What to Do If Your Email Was in a Data Breach
Short answer
Find out what was exposed, not just that something was. An email address alone means more spam and nothing else. If passwords were included, change that password everywhere you reused it, starting with your email account, then turn on two-factor authentication. Credit monitoring is rarely the useful response.
On this page
Getting told your email address appeared in a data breach sounds alarming and usually is not. Email addresses are not secret. Yours appears in every mailing list, every contact list and every company you have ever bought from, and its exposure means you will receive more spam.
What matters is what came with it. A breach that exposed only addresses is a nuisance. One that exposed passwords is a genuine problem, and one that exposed identity documents is a different problem again. Those three need different responses, and conflating them is how people spend an evening changing fifty passwords for no reason.
Find out what was exposed
Go to Have I Been Pwned and enter your address. It is run by a security researcher, has operated for over a decade, and is used by security teams and government agencies. For each breach it lists the service, the date, and the specific categories of data involved.
That last part is the whole point of the exercise. Read the compromised-data list for each entry rather than the count at the top.
| What was exposed | Severity | Response |
|---|---|---|
| Email address only | Low | Expect more spam, nothing else |
| Email and password | High | Change it everywhere it was reused |
| Email and hashed password | Moderate to high | Change it; assume crackable |
| Name, address, phone | Moderate | Expect better-targeted scams |
| Date of birth, ID numbers | High | Watch credit file, add protections |
| Payment card details | High | Card almost certainly already reissued |
| Security question answers | High | Change them; invent new answers |
A note on hashed passwords, since breach notices lean on the word reassuringly. Hashing means the password was stored scrambled rather than in plain text. Done well, with a modern algorithm, that offers real protection. Done badly, with outdated methods, common passwords are recovered quickly. Breach notices rarely specify which, so treat any exposed password as exposed.
If a password was involved
Order matters here, because one account controls all the others.
1. Change your email account’s password first. Not the breached service’s. Your email is the reset mechanism for everything else you own, so it is the account whose compromise does the most damage, and it is the first one an attacker tries with a recovered password.
2. Change the password at the breached service, if you still use it.
3. Change it everywhere you reused it. This is the step that actually matters. Credential stuffing — trying the same email and password pair against hundreds of other services automatically — is why a breach at a forum becomes a compromised shopping account. The breach is the trigger; reuse is the mechanism.
Try to be honest about where you reused it. If you cannot remember, that is the argument for a password manager, which turns this question into a search.
4. Turn on two-factor authentication on the important accounts: email, banking, anything holding payment details. A leaked password becomes close to useless. Passkeys, where offered, are better still.
5. Check for persistence on your email account. Forwarding rules, filters that delete password-reset messages, connected apps and app passwords. An attacker who had access briefly leaves these behind and they survive your password change.
If identity details were involved
Name, address, date of birth and identity numbers cannot be changed, which is what makes this category different. You are managing consequences rather than closing a hole.
Watch your credit file. In the UK, the main agencies offer free statutory reports and several provide ongoing free access. Look for accounts or searches you did not initiate.
Consider a protective marker. CIFAS offers Protective Registration in the UK, and other countries have equivalent freezes or alerts. These require extra verification before credit is granted in your name, which is inconvenient deliberately. There is usually a modest fee or none at all — considerably less than a monitoring subscription.
Expect better-targeted scams. A caller who knows your address, date of birth and where you bank sounds legitimate. This is the practical consequence most people underestimate, and it is why recognising social engineering is more useful here than any monitoring product.
Change security question answers. Mother’s maiden name and first school are exactly what these breaches expose. Answer them with invented strings stored in a password manager; there is no rule requiring the truth.
If card details were involved
Usually the least work, because card fraud is the one category with a mature mechanism behind it.
The issuer has often already detected the breach and reissued the card. If not, ring the number on the back of the card and ask for a replacement. Check recent statements for small unfamiliar transactions, which are how stolen cards get validated before being used properly.
Card fraud is generally reversible. That is the central difference between this and a leaked password, and it is why a card breach deserves a phone call rather than an evening.
What is not worth doing
- Changing every password you own. Only the leaked one, and everywhere you reused it. Blanket changes consume the energy the real steps need.
- Deleting the breached account. The data has already left. Deletion is not recall.
- Paying for dark web monitoring. It tells you an address appeared somewhere, which Have I Been Pwned does free. The guided remediation has some value; the underlying data does not need buying.
- Changing your email address. Occasionally justified for an address buried in spam, and a very large amount of work for the exposure itself.
- Panicking about an old breach. A 2016 notification that you already acted on needs nothing further.
Preventing the next one from mattering
You cannot stop companies being breached. You can make it irrelevant when they are.
A password manager with unique passwords per site. This single change means a breach at one service exposes exactly one account. It is the highest-value security action available to an ordinary person, by a distance.
Two-factor authentication on anything that matters. A leaked password alone achieves nothing.
Aliases for new signups. A separate address per service means a leak tells you exactly who leaked it, and you can retire that address alone. The practical setup is in how to stop spam emails.
Breach notifications turned on. Have I Been Pwned will email you when your address appears in a future breach, and the browser password checkups do something similar. Covered in how to check if your password was leaked.
Realistic expectations
Most breach notifications need ten minutes: confirm what was exposed, change one password, check you have not reused it, move on.
The honest limitation is that exposed data does not expire. It circulates, gets combined with other sets, and resurfaces for years. You will receive more notifications, and some will concern breaches from before you had a password manager. The goal is not keeping your details out of these databases, which is no longer achievable. It is making sure that when they appear, the only thing an attacker can do with them is send you spam.