Skip to main content
FixMyTech

What to Do If Your Email Was in a Data Breach

By

Published

8 min read

Share

Short answer

Find out what was exposed, not just that something was. An email address alone means more spam and nothing else. If passwords were included, change that password everywhere you reused it, starting with your email account, then turn on two-factor authentication. Credit monitoring is rarely the useful response.

On this page

Getting told your email address appeared in a data breach sounds alarming and usually is not. Email addresses are not secret. Yours appears in every mailing list, every contact list and every company you have ever bought from, and its exposure means you will receive more spam.

What matters is what came with it. A breach that exposed only addresses is a nuisance. One that exposed passwords is a genuine problem, and one that exposed identity documents is a different problem again. Those three need different responses, and conflating them is how people spend an evening changing fifty passwords for no reason.

Find out what was exposed

Go to Have I Been Pwned and enter your address. It is run by a security researcher, has operated for over a decade, and is used by security teams and government agencies. For each breach it lists the service, the date, and the specific categories of data involved.

That last part is the whole point of the exercise. Read the compromised-data list for each entry rather than the count at the top.

What was exposed Severity Response
Email address only Low Expect more spam, nothing else
Email and password High Change it everywhere it was reused
Email and hashed password Moderate to high Change it; assume crackable
Name, address, phone Moderate Expect better-targeted scams
Date of birth, ID numbers High Watch credit file, add protections
Payment card details High Card almost certainly already reissued
Security question answers High Change them; invent new answers

A note on hashed passwords, since breach notices lean on the word reassuringly. Hashing means the password was stored scrambled rather than in plain text. Done well, with a modern algorithm, that offers real protection. Done badly, with outdated methods, common passwords are recovered quickly. Breach notices rarely specify which, so treat any exposed password as exposed.

If a password was involved

Order matters here, because one account controls all the others.

1. Change your email account’s password first. Not the breached service’s. Your email is the reset mechanism for everything else you own, so it is the account whose compromise does the most damage, and it is the first one an attacker tries with a recovered password.

2. Change the password at the breached service, if you still use it.

3. Change it everywhere you reused it. This is the step that actually matters. Credential stuffing — trying the same email and password pair against hundreds of other services automatically — is why a breach at a forum becomes a compromised shopping account. The breach is the trigger; reuse is the mechanism.

Try to be honest about where you reused it. If you cannot remember, that is the argument for a password manager, which turns this question into a search.

4. Turn on two-factor authentication on the important accounts: email, banking, anything holding payment details. A leaked password becomes close to useless. Passkeys, where offered, are better still.

5. Check for persistence on your email account. Forwarding rules, filters that delete password-reset messages, connected apps and app passwords. An attacker who had access briefly leaves these behind and they survive your password change.

If identity details were involved

Name, address, date of birth and identity numbers cannot be changed, which is what makes this category different. You are managing consequences rather than closing a hole.

Watch your credit file. In the UK, the main agencies offer free statutory reports and several provide ongoing free access. Look for accounts or searches you did not initiate.

Consider a protective marker. CIFAS offers Protective Registration in the UK, and other countries have equivalent freezes or alerts. These require extra verification before credit is granted in your name, which is inconvenient deliberately. There is usually a modest fee or none at all — considerably less than a monitoring subscription.

Expect better-targeted scams. A caller who knows your address, date of birth and where you bank sounds legitimate. This is the practical consequence most people underestimate, and it is why recognising social engineering is more useful here than any monitoring product.

Change security question answers. Mother’s maiden name and first school are exactly what these breaches expose. Answer them with invented strings stored in a password manager; there is no rule requiring the truth.

If card details were involved

Usually the least work, because card fraud is the one category with a mature mechanism behind it.

The issuer has often already detected the breach and reissued the card. If not, ring the number on the back of the card and ask for a replacement. Check recent statements for small unfamiliar transactions, which are how stolen cards get validated before being used properly.

Card fraud is generally reversible. That is the central difference between this and a leaked password, and it is why a card breach deserves a phone call rather than an evening.

What is not worth doing

  • Changing every password you own. Only the leaked one, and everywhere you reused it. Blanket changes consume the energy the real steps need.
  • Deleting the breached account. The data has already left. Deletion is not recall.
  • Paying for dark web monitoring. It tells you an address appeared somewhere, which Have I Been Pwned does free. The guided remediation has some value; the underlying data does not need buying.
  • Changing your email address. Occasionally justified for an address buried in spam, and a very large amount of work for the exposure itself.
  • Panicking about an old breach. A 2016 notification that you already acted on needs nothing further.

Preventing the next one from mattering

You cannot stop companies being breached. You can make it irrelevant when they are.

A password manager with unique passwords per site. This single change means a breach at one service exposes exactly one account. It is the highest-value security action available to an ordinary person, by a distance.

Two-factor authentication on anything that matters. A leaked password alone achieves nothing.

Aliases for new signups. A separate address per service means a leak tells you exactly who leaked it, and you can retire that address alone. The practical setup is in how to stop spam emails.

Breach notifications turned on. Have I Been Pwned will email you when your address appears in a future breach, and the browser password checkups do something similar. Covered in how to check if your password was leaked.

Realistic expectations

Most breach notifications need ten minutes: confirm what was exposed, change one password, check you have not reused it, move on.

The honest limitation is that exposed data does not expire. It circulates, gets combined with other sets, and resurfaces for years. You will receive more notifications, and some will concern breaches from before you had a password manager. The goal is not keeping your details out of these databases, which is no longer achievable. It is making sure that when they appear, the only thing an attacker can do with them is send you spam.

Frequently asked questions

Is Have I Been Pwned safe to use?
It is a long-established service run by a well-known security researcher and widely used by security teams and governments. Searching an address does not store a password, and the password checking feature is designed so your password is never sent to the site.
Should I delete my account at the breached company?
Usually not worth it, since the data has already left and deletion does not recall it. Change the password, remove any stored card details, and keep the account if you still use the service.
Do I need to pay for identity theft protection?
Rarely. Most of what these services provide — breach alerts and credit file notifications — is available free, and in the UK and many other countries you can freeze or add protective markers to your credit file yourself at no cost.
Why do I keep getting breach notifications years later?
Because breached data is often sold privately for a long time before being published, and researchers identify sources gradually. A notification in 2026 can concern a compromise that happened in 2019.
What is a credential stuffing attack?
Automated login attempts using email and password pairs from one breach against many other services. It works purely because people reuse passwords, which is why reuse — not the breach itself — is what turns an exposure into a compromised account.

All Security guides