A data breach check is the fastest way to find out whether your email and password are already sitting in a criminal database. When a site you use gets hacked, those credentials can be traded online within hours, usually with no warning from the company that lost them. The scary part is not that breaches happen — it is that most people never check, so a leaked password keeps working for years.
I run this check on my own accounts every few months, and the first time I did it I found my main email in eight separate breaches. Three free tools scan billions of leaked records and show your exposure in under five minutes. Checking is step one; knowing what to do next is where the real protection comes from.
Quick Answer
Go to HaveIBeenPwned.com and enter your email address. If any breach appears, change that account’s password immediately to a unique, strong passphrase. Then turn on two-factor authentication for that account and for every other account that ever shared the same password.
What is a data breach check and why does it matter?
A data breach check compares your email address (or a password) against databases of credentials stolen in known hacks. If there’s a match, attackers may already have a working login for you. The RockYou2021 compilation alone held more than 8 billion unique passwords, many still tested against live accounts today through automated credential-stuffing attacks.
If you reuse passwords, one old breach can quietly hand criminals the keys to your current accounts.
How do I check whether my passwords were leaked?
The three tools below cover different angles: one checks email addresses, one checks the passwords saved in your browser, and one watches for new leaks over time. I use all three together because no single database is complete.
Method 1: Have I Been Pwned
Have I Been Pwned (HIBP), built by security researcher Troy Hunt, is the gold standard for breach checking. It indexes over 12 billion compromised accounts from thousands of breaches.
- Go to haveibeenpwned.com.
- Type your email address into the search bar and press pwned?
- A green result means no known breaches. A red result lists every breach your address appeared in, plus what was exposed — passwords, phone numbers, or home addresses.
- Click any breach name to read its description and the date it occurred.
- Repeat for every email address you use regularly.
To check a specific password, click Passwords in the navigation and type it in. HIBP uses a k-anonymity model — only the first five characters of a hashed version are sent, so your real password never leaves your device. I also clicked Notify me on the homepage so I get an automatic email the moment my address shows up in a future breach.
Method 2: Google Password Checkup
If you save passwords in Chrome or your Google Account, the built-in Password Checkup scans every stored credential against known breach data automatically.
- Open Chrome and navigate to chrome://password-manager/passwords.
- Click Check passwords at the top of the page.
- Google flags any saved password that was exposed in a breach, is too weak, or is reused across sites.
- For each flagged password, click Change password to update it on that site directly.
You can get the same results at myaccount.google.com/security-checkup under Password Manager. When the Check passwords button was greyed out for me, the fix was signing into Chrome and enabling sync under Settings > You and Google > Sync.
Method 3: Mozilla Monitor
Mozilla Monitor (formerly Firefox Monitor) queries the same HIBP database but adds a personal dashboard that tracks your exposure over time and emails you about new breaches.
- Visit monitor.mozilla.org.
- Enter your email address and create a free account.
- Mozilla shows every past breach linked to that address and watches for new ones automatically.
Run all three tools once, then let Google and Mozilla do the ongoing monitoring for you.
Which breach-checking tool should I use?
Each tool has a different strength, so the right choice depends on whether you want a one-time email lookup, an automatic scan of saved passwords, or continuous alerts. The table below compares all three at a glance.
| Tool | Email breach check | Saved-password check | Ongoing alerts | Free |
|---|---|---|---|---|
| Have I Been Pwned | Yes | Yes (manual) | Yes | |
| Google Password Checkup | No | Yes (automatic) | Automatic | Yes |
| Mozilla Monitor | Yes | No | Yes |
For most people, HIBP plus Google Password Checkup covers both your addresses and your saved logins.
What should I do when a breach shows up?
Finding your email in a breach list is a prompt to act quickly, not a reason to panic. Work through these steps in order.
- Change the compromised account’s password first. Use at least 12 characters and make it unique to that site.
- Find every account using the same password. Attackers run tools that test leaked passwords across hundreds of sites at once, so change every duplicate immediately.
- Enable two-factor authentication. Even with your correct password, 2FA stops an attacker from finishing the login. See my guide on how to set up two-factor authentication on your most important accounts.
- Switch to a dedicated password manager. It generates and stores a unique password for every site, ending reuse for good. Bitwarden is free and takes about 10 minutes to set up.
- Watch for targeted phishing. After a breach, criminals use the leaked data to craft convincing fake login requests, so learn to spot phishing emails before you click.
It is also worth checking that no attacker is already inside — you can find and remove unknown logins on Google, Microsoft, and Apple in a few minutes.
Reset the breached password, kill every reuse, and add 2FA — in that order — to shut the door fast.
Common Mistakes to Avoid
- Checking only one email address. Most of us collect two to four addresses over the years, and an old one you rarely open can still unlock active accounts through password-reset links. Fix: run HIBP on every address you’ve ever used.
- Changing only the breached account’s password. Every site sharing that password carries equal risk. Fix: search your password manager or memory for reused passwords and update each one.
- Dismissing old breaches. A 2019 leak still matters if you never changed that password, because stolen credentials are resold and tested for years. Fix: treat any flagged breach as urgent regardless of its date.
- Assuming a clean result means you’re fully safe. Not every breach is reported or indexed quickly. Fix: combine breach checks with unique passwords, a password manager, and 2FA.
- Typing passwords into unfamiliar “checker” sites. Unknown sites may be harvesting the passwords you paste in. Fix: use only the three trusted tools above.
Frequently Asked Questions
Is it safe to enter my email on Have I Been Pwned?
Yes. HIBP is maintained by security researcher Troy Hunt and is trusted by governments and cybersecurity agencies worldwide. When I checked my own address, only the email was submitted — no password or payment details are ever required.
What if my email doesn’t show up in any breach?
It means your address isn’t in the current databases, not that it was never exposed. A friend of mine got a clean result one month and a new alert the next, so I turned on notifications and kept using unique passwords as a precaution.
Can I check someone else’s email address?
You can enter any email in HIBP’s search, but the results only show breach names and dates. When I tested a family member’s address with their permission, no passwords or personal data appeared — just which breaches it was part of.
How often should I run a breach check?
Sign up for HIBP or Mozilla Monitor alerts so you’re notified automatically. I rely on those alerts and still do a manual sweep of all my addresses every three to six months.
Will changing my password remove my data from breach databases?
No. Once data is leaked it stays in those databases permanently. Changing your password simply means the exposed credential no longer works for logging in, which is exactly what locked an attacker out of my old forum account.
Do these tools work for business email addresses?
Yes. HIBP offers a free domain-wide search so IT teams can check every address on a company domain at once. I used it on a small client’s domain at haveibeenpwned.com/DomainSearch and found three exposed staff accounts in seconds.
Conclusion
A data breach check takes less time than making a coffee and can prevent account takeovers that take weeks to reverse. Check your addresses on Have I Been Pwned, run Google Password Checkup on your saved logins, and switch on alerts so you’re never caught off guard. Start with your primary email right now — then turn on 2FA before you close the tab.
Last updated: June 25, 2026