Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with the organization’s breach notice and verify it through a website or phone number you already know is legitimate. The notice should identify what information may have been affected and what steps to take. An email lookup can add context, but no single lookup can confirm whether every type of your personal data has—or has not—been exposed.

Start with the organization’s breach notice

If you received a notice saying your information may have been involved in a breach, read it for the organization involved, the information affected, and the response it recommends. Confirm that the notice is genuine: do not click an unexpected link or call a number in a message you are unsure about. Instead, contact the organization using a website or phone number you know is real. The FTC recommends visiting IdentityTheft.gov/databreach for guidance based on the type of information exposed.

A real notice is incident-specific: it can tell you what that organization says was affected. It does not establish whether the same information was exposed elsewhere.

Use lookup tools for what they can actually show

Check whether an email appears in Have I Been Pwned

Have I Been Pwned lets you search an email address against breach records loaded into its service. A match can provide details about the listed breach. A no-match result means only that the address did not match the records available there; it does not prove that the address was never exposed. The lookup is email-focused, not a comprehensive scan of all breaches or of other identifiers such as a Social Security number.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review credit reports and account activity for signs of misuse

Look for unfamiliar accounts on your credit reports and unauthorized transactions on bank and card statements. These checks can reveal signs that someone is using your information, but they do not identify every breach that may have exposed it. The FTC recommends monitoring reports and existing account statements. See its guidance on identity theft.

Check What it can establish What it cannot establish
Organization’s notice and official channel What the organization says was affected in its incident and its recommended response. Whether your information was exposed in other incidents.
Have I Been Pwned email lookup Whether the entered email appears in breach records loaded into the service. Whether every breach or every kind of personal information is covered.
Credit reports and account statements Whether unfamiliar accounts or transactions suggest misuse. Which breach exposed information or whether no exposure occurred.

Respond according to the information involved

Email address, username, or password

Change the password on the affected account and anywhere you reused it. Choose unique passwords for each account, and turn on multifactor authentication (MFA) where available. The FTC advises changing passwords promptly and suggests considering a password manager to help create and store unique ones. For MFA, the FTC identifies authenticator apps and security keys as stronger choices than common text or email codes when the account supports them. See How To Protect Your Personal Information and Use Two-Factor Authentication To Protect Your Accounts.

If you see signs that someone has taken over an account, use the provider’s official recovery process. Then review the account’s activity and recovery details and secure any other accounts that share the same credentials.

Payment-card or bank information

Contact your bank or card issuer using a trusted official channel and ask how to secure or replace the affected payment method. Watch statements for unauthorized transactions and report them to the provider. A credit freeze does not prevent someone from making fraudulent charges on an existing card or account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Social Security number or other identity information

If your Social Security number or other credit-related identity information was exposed, consider a credit freeze. The FTC says freezes are free and must be placed with all three nationwide credit bureaus: Equifax, Experian, and TransUnion. A freeze lasts until you lift it and does not affect your credit score. It helps restrict new credit from being opened using your report, but it does not prevent all forms of identity theft or misuse of existing accounts. The FTC explains freezes and fraud alerts in Credit Freezes and Fraud Alerts.

Evidence of identity theft

If you find an unfamiliar account or other evidence that your identity is being misused, report it at IdentityTheft.gov and follow the personalized recovery guidance. Continue checking credit reports and financial statements for additional signs of misuse.

Credit freeze or fraud alert: which should you choose?

Both options are free, but they work differently. A freeze restricts prospective creditors’ access to your credit report; an initial fraud alert asks businesses to take extra steps to verify your identity before granting new credit.

Option How it works Duration and setup
Credit freeze Restricts prospective creditors’ access to your report and generally prevents new credit from being opened while active. Lasts until you lift it. Contact all three nationwide credit bureaus.
Initial fraud alert Asks businesses to verify your identity before granting new credit; it does not block access to your report. Lasts one year. Place it with one bureau, which notifies the other two.

Choose based on the protection you want and whether you are willing to lift a freeze when applying for credit. Neither option prevents fraudulent charges on existing bank or card accounts, so monitor those separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Questions readers often ask

How would I know if someone is using my Social Security number or Medicare number?

Look for unfamiliar credit accounts and financial transactions, and review communications or account activity associated with the affected service. These checks may reveal misuse; they cannot prove that no exposure occurred. For suspected identity theft, report it at IdentityTheft.gov and use its recovery guidance. If a specific organization says your Medicare information was involved, contact it through a trusted official channel and follow its instructions.

Should I pay for identity monitoring?

First check whether the breached organization offers free monitoring, and ask what it covers before signing up for a paid service. Monitoring may help flag activity, but it does not remove exposed information from the internet and is not a substitute for securing accounts or responding to confirmed misuse.

Scope of this guidance

The steps here reflect U.S. federal consumer guidance. If you live elsewhere, use the relevant organization’s official instructions and your country’s identity-theft reporting and credit-protection processes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.