Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use separate checks for your email address and your passwords: a breach-search service can show whether an address appears in incidents it has indexed, while a password lookup can show whether a particular password appears in known exposed-password data. Either result is an exposure signal—not proof that someone has accessed an account. If a password is exposed, stop using it and replace it anywhere it was reused.

Check whether your email address appears in known breaches

  1. Go directly to Have I Been Pwned by typing the address into your browser or using a trusted bookmark. Do not use a login link in an unexpected breach-warning email.
  2. Enter your email address in the email lookup and review the result. If the service lists breaches, check the incident names and the types of data associated with each one.

A match means the address is present in data the service has loaded. The listed data types describe what is associated with a known incident; they do not show that an attacker currently has access to your account. A no-match means the service did not find the address in its indexed data, not that the address has never been exposed. Coverage depends on what the service has loaded.

Check a password separately

An email lookup does not tell you which password may have been exposed. Use the service’s separate Pwned Passwords lookup, or a reputable password manager’s security check, to check an individual password. Never send your password to an article, a person, or an untrusted form. If privacy handling is a concern, consult the service’s current privacy documentation; do not assume every lookup service handles data in the same way.

A password match means that password appears in known exposed-password data. It does not identify the account where it was used or establish that a particular account is currently compromised. Stop using a matched password, especially anywhere it was reused.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Check What it searches What a match establishes What to do
Email lookup An email address The address appears in the service’s loaded breach data. Review the listed incidents and data types, then secure relevant accounts.
Password lookup An individual password The password appears in known exposed-password data. Replace it on every account where it was used.

What to do if a password was exposed

  1. Change it on the service associated with the breach, if that service is identified.
  2. Change it anywhere else you used the same or a similar password. Start with important accounts and the email account used to recover other accounts.
  3. Use a different strong password for each account. A password manager can optionally generate and store unique passwords; you do not need one to run a breach lookup.

Secure accounts that may be affected

After changing credentials, follow the affected provider’s account-security options. The Federal Trade Commission recommends steps including signing out of other devices, enabling two-factor authentication, checking recovery details, and looking for email-forwarding rules you did not create. See the FTC’s account recovery guidance.

  • Sign out of active sessions on other devices.
  • Turn on two-factor authentication (also called multi-factor authentication) wherever it is offered. CISA explains that MFA makes unauthorized access harder even if a password is compromised; it is an added layer, not a guarantee. See CISA’s “More than a Password” guidance.
  • Confirm that the recovery email address and phone number are yours.
  • Check email settings for forwarding rules you did not create, and remove unauthorized ones.

If you cannot access the account

If you cannot sign in or someone changed the recovery details, use the provider’s official account-recovery process. Reach it through the provider’s known website or app, not contact links in an unexpected message. Once access is restored, change the password and secure the account using the steps above. The FTC also outlines actions to take when an email or social media account has been hacked.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret a result

An exposed email address alone does not prove that the mailbox was accessed or that identity theft occurred. Likewise, a breach-search match is not proof of current unauthorized access. Treat results as reasons to review and secure accounts, while remembering that a clean result cannot establish that no exposure has ever happened.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.