← All writing
Breaches

How to check if your email was breached, and what to do in the next hour

A breach check takes thirty seconds. Knowing which account to fix first, and finding the forwarding rule an attacker left behind, is the part that actually protects you.

To check if your email was breached, put the address into Have I Been Pwned. It will tell you which company lost a database containing your address, and roughly what was in it. That takes about thirty seconds, and it is the easy half.

The half that protects you is what comes next, in the right order. Most guides stop at "change your password", which is both incomplete and, on its own, sometimes useless — if someone is already inside the account, a new password does not evict them.

I am early in this field and I have spent the last few weeks reading how these lists actually get used. The thing that surprised me was how little the breach itself matters compared to one habit of yours.

What "breached" actually means

Your password was almost certainly not stolen from you. A company you signed up with lost its user database — through an unpatched server, a stolen employee session, a misconfigured storage bucket — and your row went with it.

What was in that row decides how bad it is.

Passwords are supposed to be stored as a slow hash: bcrypt, scrypt, Argon2. These are deliberately expensive to compute, so testing guesses against them is slow enough to be impractical at scale. Plenty of sites did it the cheap way instead — unsalted MD5 or SHA-1 — and those hashes fall to commodity hardware in bulk. When you read that a breach was "only hashed passwords", the hash algorithm is the entire story, and it is usually the detail the announcement leaves out.

Some breaches contain no passwords at all. An email, a phone number and an order history is still a good day for someone writing a convincing scam, which is why a "low severity" breach still deserves five minutes of your attention.

How to check if your email was breached

Three checks, in order of what they tell you.

  1. Your address, on Have I Been Pwned. Run by Troy Hunt, it is the reference index of known breaches. It names the company and the date, which is what you need to work out which of your old passwords was exposed.
  2. Your saved passwords, in your browser or password manager. Chrome, Safari, Firefox and every major password manager now flag saved logins that appear in known breach corpora, and the ones you have reused. This is more useful than the email check, because it points at specific accounts.
  3. Your phone number, on the same site, if you suspect you are getting targeted calls or messages.

A fair question about step two: why is it safe for a site to check a password it should never receive? Because well-built checkers do not receive it. The Pwned Passwords design hashes your password locally, sends only the first five characters of that hash, and gets back every stored hash starting with those five characters — hundreds of them. Your software does the final comparison on your own machine. The server learns the prefix and cannot tell which candidate was yours.

The rule that follows is worth keeping: a checker that asks you to paste the whole password into a web form is a different and much worse design. Do not use one.

The habit that turns one breach into ten

Attackers rarely care about the site they breached. They care that people reuse passwords.

The attack is called credential stuffing and it is unglamorous. Take the email-and-password pairs from one breach, point automation at a few hundred other login endpoints — banks, mail providers, shopping, streaming — and record which combinations work. No cleverness, no targeting, just volume. The success rate per site is tiny and completely irrelevant at that scale.

So the exposure is not the breach. The exposure is that the password from a forum you forgot about in 2019 is still the password on your email today.

Which leads to the ordering that most advice gets backwards. Fix your email account first — before the bank, before anything. Your email is the reset path for every other account you own. Someone holding it does not need your banking password; they can request a new one. It is the master key, and people protect it like a side account.

What to do, in order

Give this an hour. Do it in this sequence.

  1. Secure the email account itself. New unique password, then sign out all other sessions from the account's security page.
  2. Check for what was left behind. This is the step nearly every guide skips. In your mail settings, look at forwarding addresses, filters and rules, recovery email and phone, connected or third-party apps, and app passwords. A rule that silently forwards or auto-deletes messages matching "OTP" or "invoice" survives a password change and is how account takeover persists quietly for months.
  3. Turn on two-factor authentication, preferring a passkey or an authenticator app over SMS. SMS is better than nothing and weak against SIM swapping, which is a real and routine attack in India. Our post on passkeys vs passwords vs 2FA explains what each option actually stops.
  4. Save the recovery codes offline. Printed, or in your password manager's secure notes. Losing access to your own second factor is a more common disaster than being hacked.
  5. Then the money accounts, same treatment.
  6. Then kill the reuse. Let a password manager generate the rest. You do not need to change every password tonight — change the reused ones, and let the manager replace the others as you log in over the following weeks.

What this costs, honestly: an hour now, and a dependency on a password manager afterwards. That manager becomes a single high-value target, which is a real trade-off and not one I will talk you out of. It is still a far better deal than one password protecting forty accounts, because the manager is built for the job and your memory is not.

If money already moved

If someone has used this to take money or impersonate you, the response is different and time matters more than tidiness.

In India, report at cybercrime.gov.in and call 1930, the national cyber-fraud helpline. Reporting quickly gives banks a window to freeze the transfer, and that window is short. Tell your bank directly as well, and keep screenshots, transaction IDs and timestamps.

Nobody should feel stupid making that call. These operations are run at industrial scale by people who do this full time, and getting caught by one says nothing about you.

Frequently asked questions

My email appears in a breach from years ago. Does it still matter? Yes, if that password is still in use anywhere. Breach lists do not expire and get recombined into new collections for years. If the password is dead and the account is on two-factor authentication, you can stop worrying about it.

Have I Been Pwned says I am not affected. Am I safe? It means your address is not in the breaches that are publicly known and loaded. Plenty of breaches are never disclosed, and some are traded privately. Treat a clean result as good news, not as proof.

Should I pay for a dark web monitoring service? Usually not. Most of what they sell is the free check above on a schedule, wrapped in an alarming dashboard. Spend the money on a password manager instead, which actually changes your exposure.

Is it safe to let an AI assistant read my inbox? It is a bigger decision than it looks, because an assistant with access to your mail and the ability to browse or send can be instructed by content inside a message it reads. That combination is what the lethal trifecta is about, and it is worth reading before you grant one of these tools full mailbox access.

Will changing my password remove my data from the breach? No. The copied data is gone and cannot be recalled. Changing the password closes the door it opens; it does not retrieve anything.

Do one thing now

Open your email account's settings and read the forwarding and filter rules. Not the password page — the rules. It takes two minutes, almost nobody does it, and it is the single place where a quiet, long-running compromise shows itself.

If you found something there, work through the list above tonight rather than this weekend.

We publish this kind of thing for free on purpose, for reasons the founder wrote up in a note about why this studio exists.

BreachesPasswords