Email addresses leaked: what it means and what to do

Risk level: medium. Can you change it: yes. Found in 1035 breaches in this directory.

What this data is

The email address you used to register or log in. It is the most common field in breaches because it doubles as your username on most sites.

The risk on its own

An email address is not a secret, and most people have handed theirs out for years. On its own it brings more spam and phishing, and it confirms the address is real and active. Because it is also the username for many of your accounts, it is half of a login.

The risk combined with other data

Paired with a password from the same or another breach, it feeds credential stuffing: automated login attempts across many other sites, which succeed wherever you reused that password. With your name and the breached service, phishing can reference an account you really have. It is also the key that links your records together across different leaks.

How criminals use it

  • Bots try your email and leaked password on banking, shopping and streaming sites, and get in wherever you reused it.
  • A phishing email claiming to be the breached company mentions the breach and asks you to reset your password through a fake link.
  • Your address is signed up to a flood of newsletters so that a genuine fraud alert gets buried.
  • A sextortion email quotes an old leaked password to make a bluff sound real.

What to do now

  1. Change the password on the breached account and on every other account where you used the same password.
  2. Use a password manager so every account has a unique password, and test your important passwords with a password checker.
  3. Secure your email account first, since it can reset everything else: turn on two-factor authentication with an authenticator app or a passkey.
  4. Use email aliases for new signups, such as Hide My Email from Apple, Firefox Relay or SimpleLogin, so a future breach exposes an alias you can delete.
  5. Check the recovery phone number and backup email on your main email account, and review its recent security activity.
  6. Treat breach themed emails as suspicious and go to the company's website directly rather than following links.

Frequently asked questions

Should I change my email address after a breach?

Usually not. The address being known is not the real problem. Changing reused passwords and turning on two-factor authentication deals with the actual risk.

Why am I suddenly getting more spam?

Leaked addresses are traded and added to spam and phishing lists. Mark those messages as spam so your provider's filters learn, and avoid unsubscribe links in suspicious mail.

My email is in lots of breaches. Is that normal?

Yes, for anyone who has had the same address for a while. What matters is whether passwords leaked with it and whether you reused them.

Breaches that exposed this data

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.