LeakNix
Security EducationSeptember 14, 20267 min read

Email Data Breach: What It Means and What to Do Now

Email data breach: what it means, how worried to be, what to do in the next ten minutes, and how to find out which password actually leaked.

By LeakNix

If your email address was in a data breach, it almost always means a website or app you once signed up to was hacked and its customer list leaked with your address on it. Your inbox itself probably wasn't touched. But if that site also leaked your password and you've used it anywhere else, your inbox is exactly where the trouble starts.

The fix is mostly passwords, and it takes less time than reading this page.

The short version

  1. Change the password on your email account to one you've never used anywhere else, and turn on two-factor authentication. An authenticator app beats text messages, and text messages beat nothing.
  2. Find out which breaches your address is in. Have I Been Pwned does this for free, or you can use our free scan.
  3. Change the password on each breached site, then on every account where you used the same password.
  4. Treat any email "about the breach" as suspicious until you've checked by going to the company's website yourself.

Your address can't be pulled back out of a leak, but you can make the leaked password worthless.

An email data breach usually means a website leaked, not your inbox

"Email data breach" means one of two things.

Most of the time you've had an alert, from Google, a password manager, your bank or a checker like ours, saying your address was "found in a breach". That means a company somewhere lost a copy of its user database and your address was one of the rows. It could be a shop you ordered from once, an old forum, a fitness app you forgot about. Your email provider has nothing to do with it.

The other meaning is that someone got into the email account itself. That looks different. Sent messages you didn't write. Password reset emails you never asked for. A sign-in alert from a city you've never been to. If you're seeing any of that, skip down to the section on locking down your email account and do it now.

The two are connected, and that's why the first kind matters. Your email account is where every other password reset lands, so whoever controls it can reset their way into your bank, your shopping accounts and your phone's cloud backup.

What leaked decides how worried to be

Breaches aren't all equal. As of 14 September 2026, Have I Been Pwned's public list holds just over 1,000 breaches covering about 17.8 billion accounts (accounts, not people, since most of us show up more than once). Nearly all of those breaches include email addresses, and about two in three include passwords. Those counts come from HIBP's breach API, so you can reproduce them yourself, and they go up most weeks.

Here's the rough order of how much it matters:

  • Your email address alone. Expect more spam and more phishing. Irritating, and rarely dangerous by itself.
  • Your email and a password. This is the one to act on. Criminals feed leaked pairs into software that tries them on other sites, which is called credential stuffing. If you reused that password, every account sharing it is exposed.
  • Your email plus name, phone number, date of birth or home address. There's nothing to change here, because you can't change your birthday. What it does is make scams convincing. A caller who knows your address and the last shop you used sounds a lot like the real company.

For that last kind, you'll see data removal services offered as the answer. They ask data brokers and people-search sites to delete your profile, which can be worth doing for its own sake. They can't touch a breach dump. Nobody can file a removal request with whoever is passing a stolen database around, so the best defence is knowing the details are out there and being slow to trust anyone who quotes them back to you.

Two details catch people out. Many sites store passwords "hashed", scrambled so they can't be read directly, but short or common passwords get unscrambled anyway, so don't take "hashed" as "safe". And old breaches don't expire. LinkedIn was breached in May 2012, and the 164 million accounts from it weren't added to Have I Been Pwned until May 2016, according to HIBP's record of that breach. If you still use a password from 2012, it's still a live problem.

Lock down the email account before anything else

Order matters here. If someone has your email password, changing your other passwords just sends the reset links to them.

Start by changing the email password to one you have never used anywhere else. A password manager makes that painless, and the one built into your phone or browser is fine. You don't need to buy anything for this step.

Then turn on two-factor authentication. A 2023 Microsoft study of Azure Active Directory accounts found it cut the risk of compromise by about 99% for accounts whose credentials had already leaked. Those were work accounts, not personal Gmail. The principle carries over, though: a stolen password on its own stops being enough.

While you're in the settings, look for what an intruder would quietly change. Check for forwarding rules you didn't set, filters that hide messages from your bank, and a recovery number or backup address you don't recognise. Both Google and Microsoft accounts show every signed-in device on their security page, and you can sign out the ones you don't recognise.

After that, change the password on the breached site, then on every other account that used the same one. That last part is the hard bit, because you need to know which password leaked.

Free checkers list the breaches, not the password

Have I Been Pwned is free and it's very good at its job. Put your address in and it lists the breaches you're in and what type of data each one exposed. Mozilla Monitor, which launched as Firefox Monitor, has used Have I Been Pwned's data since 2018 and is free too. If all you want is the list of breached sites, use either of them.

What neither shows you is the password itself. HIBP's FAQ states that no password is stored next to any email address, which is the right call for a public service. It does leave you guessing. If you've rotated through five or six passwords over the years, "you were in a forum breach" doesn't tell you which one is burned, or which of your current accounts still uses it.

That's the gap LeakNix fills. The free scan looks your address up in two breach indexes, merges what they find and tells you what turned up. The full report is a one-off $28.95, not a subscription, and it shows the actual leaked password wherever the source had one. When a breach only held a hashed password or none at all, there's no password to show you, and the report won't pretend there is. If you want to see how a leaked password result reads and what to do with it, our password leak check guide walks through one.

What "on the dark web" really means for your email address

"Is my email on the dark web?" is usually the real question. Every consumer checker, ours included, answers it from breach data that has already been found, gathered and indexed: a hit means your address was in a dump that has surfaced.

Google used to include a free dark web report in Google accounts, and it's gone. According to 9to5Google's report of Google's announcement in December 2025, scanning stopped on 15 January 2026 and the report was removed on 16 February 2026. Google's reason was that it "didn't provide helpful next steps".

So read any result for what it is. A clean result means nothing was found in what's been indexed, not that nothing exists. The LinkedIn gap above was four years. A clean scan is a reason to keep good habits, not to drop them. If you want the detail on how these collections get built, we've written about how leak websites work and what dark web monitoring really does.

What to do in the next ten minutes

Once your email account is locked down, run your address through our free scan and work down the breaches it lists, starting with any site where you know you reused that password.

The slower habits (a password manager, two-factor everywhere, spotting phishing that name-drops a real breach) are in our ten-step security checklist.

Check your own address

The scan is free, takes a few seconds and needs no account. It searches billions of leaked records and shows you which of your passwords are already out there.

Check my email