Skip to content
Digital Life Check

Has my email been in a data breach? How to check and what to do

A free search shows which known breaches include your email address. Here's how to check safely, which passwords to change first, and what the organisation has to tell you.

Written by
Digital Life Check editorial team
Last checked
On this page
  1. What is a data breach?
  2. How do I check if my email was in a breach?
  3. Can I check whether a password has been leaked?
  4. What should I do if my email is in a breach?
  5. What if bank details or my identity were exposed?
  6. Does the organisation have to tell me?
  7. How do I complain about a data breach?
  8. Common questions

Quick answer: search your email address at haveibeenpwned.com, a free service the National Cyber Security Centre (NCSC) points to for this. If it shows up in a breach, change the password for that account and for any other account where you used the same password, turn on two-step verification, and watch for scam emails that mention the breach. Being in a breach does not mean someone has used your details, but it does mean reused passwords are no longer safe.

What is a data breach?

The Information Commissioner's Office (ICO) says a personal data breach happens when your information is no longer protected: when it is lost, accidentally destroyed, changed without permission, damaged, or accessed, disclosed to or kept by someone it shouldn't have been.

For most people, the practical risk is that an email address and password from one website end up in criminals' hands. If you used that password anywhere else, those accounts are at risk too.

How do I check if my email was in a breach?

Have I Been Pwned (haveibeenpwned.com) is a free service created and run by security researcher Troy Hunt since 2013. You type in one email address and it lists the known breaches that address appears in. The NCSC's guidance for individuals suggests using it to check whether your details have appeared in other public data breaches.

A few things to know:

  • It doesn't show your password. The service says no passwords are loaded alongside the email addresses in its breach database.
  • Some breaches are hidden from public search. Have I Been Pwned treats some breaches as sensitive, and only shows them after you prove you own the email address.
  • You can get alerts. Its free Notify me service emails you if your address appears in a future breach. The service says it stores only the email address, the date you subscribed and a verification token.
  • Type the address in yourself. Go to the site directly rather than following a link in an email.

Can I check whether a password has been leaked?

Yes. Have I Been Pwned also runs Pwned Passwords, which checks whether a password has appeared in a known breach. It says your password is hashed on your own device and only the first five characters of that hash are sent, so the password itself isn't sent anywhere.

If a password shows up there, the service's advice is that it should never be used again. Our Password Check runs entirely on your device and explains what makes a password hard to guess.

What should I do if my email is in a breach?

The NCSC sets out these steps:

  1. Confirm it with the organisation. Contact it through its official website or social media accounts, not through links in a message you were sent.
  2. Change the password for that account if you still use it.
  3. Change it everywhere else you used it. The NCSC says if any other account uses the same password, change that too. Start with your email account, because it can be used to reset everything else.
  4. Turn on two-step verification, so a leaked password alone isn't enough to get in. See what two-factor authentication is.
  5. Watch for scam messages. The NCSC warns that phishing can arrive some time after a breach becomes public: messages asking you to reset a password, offering compensation, or pushing you to act immediately.
  6. Check for signs someone has got in: you can't log in, security settings have changed, there are messages you didn't send, or logins from places you don't recognise. If your email account has been taken over, follow what to do if your email account is hacked.
  7. If you've lost money, tell your bank and report it to Report Fraud, or call 101 in Scotland.

Reusing passwords is what turns one breach into several hacked accounts. A password manager removes the need to reuse them. Our guide on how to choose a password manager covers the free options built into your phone as well as paid ones.

What if bank details or my identity were exposed?

If a breach included card or bank details, contact your bank. If it included details such as your date of birth and address, criminals may try to use them to open accounts in your name.

  • Check your credit file with all three credit reference agencies. Our guide to protecting yourself from identity theft explains how, for free.
  • Consider Cifas Protective Registration. The ICO notes you can apply to Cifas, the UK's fraud prevention service, to put a warning flag against your details. There is a fee.

Does the organisation have to tell me?

Not always. The ICO says that if a breach is likely to put you at risk, the organisation must inform you directly and as soon as reasonably possible. Whether it has to tell you depends on how serious the breach is and the harm it could cause, for example to your finances, wellbeing or safety. Where an organisation has to report a breach to the ICO, it must do so within 72 hours of becoming aware of it.

How do I complain about a data breach?

The ICO suggests going to the organisation first. You can ask it to explain what happened, what information was affected and what it plans to do to protect your information. The ICO says the organisation has 30 days to acknowledge your complaint, and should investigate, keep you informed and give you an outcome without unjustified delay.

If you're not happy with the response, you can then complain to the ICO.

Common questions

Is Have I Been Pwned safe to use?

It is a free service created and run by security researcher Troy Hunt since 2013, and the National Cyber Security Centre points people to it for checking whether their details appear in public data breaches. It asks only for an email address, doesn't show passwords, and its Pwned Passwords check sends only part of a scrambled version of your password, never the password itself. Go to haveibeenpwned.com directly rather than through a link someone sends you.

My email is in a breach. Have I been hacked?

Not necessarily. It means your email address, and sometimes a password or other details, were in data taken from an organisation. It becomes a problem if you used the same password elsewhere or if criminals use the details to target you with scam messages. Change any reused passwords, turn on two-step verification and look out for signs someone has logged in to your accounts.

Will the company tell me if my data is stolen?

The Information Commissioner's Office says an organisation must tell you directly and as soon as reasonably possible if a breach is likely to put you at risk. Lower-risk breaches may not be reported to each person, which is why a free check with Have I Been Pwned is worth doing yourself.

Should I reply to an email saying my data was in a breach?

Don't use the links, phone numbers or attachments in the message. The National Cyber Security Centre warns that scam messages often follow a publicised breach, asking you to reset passwords or claim compensation. Contact the organisation through its official website or app instead.

Sources

Last checked: 25 September 2026

  • Identity

    How to protect yourself from identity theft

    Your email, your post and your paperwork are the easy ways in for identity thieves. A few habits protect all three, and here is who to call if it happens.

    Last checked 22 September 2026