Website activity leaked: what it means and what to do
Risk level: medium. Can you change it: no. Found in 77 breaches in this directory.
What this data is
Records of your actions on a website or app, such as pages viewed, searches, clicks, downloads, logins, cart activity, IP addresses and timestamps.
The risk on its own
Activity logs can reveal far more than a profile. Searches and page views may show health concerns, financial problems, sexual interests, job searches or legal issues. Timestamps and IP addresses can also reveal routines and approximate location.
The risk combined with other data
With your name or email address, website activity becomes a detailed behavioural profile. It can be used for extortion, targeted scams, discrimination or embarrassment. Security logs may also show which devices and locations you normally use, helping attackers mimic them.
How criminals use it
Searches for medical or adult content are used to extort you.
A phishing email mentions a product you recently viewed and asks you to complete payment.
Login times and IP addresses reveal when you are usually home or at work.
Job search activity is exposed to your current employer.
What to do now
Ask the company what activity data was exposed and whether IP addresses or searches were included.
Clear account history and turn off personalised tracking where the service allows it.
Use private browsing and a separate email for sensitive research or accounts.
Do not pay extortion demands based on browsing activity. Save the message and report it.
Review ad and tracking settings in Google, Meta and your browser.
Frequently asked questions
Can a website breach reveal my browsing history?
It can reveal activity on that website, including searches and pages viewed, but not your whole browser history unless tracking data was shared.
Does private browsing stop this?
It helps avoid saved history on your device, but websites can still record activity while you are logged in.
Should I be worried about IP addresses in activity logs?
They can show approximate location and network. The risk is higher if combined with your name and address.
Breaches that exposed this data
piZap: 2017-12-07, 42M accounts, Email addresses, Genders, Geographic locations, Names, Passwords, Social media profiles
Fling: 2011-03-10, 41M accounts, Dates of birth, Email addresses, Genders, Geographic locations, IP addresses, Passwords
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.