
  6. Review connected apps and forwarding rules on your email account specifically. A quiet forwarding rule is the most common way a compromise survives a password change.

If the breached account is a Google account and you have already lost access, the recovery process has its own quirks, which we cover in the guide to recovering a hacked Google account.

What you cannot change

Passwords are replaceable. Your date of birth, your permanent address history, your phone number and any identity document numbers exposed in a leak are not. You cannot un-leak them, so the sensible response is to assume that a determined scammer can obtain enough personal detail to sound convincing on a phone call.

Practically, that means treating unsolicited calls that quote your details as suspicious rather than reassuring. A caller knowing your last order or your address proves nothing. It also means keeping your phone number’s link to your bank accounts protected, because number takeover is a standard follow-up to an identity leak; our explainer on SIM swap fraud and how to protect yourself covers what that looks like in practice. Reducing what you hand over in the first place is the long game, and our notes on how to protect your privacy online are the starting point.

Is paid dark web monitoring worth it?

Most consumer dark web monitoring products are built on the same publicly circulating breach corpora that free checkers index, sometimes with extra sources for card numbers. What you are buying is packaging: a dashboard, scheduled alerts, and often a bundled insurance or restoration service. That has some value if you would genuinely never check manually, but it is worth knowing what it is.

Three honest limitations. First, monitoring is detection, not prevention; the alert arrives after the leak. Second, nobody can scan “the entire dark web”, so coverage claims are inherently loose. Third, the actions the alert prompts are the same free actions listed above. Before paying for a subscription bundled with an antivirus or card, check whether the free breach-notification alerts and your password manager’s audit already cover you.

Frequently asked questions

Is it safe to type my email into a breach-checking site?

On a well-established service, yes. It only needs an email address, and reputable checkers never ask for a password. Be wary of unfamiliar sites that ask for more than an address or push you towards a paid scan.

My email shows up in several breaches. Has my account been hacked?

Not necessarily. It means a company that held your address was breached. Your account is at risk mainly if you reused that password elsewhere or never changed it since.

Should I delete accounts on services that were breached?

Deleting dormant accounts is good practice regardless, because it shrinks the amount of your data sitting in databases you have forgotten about. Change the password first, then request deletion.

Does changing my password fix everything?

No. Also sign out other sessions, enable two-factor authentication, and check recovery email, recovery phone and mail forwarding rules. An attacker who was already inside may have left a way back.

What if my phone number leaked rather than my email?

Expect more spam and more convincing scam calls. Tighten the accounts that use SMS for verification, move them to an authenticator app where possible, and never read a one-time code aloud to a caller.

The bottom line

Checking whether your data leaked is genuinely a two-minute job, and the checkers are free. The work that follows is the part that matters: retiring reused passwords, switching on two-factor authentication for the accounts that would hurt to lose, and making sure recovery settings still point at addresses and phone numbers you control.

Do that once properly and future breach notifications become routine information rather than bad news. A leak of an address and a hashed password from a site you barely remember is only dangerous when the password behind it is still guarding something important. Break that link and you have removed most of the risk that breaches actually carry.

Tags:

TechLein Editorial Team - Author Profile

Chief Editorial Team

The TechLein Editorial Team is a collective of seasoned technology journalists, software engineers, and industry analysts with over 50 years of combined experience in tech journalism and software deve...

Credentials:

Certified Information Systems Security Professional (CISSP)AWS Certified Solutions ArchitectGoogle Cloud Professional Developer

More from TechLein Editorial Team

View all articles →