Skip to main content

Protection

What to do when your details appear in a breach

A breach matters only where what leaked can be reused: passwords, security answers, card numbers and the links between your accounts.

Not every leak changes your risk. A leaked newsletter email list and a leaked customer database are different problems, because only one of them contains something an attacker can use against an account.

The useful first question is therefore not 'how many breaches was I in?' but 'what of mine is out there, and where is it still live?'

Classify before you panic

  • Passwords or password hashes: act the same day. Change the password at that service and anywhere else it was reused.
  • Security questions and answers: these are the ones people forget. If a mother's maiden name or a first car is exposed, the answer needs to change on every account that still asks it.
  • Card numbers and bank details: contact your bank and have the card replaced rather than watching for charges.
  • Address and identity documents: expect more convincing impersonation, and change how you verify callers and messages.
  • Contact details alone: lower urgency for you, higher for the people who will now receive targeted messages. Warn them.

Where exposure data is shown on this site, the source that supplied it is named there: XposedOrNot for email monitoring, and Pwned Passwords, operated by Have I Been Pwned, for the password check. The credit appears alongside the data itself, not on a separate page.

The order to work in

  • Email account first, because it can reset everything else.
  • Then any account sharing the leaked password, starting with the ones holding money.
  • Then accounts that use the leaked personal facts for recovery rather than for login.
  • Then older accounts, which are often the softest: they are unmaintained, and they still accept a login.
  • Then delete what you no longer use, so the list of things to protect stops growing.

Then check what is arriving

  1. 1Expect messages that reference the breached service by name. That is the exploitable part of a leak, and it is why they sound informed.
  2. 2Check the email address with the tool here and read the reasons, not only the score.
  3. 3Check any link in a suspicious message before opening it, because a familiar brand name is not a familiar domain.
  4. 4Check the phone number if the message asks you to call back, because a call-back request is often the whole attack.
  5. 5Do not answer security questions over the phone, however much of your own information the caller already has.

Frequently asked questions

Does being in a breach mean my account was hacked?

No. It means data was copied from one service. The account is at risk only where the leaked material can be used to sign in — which is why reused passwords and exposed security answers are the parts worth acting on immediately.

How can I tell which of my accounts is affected?

Start from the address rather than the account. If an address is exposed, every account using it inherits the risk, and accounts using the same password inherit it twice.

Should I close accounts at companies that leaked my data?

Where the account no longer serves you, yes — deleting it reduces what can leak next time. Where it is one you need, secure it and keep a record of the notification you received, which is useful if there is a later loss.

Written by The BaitScan team

Last updated September 16, 2026

Results are automated risk estimates based on public indicators and heuristics.