How to Check If Your Email Was in a Data Breach

Why This Matters
Your email sits at the center of almost everything online — password resets arrive there, and security alerts land there. If attackers have your email address, they have a verified email address they can build from. Data breaches expose billions of credentials every year, and chances are your email address has appeared in at least one. The sooner you know, the sooner you can take action.
The Best Tool: Have I Been Pwned
Have I Been Pwned (HIBP) is a free tool created by security researcher Troy Hunt that checks your email or phone number against a database of billions of leaked records. As of 2025, the site has information from over 900 breached websites and over 15 billion compromised accounts, making it one of the most comprehensive breach databases available to the public.
How to Use It
Getting started takes less than a minute:
- Go to haveibeenpwned.com
- Type your email in the search box and click the "pwned?" button
- The results appear within seconds
Understanding the Results
If the page is red, your email was found in at least one breach — you will see a list of breaches, including the company, date, and what type of data was exposed. If the page is green, your email was not found in any known breach.
The site will provide information such as when each data breach happened, the name of the affected company, what data was compromised, how the breach was discovered, and how many accounts were involved.
Built-In Browser and Password Manager Tools
If you prefer checking through tools you already use, several options are available:
Google Password Manager
Google Password Manager includes a native checker that reviews every password you've saved and flags any that appear in Google's list of known compromised credentials, with results displayed directly at passwords.google.com under "Checkup". However, Password Checkup only covers passwords saved inside Chrome, and has no visibility into breaches involving your email address on sites you never told Google about.
Firefox Password Manager and Monitor
When Firefox detects that a saved login may have been exposed in a known data breach, it shows a clear, private alert in your Firefox Password Manager. For broader checking, Mozilla Monitor gets its data breach information from a publicly searchable source, Have I Been Pwned.
You'll be greeted with an invitation to check an email address against known public data breaches, though you will need a Firefox account if you want to sign up for continued monitoring and alerts.
Other Free Breach-Checking Tools
Beyond Have I Been Pwned, several other free options exist:
F-Secure helps you check if your private information appears in known data breaches. CyberNews has a 500 GB database of leaked hashed emails. DataBreach.com allows you to search your email to see where your data was leaked and learn how to protect yourself. All these tools work similarly — enter your email and get instant results.
What to Do If Your Email Was Found in a Breach
If your email appears in a breach, the next steps matter more than the discovery itself:
Immediate Actions
Start with the breached service itself: sign in, change the password to something you have not used anywhere else, and sign out of all sessions if the service offers that option.
Change passwords for critical logins that use this email, starting with banking, payroll, tax, and major shopping sites. If the breach revealed that you've been reusing weak passwords across multiple sites, this is the moment to fix that for good.
Enable Two-Factor Authentication
Turn on MFA everywhere it's offered. App-based authenticators or passkeys are more secure than SMS alone.
Secure Your Email Inbox
Attackers may send phishing emails that reference the real breach, look for inbox rules, forwarding, or hidden filters, or use your email to quietly reset passwords elsewhere. Review your email settings for any unauthorized forwarding or suspicious activity.
Monitor for Fraud
Check what other data was exposed, such as a phone number, physical address, or financial information. Check your bank and financial accounts daily for unexpected activity and set up transaction alerts.
If sensitive financial data was included, consider placing a credit freeze with the major credit bureaus and pulling your credit reports to check for any suspicious activity.
Setting Up Ongoing Monitoring
If you want to stop manually checking, continuous monitoring services can alert you to future breaches:
With Firefox Monitor, you'll need a Firefox account to sign up for continued monitoring and alerts; after signing in, you'll land on a breach summary page that tells you how many data breaches that the email account has been associated with, and this page will also confirm how many email addresses are being actively monitored for future data breaches.
Have I Been Pwned also allows you to get notified when your email appears in future data breaches.
Most services scan continuously, with real-time alerts for new findings, constantly checking known marketplaces, forums, and data breach dumps while expanding coverage as new dark web sources emerge. Some services like Google and Experian offer free dark web monitoring services to scan for compromised data like your email addresses.
Important Things to Remember
Not all breaches are included in the database — a clean result doesn't guarantee your information was never compromised, only that it hasn't been found in publicly known breaches that Have I Been Pwned has indexed.
It can take time for data breaches to be discovered, verified, and added to public databases, so there may be a lapse of time between when the actual breach occurred and when Firefox Monitor alerts you.
The Bottom Line
Checking if your email was in a data breach takes minutes and costs nothing. Start with Have I Been Pwned, understand what was exposed, then take the targeted steps needed to protect your accounts. The difference between checking today and checking later could mean the difference between a quick password change and a full identity theft recovery.
