Risk level: medium. Can you change it: no. Found in 1 breaches in this directory.
Records of each sign-in to an account: date and time, IP address, approximate location, device and browser, and sometimes whether the attempt succeeded.
A login history maps your online routine: when you are active, which devices you use and roughly where you connect from, including home, work and travel. It cannot log in to the account. It can show patterns such as when you are usually asleep or away.
With your email and the account, an attacker learns your usual devices, locations and times, which helps them imitate you and slip past fraud checks that look for unusual sign-ins. It also shows which accounts you use actively, so they know where to aim. Travel patterns can reveal when your home is empty.
No. It does not contain your password. It helps an attacker who already has a password look more like you.
Most services list active sessions and recent sign-ins in their security settings, where you can also sign out of unknown devices.
For security monitoring, fraud detection and to show you recent activity. It is useful data, which is exactly why losing it matters.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.