Somebody has told you that your email address is in a data breach. Perhaps a checking site returned a list of names you half remember signing up to, perhaps the company itself sent a carefully worded apology, perhaps your password manager put a red dot next to an entry you had forgotten existed. Either way you are now holding a piece of information that manages to feel urgent and vague at the same time.
The first useful thing to know is that an address appearing in a breach is not the same as an account being broken into, and neither of those is the same as your identity being stolen. Those are three different problems with three different responses. What matters is not really that your address is out there, because for most people it already was. What matters is what travelled alongside it, and what you do in the next few weeks.
The order below is deliberate. The early steps close the routes an attacker is most likely to try in the first days after a dump circulates. The later ones reduce what the next breach costs you, because there will be a next one. Most of this takes an evening. The step people skip, and the step where real money is lost, is number four.
Step one: confirm what actually happened
Start with Have I Been Pwned. It is free, it has been run carefully for years, and it is the closest thing the public has to an authoritative index of breached data. You type an address, it tells you which known breaches that address appears in. Its own documentation is worth a minute of your time: searches run over an encrypted connection and are not logged, the records it stores amount to the address plus a list of the sites it appeared on, and no passwords are loaded alongside those addresses.
What you want from that search is not the emotional hit of seeing a list. It is the detail underneath each entry. Every breach record names the data classes that were exposed, and that decides how much of the rest of this checklist applies to you. An address and a display name is an annoyance. An address and a password hash is a live problem. An address, a home address, a phone number and a partial payment card is a phishing kit assembled for somebody else's convenience.
Two limits are worth holding in mind. Some breaches are classed as sensitive, because being listed in them could harm someone, and those can only be searched by the verified owner of the address rather than by anyone typing it into the public box. And no index is complete: plenty of breached data never surfaces, or surfaces years later. A clean result means nothing known, not nothing happened.
There is one more trap here. If you learned about the breach from an email or a text, treat that message as untrusted until proven otherwise. The UK's National Cyber Security Centre is direct about this: check with the organisation through their official website or social media channels rather than through the links or contact details in whatever arrived in your inbox. Breach notifications are easy to fake, and the fake ones arrive at exactly the moment you are primed to believe them.
Before moving on, write down three things: which sites, which data classes, and roughly when. Everything below is easier with that list in front of you.
Step two: change the passwords that matter, and get a password manager
Not all of them. There is a version of this advice that tells you to change every password you own, and it is bad advice, because it is exhausting enough that most people do a third of it badly and then stop. Change these, in this order:
- The password on the breached site itself.
- The password on your primary email account, if it is anything you have ever used elsewhere.
- Every account where you reused the breached password, or something recognisably similar to it.
That third category is the whole ballgame. Attackers rarely care about your account on a forum that closed in 2019. They care that the password from that forum still opens something valuable. The NCSC describes credential stuffing plainly: the technique takes advantage of people reusing username and password combinations across different accounts, so valid pairs harvested from one site can be tried automatically against many others. Your address is the constant that lets them line the attempts up.
Whatever you replace those passwords with should be unique per site and long. NIST's digital identity guidance spent a decade arguing against the rules most sites still enforce. It says verifiers should not impose composition rules such as requiring mixtures of character types, should not force arbitrary periodic changes, but must force a change where there is evidence of compromise. It also says new passwords must be checked against lists of values known to be commonly used or compromised, including passwords obtained from previous breach corpuses. In plain terms: length and uniqueness beat punctuation, and a password that has appeared in a breach is finished permanently.
Nobody can invent and remember thirty unique long passwords. A password manager is the only realistic way to hold this shape, and which one you pick matters far less than starting. The browser built-ins from Apple, Google and Mozilla are free and sync across devices.
While you are in there, look for passkeys. Google's own description is the clearest short explanation of why they differ: unlike passwords, passkeys cannot be shared, copied, written down or accidentally given to someone else, which makes them more resistant to phishing. A passkey cannot leak in a breach the way a password can, because the site never holds the secret that signs you in. Where a service you care about offers one, take it.
An address in a breach is an inconvenience. A reused password in a breach is an emergency, and the difference between them is entirely under your control.
Step three: two-factor authentication, starting with your email
Your email account is not one account among many. It is the reset mechanism for all the others. Anyone who controls it can walk through your bank, your cloud storage and your domain registrar at their leisure, using nothing more sophisticated than the forgotten password link. Secure it first, and properly, before working outwards.
Prefer an authenticator app or a hardware security key over SMS codes. This is not general paranoia about text messages, it is a documented weakness: NIST classifies use of the public telephone network for out of band verification as restricted, and tells verifiers to weigh risk indicators such as device swap, SIM change and number porting before relying on it. A phone number is one of the fields that turns up in breach data constantly. SMS is still far better than nothing. It is simply the weakest of the good options.
Then do the unglamorous part. Generate your recovery codes and store them where you will still reach them when your phone is lost, stolen or dead, which usually means your password manager. Lockouts are the most common way second factors go wrong, and the fix is five minutes of preparation now.
Work outward in order of blast radius: email, then anything holding money, then anything holding identity documents, then the rest.
Step four: expect the phishing wave, because that is where the losses happen
Most breach checklists end at passwords and two-factor. That is usually the point at which the actual attack begins.
Here is the mechanism. A breach file rarely contains only addresses. It contains names, phone numbers, physical addresses, order histories, account numbers, the last four digits of a card, sometimes support tickets in which you described your own problem in your own words. None of that is enough to log in as you. All of it is enough to write a message that sounds exactly like a company you deal with, referencing a purchase you actually made, addressed to the name you actually use. The credential is not the product. The context is.
So the mail arrives, days or weeks or months later, and it is good. The NCSC's guidance lists the shapes it takes: official sounding emails about resetting your password, about receiving compensation, about a device scan or about a missed delivery, often full of technical language, usually pressing you to act immediately. Add the phone call from a fraud team that already knows your last transaction, and the extortion email quoting a real old password of yours as proof of an intrusion that never happened. That last one has become an industry of its own, and it is worth seeing how those campaigns are assembled from recycled dumps before one lands in your inbox.
Three rules survive contact with all of it:
- Never act on a link or a phone number that came inside the message. Navigate to the site yourself, or ring the number printed on your card. This single habit removes the attacker's control of where you end up, which is what most of these messages depend on.
- Treat urgency as evidence against, not evidence for. Real organisations are slow. Deadlines measured in minutes are a technique.
- No legitimate breach response ever needs your password, your full card number, your recovery codes or remote access to your machine.
If you have already clicked something, do not spend the evening being embarrassed. Change that service's password from a different device, open its active sessions list and sign the others out, and watch the linked payment method closely. Speed matters much more than dignity. If money moved, tell the bank first and the national fraud reporting service second.
Step five: check the accounts that hold money
Log in to your bank, your card accounts and any payment wallet you use, and read the recent transactions properly rather than skimming for something large. Card testing usually starts small, because a tiny charge that goes through tells the person holding the number that it is live and worth selling on. Look for amounts you cannot place, subscriptions you do not remember starting, and any change to the contact details or delivery addresses on the account itself.
If the breached site held your card, ask the bank to reissue the number rather than waiting to see what happens. A couple of subscriptions will need updating, and the old number stops being worth anything to whoever has it. If the breach included bank account details or government identifiers, escalate, because those cannot be reissued as easily and the fraud that follows them is slower and more damaging than a cloned card.
In several countries you can also freeze or restrict your credit file, which makes it harder for anyone to open new credit in your name while leaving your existing accounts working. Check what your national credit agencies offer and what, if anything, it costs. Set that up through the credit agency's own site rather than through any service that emails you to offer it. And turn on transaction alerts if your bank has them: being told about a payment as it happens turns a month of undetected fraud into an afternoon of it.
Step six: from now on, give every site its own address
Everything above is cleanup. This is the part that changes the arithmetic for next time.
The structural problem is not that one company was careless. It is that you have handed the same identifier to every company for years, which makes that identifier a join key. Your address is what lets a marketing broker merge the list from the shop with the list from the newsletter with the list from the app, and what lets an attacker holding four separate dumps assemble one person out of them.
The fix is to stop having one address. Forwarding aliases are the practical version: you generate a distinct address per site, mail sent to it is forwarded to your real inbox, and the site never learns where the mail lands. Apple's Hide My Email is the version many people already own, since iCloud+ generates unique random addresses that forward to your real account and lets you deactivate the ones you no longer want. Independent providers do the same with more control, and if you have your own domain you can run the scheme on it. The idea is duller than the marketing suggests, and it is set out properly in what an email alias actually is.
Two honest caveats, because this is sold badly by nearly everyone who sells it. First, it does nothing for the address that has already leaked. Aliases are forward looking, and anyone implying otherwise is selling you a time machine. Second, it introduces a dependency: your mail now passes through another party, and if that party disappears, every address pointed at it stops working. Using your own domain removes most of that risk.
There is a cheaper sounding alternative that mostly fails, which is opening a second free mailbox for signups. It collapses within a year into two inboxes with the same problem, and it is worth understanding why the second account does not save you before spending the year finding out. Expect too that a small number of sites reject alias domains at signup, which is covered in what to do when a site refuses your alias.
Step seven: kill what is already burned
The leaked address will keep receiving whatever the leak generates. You can shrink that surface rather than living with it.
Start with accounts, not mail. Every dormant account attached to that address is a small hostage: it holds data you have forgotten about, it will be breached eventually, and it is one more record sitting in a database nobody maintains. Close the ones you do not use. Deleting an account is nearly always more effective than unsubscribing from its mailings, because it removes the record as well as the mail.
Where the account has to stay, unsubscribe through the site's own preference page rather than through links in mail you did not expect. In the UK and the EU you can additionally ask an organisation to erase the personal data it holds on you, though that right is not absolute and there are lawful grounds to refuse, so treat it as a strong request rather than a switch.
If the leaked address is an alias, this is where the design pays off: you switch it off and the problem ends. If it is your main address, be realistic about the cost of replacing it. A primary address is woven through your bank, your two-factor recovery and every contact who has ever written to you, and a big bang migration usually fails halfway. The workable version is a slow wind down: point new signups at fresh per site addresses, move important accounts one at a time as you happen to log in, and let the old address decay into something you check occasionally rather than live in.
Step eight: set up monitoring so the next one finds you
You will not remember to check this again. Nobody does. So make it automatic.
Have I Been Pwned will notify you when your address appears in a future breach, and its documentation notes the subscription stores only the address, the date you subscribed and a random token. It cannot monitor addresses you do not control, for the obvious privacy reason. Most password managers now include a breach monitor too, and browser based ones will flag saved passwords that turn up in known dumps. Turning one of these on is enough.
If you own a domain, the domain wide search is the most useful version, because it tells you which per site address leaked, which in turn tells you which company failed. That is more than a single personal address will ever give you, and it turns a vague suspicion into a name. There is a longer discussion of that detective work in how to work out which company leaked your address.
Finally, do one pass over the security pages you touched today and use whatever active sessions or recent activity view they offer, signing out devices you do not recognise. Then put a note in the calendar six months out. Vigilance is not a strategy, but a recurring reminder is.
You cannot un-leak an address
This is worth saying plainly, because an industry is built on implying otherwise. Once your address is in a breach corpus, it is out. The data has been copied, mirrored, traded and folded into aggregate dumps that will circulate long after the original company has apologised, rebranded or gone under. Have I Been Pwned reflects this in its own handling: a breach recorded against an address cannot later be changed, and only a tiny number of breaches have ever been retired, in the rare cases where the data genuinely was not circulating elsewhere.
No removal service fixes it either. Firms offering to delete you from the internet can file requests with data brokers, which is a real if partial service, but no request reaches the copies already sitting on somebody's hard drive. Be sceptical of anything advertised as removing your address from a breach.
What you can change is what the address is worth. A leaked address that opens no account, because every password is unique and every login has a second factor, is worth very little. A leaked address that cannot be correlated with your other accounts, because every site got a different one, is worth less still. An address you can switch off the moment it starts attracting rubbish is worth almost nothing.
That is the honest end state. The spam will continue for a while and then settle. The phishing will keep arriving, occasionally very well made, and your defence is the habit from step four rather than any filter. What an evening of work buys you is not invisibility. It is that the next breach, and there will be one, costs you a deleted alias instead of a bank account.