Check Whether Your Email Appeared in a Data Breach

Matthew Leo · September 26, 2026 · Guides

A woman reads the front of a printed notice at a kitchen table.

A company does not always know how to reach you after a breach. An old account may use an email address you rarely check, and a notice can be missed or mistaken for phishing.

You can search your address against known breach records without handing over the email account's password. The important part is understanding what the result does and does not prove.

Start with your email address, not your password

Have I Been Pwned lets you enter an email address and see whether it appears in breaches in its database. The normal search asks only for the address. It does not need the password for that email account.

Type the website address yourself or use a trusted bookmark. A page that asks you to sign in to your email provider, download a scanner or pay to reveal the basic result is not the standard public search.

Check every address you still use, including older addresses tied to shopping, gaming, school or work accounts. If you control your own domain, the service has a separate verification process for viewing addresses on that domain.

Read the breach details

A result normally identifies the service, the approximate breach date and the kinds of data involved. Those data classes matter more than the fact that an email address was listed.

The presence of an address does not mean someone currently controls the account. It means information associated with that address appeared in a dataset that the service has indexed.

The reverse is also important: a clean result does not prove that the address has never been exposed. A breach may be undiscovered, withheld from the public or absent from the database. Some sensitive breaches are handled differently to prevent the search itself from exposing a person's membership in a service.

Check your password manager too

Google Password Manager and Apple's Passwords app can warn when a saved password appears in known leaked-password data. These checks answer a different question from an email search. They look for compromised credentials stored in the password manager rather than every breach associated with the address.

In Google Password Manager, open Password Checkup from the official Google Account page. On current Apple devices, open the Passwords app and review Security recommendations.

A warning does not mean Google or Apple knows your complete account history. It means the saved credential matches information that its monitoring system considers compromised, weak or reused.

What to do if your address appears

  1. Go directly to the affected service. Do not use a password-reset link from an unexpected breach email. Open the app or type the known address yourself.
  2. Change a reused or exposed password. Make it unique. If the same password was used elsewhere, change those accounts too.
  3. Secure the email account first. Email can usually reset other accounts. Review recovery addresses, phone numbers, forwarding rules and signed-in devices.
  4. Turn on multifactor authentication or a passkey. Keep a separate recovery method. Mapletechie's passkey recovery guide explains how to avoid creating a new lockout risk.
  5. Review recent activity. Look for logins, purchases, messages, forwarding rules or account changes you do not recognize.
  6. Keep the breach notice. It may describe what was exposed, the organization's response and any credit-monitoring offer.

Do not change every password simply because an email address appeared in a breach years ago. Prioritize the affected service, reused credentials, email, financial accounts and any account capable of resetting the others.

When to check your Canadian credit reports

An exposed email address by itself does not require a credit freeze or paid monitoring. Take stronger steps when the breach includes a Social Insurance Number, financial data, government identification or enough personal information to support identity fraud.

The Office of the Privacy Commissioner of Canada recommends reading the notice, changing relevant passwords, monitoring accounts and considering credit alerts or reports when the risk justifies it.

Canadians can obtain reports from both major bureaus without paying for a subscription. Mapletechie's credit-report guide explains what to review and how to respond to an unfamiliar account.

Turn on future notifications

Have I Been Pwned offers email notifications for newly added breaches. Verification is sent to the address, which helps prevent someone else from enrolling you without access to the inbox.

Notifications are useful, but they are not real-time protection for every breach. Keep unique passwords, protect the email account and review important accounts after any credible notice.

Watch for breach-notice scams

Criminals use real breach news to send fake reset links. A legitimate-looking logo and correct personal detail do not make a message safe.

Open the organization's official app or website separately. If the notice offers credit monitoring, confirm the offer through a published company contact before entering identification. Do not send a password, verification code or full Social Insurance Number by email.

A breach search is a useful inventory tool. It tells you which known incidents deserve attention. It does not replace account recovery, password checks or credit monitoring when sensitive information was actually exposed.

Sources

Tags: Data breaches, Email security, Passwords, Identity theft, Cybersecurity

Read on Mapletechie