Data breach check
Companies get hacked, and the stolen data ends up in public collections. Checking whether your email address is in one takes a minute and tells you which passwords and details to worry about.
This page never asks for your email address. We do not run our own breach database, because storing other people's leaked data is a risk we do not want to take. Instead we send you to the two services we trust, and explain what to do with the answer. For passwords, our password checker can check a password without sending it anywhere.
Step 1: check your address
- Have I Been Pwned is the best-known service, run by security researcher Troy Hunt. Type your email address and it lists the breaches it appears in and what was taken. You can also sign up for free alerts about future breaches.
- Mozilla Monitor uses the same underlying data, with Mozilla's own alerts and guidance.
Check every address you use, including old ones. Those two sites are outside our control and will see the address you type, the same as any website would.
Step 2: read what was taken
| If the breach included | Do this |
|---|---|
| Passwords | Change that password now, and anywhere else you used it. Use a different long password for each site. Turn on two-factor authentication. Even hashed passwords can be cracked when they are weak. |
| Phone number or home address | Expect scam calls, texts and mail that use your real details to sound convincing. Do not trust unexpected contact, even if it knows your address. See Scams. |
| Date of birth, national ID or bank details | This is the serious kind. Watch your accounts, tell your bank, and where your country offers it, place a fraud alert or credit freeze. |
| Only your email address | Expect more spam and phishing. Change nothing else, but do not click links in unexpected mail. |
| Security questions or private messages | Change the answers wherever you used them, and assume the messages were read. |
Step 3: make the next breach matter less
- Use a password manager so every site has its own password. One breach then exposes one account, not all of them.
- Turn on two-factor authentication, preferably with an app or a security key rather than text messages.
- Use a different email alias per site, so a breach shows you who lost your address, and you can switch that one off. See the email alias guide.
- Delete accounts you no longer use. Data you no longer have with a company cannot be leaked by it.
Beware of fake breach checkers
- Scam sites copy the look of breach checkers to collect email addresses, or even passwords. Type the address of the real service yourself; do not follow a link from an email or ad that says you have been breached.
- Never type a password into a breach-check site. The one safe exception is a check built so the password itself is never sent, like ours.
- A real alert email from a service you signed up to will not ask for your password or payment details.
"Not found" does not mean "never breached". Many breaches are never made public. Take it as good news, not a guarantee. More in How your privacy is at risk and on the Resources page.