Is my data exposed? How to check every kind of exposure

Breach / exposure. Updated 2026-09-13. About 6 minutes to read.

Check your main email first, and if its password appears in any breach or is used anywhere else, change it and turn on two-factor authentication before you do anything else.

Your data is almost certainly exposed somewhere. The useful question is which kind of exposure you have, because a breach, a leak, a scrape and a data broker listing each need a different fix. This guide shows you how to check all of them in about 30 minutes, and what to fix first.

Start with your main email address. It is the reset channel for every other account you own, so an exposed email address paired with a reused password is the most urgent problem you can find. Everything else can wait an hour.

Breach, leak, scrape or broker listing: four different problems

People use these words as if they mean the same thing. They do not, and the difference decides what you can do about it.

  • Breach: someone broke into a company's systems and copied its data, often email addresses, password hashes, names and phone numbers. The company usually has a legal duty to tell you. In Australia, for example, an organisation has 30 days to assess a suspected breach under the Notifiable Data Breaches scheme.
  • Leak: data was left open by mistake, such as a database with no password or a public cloud storage folder, and someone found and copied it. Nobody hacked anything, but once it is copied the result is the same as a breach.
  • Scrape: data was collected at scale from public or semi-public pages. The 2021 Facebook dataset of more than 500 million accounts was built by abusing a contact lookup feature. It held phone numbers for almost everyone but email addresses for only a few million people.
  • Broker listing: a people-search or marketing company compiled your name, address, phone number and relatives from public records and commercial data, and publishes or sells the profile. In most US states this is legal and it is not a breach at all.
  • Stealer log: malware on one of your own devices recorded the website, username and password as you typed them. Have I Been Pwned now indexes stealer logs, and a hit here means a device you use was infected.

Check your email and phone number against breach data

  1. Run your main email address through the free breach check on this site or through Have I Been Pwned. Write down each breach name, its date and the data types listed against it.
  2. Repeat for every address you have used in the last ten years, including old work, university and internet provider addresses.
  3. Search your mobile number in international format: country code first (1 for the US and Canada, 61 for Australia, 44 for the UK) and no leading zero.
  4. Subscribe each address to Have I Been Pwned notifications. Sensitive breaches, such as adult sites, are never shown in a public search and only appear after the service verifies that you own the address.
  5. Test your current passwords with a checker that uses k-anonymity, where only the first five characters of a hash of the password leave your device.

A real breach checker never asks for your email password. If a site asks you to log in to see your results, close it.

Look for scraped and leaked records the checkers miss

Breach search only covers datasets that someone has found, verified and loaded. Many leaks are never announced. Search your full name in quotes with your city, then your mobile number in quotes, then your personal email address, on Google and Bing.

Read any breach notification letters or emails you have received in the last two years, even from companies you barely remember. A letter often arrives weeks after the incident, so assume the exposure started earlier than the date on the letter.

Find your data broker listings

  1. Open a private browser window so your search history does not follow you onto broker sites.
  2. Search your full name plus your city or state on Google, and note every people-search result on the first two pages.
  3. Search directly on the big US sites: Whitepages, Spokeo, BeenVerified, FastPeopleSearch, TruePeopleSearch and Radaris.
  4. Copy the web address of every listing that matches you, including duplicates that show an old address or a misspelled name.
  5. Outside the US, check 192.com in the UK, Canada411 in Canada, and reverse phone sites such as Reverse Australia in Australia.

Never buy a background report on yourself. You can see enough for free, and paying creates an account record tied to your verified details.

The triage order: fix these in this sequence

  1. Email account: change the password if it appeared in any breach or is used on another site, turn on two-factor authentication, and check for forwarding rules you did not create.
  2. Reused passwords: a password that appears in a breach is burned everywhere. Change it on banking first, then shopping sites with saved cards, then social media.
  3. Financial and identity numbers: if a Social Security number, tax file number, passport or licence number was exposed, freeze or ban your credit file and follow the identity theft checklist.
  4. Phone number: add a port-out PIN or number lock with your carrier so the number cannot be moved to a criminal's SIM.
  5. Broker listings: opt out, starting with any site that shows your home address next to your phone number.
  6. Scraped social data: tighten profile visibility. You cannot recall copies already taken, but you can stop the next scrape.

What you cannot fix, and what to do instead

Nobody can delete breach data from criminal copies. Have I Been Pwned offers an opt-out, but it only hides your address from public search on that site. It does nothing to the copies already traded.

What you can do is make the stolen data useless: new passwords, a credit freeze, a reissued card and a locked phone number. Broker listings are different. They can be removed, but they come back, so plan to search yourself again every 90 days.

Keep watching without paying for it

  • Have I Been Pwned notifications for every email address you still use.
  • Breach alerts built into your password manager, including Chrome's Password Checkup and the security recommendations in Apple's Passwords app.
  • Transaction alerts from your bank and card issuers, set to the lowest amount they allow.
  • Free weekly credit reports from each US bureau at AnnualCreditReport.com.
  • A calendar reminder every 90 days to search your name and phone number again. Google's own dark web report was shut down in February 2026, so do not rely on it.

Frequently asked questions

Is it safe to type my email address into a breach checker?

Yes, if the checker only asks for the address. Your email address is not secret and is already in the breach data if you were affected. Do not enter your email password anywhere except the real login page of your email provider.

My email is in a breach. Does that mean I was hacked?

Not necessarily. It means your record was in a copied dataset. The risk is that the password from that dataset still works somewhere else. Change it wherever you used it and turn on two-factor authentication, and you have closed the main risk.

Why is my email in a breach from a site I never used?

Common reasons are an account you forgot creating years ago, a company that bought or merged with another service, a third-party supplier that held the data, or someone signing up with your address by mistake. Treat it as real and change any password it could share.

Can I get my data removed from a breach?

No. Once a dataset is copied and traded, there is no way to recall it. You can remove broker listings and delist search results, but for breaches the only fix is to change what the data gives access to.

How often should I check again?

Set up breach notifications once and they will email you when a new dataset appears. Search for broker listings every 90 days, because opt-outs do not stay removed forever.

Tools that help

Related guides

Sources