RESOURCES · SECURITY & EMAIL

Check if your email
has been breached

Worried your email or password is floating around on the dark web? You can check in a couple of minutes. Here's how to use Have I Been Pwned, how to read the result, and what to do if your address shows up.

Applies to: Any email account Time: ~5 minutes Level: Anyone
Quick answer

Go to haveibeenpwned.com, enter your email address, and it tells you which known data breaches included your details. If you appear, change the password on those services (and anywhere you reused it), turn on MFA, and start using a password manager.

WHAT IT IS

Why your email ends up on a list.

When a website is breached, lists of emails and passwords circulate online and get traded between attackers. Have I Been Pwned (HIBP) is a reputable, free service — widely used and referenced by governments and security teams — that indexes those breaches so you can check whether your address appears in any of them. Being listed doesn't mean you're being actively hacked; it means a service you used lost your data, and you should assume that password is now public.

HOW TO CHECK AND WHAT TO DO

Work through these in order.

  1. Search your email on the official siteGo to the official haveibeenpwned.com and enter your email address. It's free and you don't need an account to run a search.
  2. Read which breaches you appear inHIBP names each breach — the site involved and what data was exposed (email, password, phone number, and so on). This tells you how worried to be and which accounts to act on.
  3. Change the password on each affected serviceUpdate your password now — and, crucially, change it anywhere you reused the same one. Password reuse is the real danger: one leaked site becomes a key to all your accounts.
  4. Turn on MFAEnable multi-factor authentication on those accounts, especially email and banking. Even if a password leaks again, MFA stops someone signing in with it.
  5. Start using a password managerA password manager creates and remembers a unique, strong password for every account, so a single breach can never unlock the rest. It's the single biggest upgrade to your personal security.
  6. Set up breach alertsUse HIBP's "Notify me" feature to be alerted automatically if your address turns up in a future breach — so you find out early rather than months later.
  7. Ignore the "we've got your password" scare emailsTreat any resulting "we've got your password" emails as extortion scams. A breached old password showing up doesn't mean you're being actively hacked — change it, and don't pay or reply.
Only ever use the official site. Enter your email on the real haveibeenpwned.com, and NEVER type a working password into a random "breach checker" website — that's exactly how some scams harvest credentials. For a business, we can run proper dark-web monitoring across your whole domain (not just one address), so you're alerted the moment any staff credential leaks — it's included free in an IT Health Check.
SEE WHAT'S ALREADY OUT THERE

One address is a start. Your whole domain is the picture.

Checking your own email is smart — but attackers target every account in your business. Our free IT Health Check includes dark-web monitoring across your entire domain, plus a review of your passwords, MFA and sign-in security, so you can see exactly which credentials are exposed and shut the door on them.

KEEP READING

Related resources