Every year, billions of user records are stolen in massive data breaches involving popular websites, apps, and services. When these companies are hacked, cybercriminals steal databases containing user email addresses, passwords, phone numbers, and sometimes even financial information. This stolen data is then dumped onto hacker forums or sold on the dark web.
Because many people use the same password across multiple websites, a data breach on a relatively unimportant website can give hackers the keys to your primary email account or banking app. It is critical to regularly check if your information has been compromised.
How to Check for Data Breaches Using Have I Been Pwned
The safest and most universally trusted tool for checking data breaches is a free website called Have I Been Pwned (HIBP). Created by Troy Hunt, a renowned cybersecurity expert, this site safely collates public data breaches and allows you to search for your email address.
- Open your web browser and navigate to haveibeenpwned.com.
- In the large search bar in the centre of the page, type your email address (or your mobile phone number including the country code).
- Click the pwned? button.
If the screen turns green and says “Good news — no pwnage found!”, your email address has not appeared in any known data breaches.
If the screen turns red and says “Oh no — pwned!”, your information has been leaked. Scroll down the page to see a detailed list of exactly which websites were breached, when the hack occurred, and what specific data (e.g., passwords, IP addresses, names) was compromised.
What to Do if Your Email Was Breached
If your email address appears in a breach, do not panic, but take immediate action.
1. Change the Password for the Breached Account
If the breach involved a service you still use (for example, LinkedIn or Adobe), log into that specific website immediately and change your password.
2. Stop Password Reuse
The most dangerous outcome of a data breach is password reuse. If you used the same password on the breached website as you do for your Gmail or banking accounts, hackers will try to use the leaked password to break into those more important accounts (a technique known as “credential stuffing”). You must immediately change the password on any other website where you reused the compromised password.
3. Enable Two-Factor Authentication (2FA)
For crucial accounts (email, banking, social media), turn on Two-Factor Authentication. This ensures that even if a hacker buys your stolen password on the dark web, they still cannot log in without having physical access to your mobile phone to receive the secondary code.
How to Check Using Google Password Manager
If you use Google Chrome to save your passwords, Google has a built-in tool that cross-references your saved passwords against known data breaches automatically.
- Open Google Chrome.
- Click the three vertical dots in the top right corner and select Settings.
- Click on Autofill and passwords in the left sidebar, then click Google Password Manager.
- Click on Check up.
Chrome will analyse your saved passwords and provide a list of accounts that have been compromised in data breaches, as well as accounts where you are using weak or reused passwords. It will provide direct links allowing you to quickly navigate to those sites and update your credentials.