Start with the organization’s breach notice and verify it through a website or phone number you already know is legitimate. The notice should identify what information may have been affected and what steps to take. An email lookup can add context, but no single lookup can confirm whether every type of your personal data has—or has not—been exposed.
Start with the organization’s breach notice
If you received a notice saying your information may have been involved in a breach, read it for the organization involved, the information affected, and the response it recommends. Confirm that the notice is genuine: do not click an unexpected link or call a number in a message you are unsure about. Instead, contact the organization using a website or phone number you know is real. The FTC recommends visiting IdentityTheft.gov/databreach for guidance based on the type of information exposed.
A real notice is incident-specific: it can tell you what that organization says was affected. It does not establish whether the same information was exposed elsewhere.
Use lookup tools for what they can actually show
Check whether an email appears in Have I Been Pwned
Have I Been Pwned lets you search an email address against breach records loaded into its service. A match can provide details about the listed breach. A no-match result means only that the address did not match the records available there; it does not prove that the address was never exposed. The lookup is email-focused, not a comprehensive scan of all breaches or of other identifiers such as a Social Security number.
#1 Best Overall
Review credit reports and account activity for signs of misuse
Look for unfamiliar accounts on your credit reports and unauthorized transactions on bank and card statements. These checks can reveal signs that someone is using your information, but they do not identify every breach that may have exposed it. The FTC recommends monitoring reports and existing account statements. See its guidance on identity theft.
| Check | What it can establish | What it cannot establish |
|---|---|---|
| Organization’s notice and official channel | What the organization says was affected in its incident and its recommended response. | Whether your information was exposed in other incidents. |
| Have I Been Pwned email lookup | Whether the entered email appears in breach records loaded into the service. | Whether every breach or every kind of personal information is covered. |
| Credit reports and account statements | Whether unfamiliar accounts or transactions suggest misuse. | Which breach exposed information or whether no exposure occurred. |
Respond according to the information involved
Email address, username, or password
Change the password on the affected account and anywhere you reused it. Choose unique passwords for each account, and turn on multifactor authentication (MFA) where available. The FTC advises changing passwords promptly and suggests considering a password manager to help create and store unique ones. For MFA, the FTC identifies authenticator apps and security keys as stronger choices than common text or email codes when the account supports them. See How To Protect Your Personal Information and Use Two-Factor Authentication To Protect Your Accounts.
If you see signs that someone has taken over an account, use the provider’s official recovery process. Then review the account’s activity and recovery details and secure any other accounts that share the same credentials.
Payment-card or bank information
Contact your bank or card issuer using a trusted official channel and ask how to secure or replace the affected payment method. Watch statements for unauthorized transactions and report them to the provider. A credit freeze does not prevent someone from making fraudulent charges on an existing card or account.
Social Security number or other identity information
If your Social Security number or other credit-related identity information was exposed, consider a credit freeze. The FTC says freezes are free and must be placed with all three nationwide credit bureaus: Equifax, Experian, and TransUnion. A freeze lasts until you lift it and does not affect your credit score. It helps restrict new credit from being opened using your report, but it does not prevent all forms of identity theft or misuse of existing accounts. The FTC explains freezes and fraud alerts in Credit Freezes and Fraud Alerts.
Evidence of identity theft
If you find an unfamiliar account or other evidence that your identity is being misused, report it at IdentityTheft.gov and follow the personalized recovery guidance. Continue checking credit reports and financial statements for additional signs of misuse.
Credit freeze or fraud alert: which should you choose?
Both options are free, but they work differently. A freeze restricts prospective creditors’ access to your credit report; an initial fraud alert asks businesses to take extra steps to verify your identity before granting new credit.
| Option | How it works | Duration and setup |
|---|---|---|
| Credit freeze | Restricts prospective creditors’ access to your report and generally prevents new credit from being opened while active. | Lasts until you lift it. Contact all three nationwide credit bureaus. |
| Initial fraud alert | Asks businesses to verify your identity before granting new credit; it does not block access to your report. | Lasts one year. Place it with one bureau, which notifies the other two. |
Choose based on the protection you want and whether you are willing to lift a freeze when applying for credit. Neither option prevents fraudulent charges on existing bank or card accounts, so monitor those separately.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
Questions readers often ask
How would I know if someone is using my Social Security number or Medicare number?
Look for unfamiliar credit accounts and financial transactions, and review communications or account activity associated with the affected service. These checks may reveal misuse; they cannot prove that no exposure occurred. For suspected identity theft, report it at IdentityTheft.gov and use its recovery guidance. If a specific organization says your Medicare information was involved, contact it through a trusted official channel and follow its instructions.
Should I pay for identity monitoring?
First check whether the breached organization offers free monitoring, and ask what it covers before signing up for a paid service. Monitoring may help flag activity, but it does not remove exposed information from the internet and is not a substitute for securing accounts or responding to confirmed misuse.
Scope of this guidance
The steps here reflect U.S. federal consumer guidance. If you live elsewhere, use the relevant organization’s official instructions and your country’s identity-theft reporting and credit-protection processes.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

