Browsing histories leaked: what it means and what to do
Risk level: high. Can you change it: no. Found in 2 breaches in this directory.
What this data is
A list of web addresses you visited, often with dates and times, collected by a browser extension, an internet provider, a VPN, an ad network or an app with a built-in browser.
The risk on its own
A browsing history is one of the most revealing records that exists. Visits and searches show medical conditions, money trouble, sexual interests, job hunting, religious or political reading and legal worries, often before you told anyone. Even without a name attached, journalists and researchers have shown that a handful of visited pages can single out one person.
The risk combined with other data
Joined to your email or account it becomes a ready extortion file, because the attacker can quote exact pages and dates. It also exposes private share links for documents and photo albums, some of which still open for anyone holding the address. For someone in an abusive relationship it can reveal plans to leave or seek help.
How criminals use it
A sextortion email lists real adult sites from your history with dates and demands payment in cryptocurrency.
Unguessable share links for cloud documents and photo albums in the history are opened by whoever holds the list.
Visits to a clinic, a debt counsellor or a lawyer are used to pressure or embarrass you.
Scammers send fake loan, recovery or health offers based on exactly what you were reading about.
What to do now
Remove browser extensions you do not actively use, since many history leaks come from extensions that sold or lost data. In Chrome open the menu and choose Extensions; in Firefox open Add-ons and themes.
Stop sharing any document or album links that appear in the history, then create fresh links for the people who need them.
Clear stored history and set it to delete automatically: in a Google account go to myactivity.google.com, open Web and App Activity and choose Auto-delete.
If an extortion email arrives, do not pay and do not reply. Keep a copy and report it to your national cyber crime reporting service.
Use a separate browser profile for sensitive research such as health, legal or support services.
Delete the extension, VPN or app account that leaked the history if you no longer trust it.
Frequently asked questions
Someone emailed saying they have my browsing history. Is it real?
Most of these are bulk scams that bluff or quote an old leaked password as bait. If it lists genuinely specific pages, treat it as extortion: do not pay, keep the email and report it.
Does private or incognito mode protect me?
It stops history being saved on your own device. It does not hide visits from extensions, your internet provider, a work network or the sites themselves.
Can my history be deleted from the leak?
No. You can ask the company that held it to delete its copy and clear history at the source, which limits what the next breach can take.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.