Email Breach Check
Find out if your email appeared in known data breaches
What to Do If Your Email Was Breached
Step 1 — Change passwords on breached sites immediately
If your email appears in a breach from a specific service, go to that site and change your password right away. If you used the same password anywhere else, change it there too — attackers run automated tools that test leaked credentials across hundreds of services simultaneously (credential stuffing).
Step 2 — Check for password reuse
Password reuse is the reason one breach becomes ten compromised accounts. Search your password manager (or memory) for any site where you used the same password, and update each with a unique one.
Step 3 — Enable two-factor authentication
Enable two-factor authentication, starting with your email account. It reduces the risk of account takeover, but some methods remain vulnerable to phishing.
Step 4 — Use a password manager
Use a password manager to create unique passwords and review any breach reports available in your plan.
What is a data breach?
A data breach occurs when attackers gain unauthorised access to a company's database and extract user records — typically email addresses and hashed passwords, sometimes names, phone numbers, or payment details. These records are sold on dark web forums and used for credential stuffing attacks.
XposedOrNot is a public breach notification database that aggregates billions of records from hundreds of confirmed breaches. Unlike some services, it provides a free public API specifically to help people check their exposure without barriers.
What data is typically exposed?
- Email addresses and usernames
- Passwords (hashed or, in worst cases, plaintext)
- Names, phone numbers, physical addresses
- Dates of birth and security question answers
- IP addresses and device information
Related tools
If you find exposures, generate new passwords with the Password Generator and test their strength with the Password Strength Checker.