Has My Email Been Hacked? Free Breach Check

Find every known data breach that includes your email address, see exactly what was taken, and get a plan in the right order.

Your address is looked up and stored only as a one way hash plus a masked copy. It is never sold or added to a mailing list.

When a company is breached, the stolen records usually include email addresses. Those lists get copied, sold and merged into bigger collections that circulate for years. Your address being in one does not mean someone is inside your account right now. It means your address, and whatever else that company held about you, is sitting in a dataset criminals use.

This check searches the publicly known breach datasets for your address and shows you every hit. Instead of a bare count, you get the date of each breach, how big it was, exactly which types of data were exposed, an exposure score that weighs how dangerous that combination is, and an action plan ordered by what matters most for your result.

How it works

  1. Enter an email address you own. It is sent over an encrypted connection to our server, and never placed in the page address, so it cannot end up in your browser history or someone else's logs.
  2. Our server looks the address up against breach datasets from Have I Been Pwned and XposedOrNot.
  3. Each breach found is matched to our directory of over a thousand publicly known breaches, which adds the breach date, the number of accounts affected and the full list of data types exposed.
  4. The results are scored for breadth, how many breaches; depth, the most damaging data types across all of them; and recency, whether any happened in the last two years.
  5. An action plan is built from what was actually exposed. Leaked passwords put password changes first. Identity details bring in credit freezes and broker removal. Malware log hits put a device scan ahead of everything.
  6. We keep a one way hash of the address and a masked copy such as ab***@example.com so your history works if you are signed in. The readable address is not stored.

Reading your results

  • Found in N breaches is the number of distinct datasets that contain your address. Older, more active addresses usually have more.
  • The exposure score runs from 0 to 100. Under 25 is low, 25 to 49 is moderate, 50 to 74 is high, and 75 or more is critical. Every point is explained in the reasons under the score.
  • With passwords counts breaches where passwords or password hints were taken. These are the ones that lead to account takeovers, so they drive the first actions in your plan.
  • With identity details counts breaches that exposed things like date of birth, home address, phone number or government ID numbers. These cannot be changed, which is why the plan points to credit freezes and removal rather than a quick fix.
  • From malware logs means your address was captured by infostealer software running on a device. That points to an infected computer or phone, not a company breach, and it needs a malware scan before you change passwords on that device.
  • What was exposed about you lists every data type across all your breaches, most damaging first. Each links to a page explaining what that data can be used for.
  • Not found in any known breach is good news with a limit. It only covers breaches that were published and indexed.

How this fits into the real world

The most common harm from a breach is not the breached company being attacked again. Criminals take the email and password pairs and try them automatically against email providers, banks, shopping sites and streaming services. Anyone who reused that password is exposed on every site that shares it. That is why the plan puts password changes, starting with your email account, at the top.

Breach data also makes scams convincing. A message that knows your name, the company you used and roughly when you signed up reads as genuine. Phishing campaigns increasingly quote real breach details, and callers pretending to be your bank may recite your address or date of birth to seem legitimate.

Some data does not expire. A password can be changed in a minute, but a date of birth, a home address or a government ID number stays true. When those appear in your results, the goal shifts from undoing the leak to making the data less useful: freezing credit so accounts cannot be opened in your name, and removing yourself from the people search sites that combine breach data into public profiles.

Checking again matters. New breaches are added every week. Rechecking after a large breach is in the news, or every few months, tells you whether a new dataset has added to your exposure.

Who this is for

  • Anyone who received a breach notification email or letter and wants to see the full picture.
  • People who noticed unexpected login alerts, password reset emails or account changes.
  • Anyone who has used the same email address for many years and never checked.
  • Families checking the addresses of older relatives who are more often targeted by scams.

What this tool cannot tell you

  • It only finds breaches that have been published and indexed. Private breaches, recent breaches still being investigated and data sold privately will not appear.
  • A hit means your address was in a dataset, not that your current password is known or that your account has been accessed.
  • Phone numbers are indexed in very few breaches, so this tool checks email addresses. Use the phone exposure audit for your number.
  • Breach checks do not show data brokers and people search sites, which publish addresses and phone numbers from public records rather than breaches.
  • Only check addresses you own or have permission to check.

Frequently asked questions

How do I know if my email has been hacked?

Enter the address above. If it appears in known breach datasets you will see each breach, what it exposed and when. Signs your actual account has been accessed are different: password reset emails you did not request, sign in alerts from unfamiliar places, sent messages you did not write, or new forwarding rules in your settings.

Is it safe to enter my email address into a breach checker?

Your email address is not a secret, since you give it to every site you use, so checking it carries little risk. What matters is how the checker treats it. We do not sell or share it, we do not add it to a mailing list, and we store only a one way hash and a masked copy.

What should I do if my email shows up in a data breach?

Change the password for that site, and for every other site where you used the same password, starting with your email account. Turn on two factor authentication on your email and banking. Then follow the plan on this page, which adds steps based on the specific data that was exposed.

If my email is in a breach, does that mean my account was hacked?

Not necessarily. It means your address was in a stolen dataset. If a password was also taken and you still use that password anywhere, those accounts are at real risk until you change it.

Can I get my information removed from a breach?

No. Once breach data has been copied and shared, it cannot be recalled. You can close the account with the breached company and ask it to delete your data, but the leaked copy stays in circulation. The practical defence is making the leaked data useless: new passwords, two factor authentication and a credit freeze where identity details were exposed.

What does pwned mean?

It is slang for compromised or defeated. It became the common word for appearing in a breach through the Have I Been Pwned service, which popularised checking email addresses against breach data.

Related tools

Guides that go with this tool