Where to check if your data was exposed in a breach

The fastest way to learn about your information was compromised is to search Have I Been Pwned, a free website that tracks data breaches. Go to haveibeenpwned.com, enter your email address, and the site will tell you which breaches included that address. It covers thousands of known breaches going back years, so a single search covers most major incidents.

If Have I Been Pwned shows your email in a breach, it tells you which company or service was affected and roughly when. That tells you what passwords to change first — if your email was in a breach at a bank, change that bank's password when ready. If it was in a breach at a shopping site, change that site's password and any other site where you used the same password.

You can also check the Federal Trade Commission's website at reportfraud.ftc.gov, which has a section on data breaches. The FTC publishes notices when major breaches happen and sometimes lists which companies were affected. This is useful if you want to know about breaches that happened recently but may not yet be in Have I Been Pwned's database.

Key Takeaways

  • Have I Been Pwned is a free search tool that shows you which breaches included your email address and what information was exposed.
  • If your email appears in a breach, change the password for that specific site first, then change any other sites where you used the same password.
  • You can also check the FTC's breach notification page to see recent breaches and what types of information were exposed.
  • If a breach included your Social Security number or financial account numbers, place a fraud alert or credit freeze with the credit bureaus.
  • Monitor your credit report for unauthorized accounts opened in your name, which you can check free once a year at annualcreditreport.com.

What to do if your password was in a breach

If Have I Been Pwned shows your email in a breach, the first step is to change the password for that specific site. Do this even if you have not seen any suspicious activity — the breach may have happened months ago and criminals may not have acted on it yet. Use a password that is different from any other password you use, and make it at least 12 characters long with a mix of uppercase, lowercase, numbers, and symbols.

Next, check whether you used the same password on other sites. If you did, change those passwords too, starting with the ones that matter most: your email account, your bank, and any site that holds payment information. If you have many accounts with the same password, this is a sign to switch to a password manager like Bitwarden or 1Password, which generates and stores unique passwords for each site.

What to do if your Social Security number or financial information was exposed

If the breach included your Social Security number, financial account numbers, or credit card numbers, you should place a fraud alert with the credit bureaus. A fraud alert tells lenders to verify your identity before opening new accounts in your name. You only need to contact one bureau — Equifax, Experian, or TransUnion — and they will notify the others. Call or go online to any of their websites and request a fraud alert. It lasts one year and is free.

If you want stronger protection, you can place a credit freeze instead. A credit freeze blocks lenders from accessing your credit report entirely, which makes it much harder for someone to open accounts in your name. You have to request it from all three bureaus separately, and you will need to temporarily lift it if you explore for credit yourself. A credit freeze is free and lasts until you remove it.

You should also monitor your credit report for accounts you did not open. You can check your credit report free once a year at annualcreditreport.com, which is the official site run by the three bureaus. Check all three reports — sometimes fraud shows up at one bureau before the others. If you see accounts you did not open, contact the bureau and the lender to dispute them.

How to monitor for ongoing fraud after a breach

After a breach, watch your bank and credit card statements for charges you did not make. Most banks let you set up alerts for transactions over a certain amount, which can catch fraud quickly. Check your statements at least once a month, and more often if the breach included financial information.

You should also watch for unexpected bills or mail from companies you do not use. If someone opened a credit card or loan in your name, you may receive a statement or collection notice. If this happens, contact the company when ready and tell them you did not open the account. Ask them to close it and send you written confirmation.

If you see signs of identity theft — accounts you did not open, bills for services you did not use, or calls from debt collectors about debts you do not recognize — file a report with the FTC at identitytheft.gov. The FTC will create a record and give you a recovery plan. You can also file a police report, which you may need if you have to dispute fraudulent accounts.

Whether to use credit monitoring services

Many companies offer credit monitoring services that watch your credit report and alert you to changes. Some are free, some charge a monthly fee. Free options include the monitoring built into some credit cards, or services like Credit Karma, which shows your credit score and alerts you to new accounts. Paid services like LifeLock or Experian IdentityWorks offer more features, including monitoring of the dark web for your information.

Credit monitoring is useful if you have been a victim of identity theft or if a breach exposed your Social Security number. For most people, checking your credit report once a year and monitoring your statements is enough. If you choose a paid service, read the fine print — some require you to sign up for a trial and will charge you if you do not cancel before the trial ends.

What information is usually exposed in breaches

Different breaches expose different information. A breach at a shopping site might expose your name, address, email, and payment information. A breach at a healthcare provider might expose your name, Social Security number, and medical history. A breach at a social media site might expose only your email and username. Have I Been Pwned tells you what information was exposed in each breach, so you know what to watch for.

The most dangerous breaches are the ones that expose your Social Security number, because that number can be used to open credit accounts, take out loans, or file tax returns in your name. Breaches that expose financial account numbers or credit card numbers are also serious, but credit card companies often catch fraud quickly and credit card holders are usually not liable for unauthorized charges. Breaches that expose only your email and username are less urgent, but you should still change your password if you used the same password elsewhere.

Frequently Asked Questions

How often should I check Have I Been Pwned?

You can check once and then sign up for breach notifications, which will email you if your address appears in a new breach. Go to haveibeenpwned.com, enter your email, and click the option to be notified of future breaches. You can also check manually every few months if you prefer.

If my information was in a breach but I see no fraud, do I still need to do anything?

Yes. Change your password for that site and any other sites where you used the same password. If the breach included your Social Security number or financial information, place a fraud alert. Fraud can take months to appear, so acting now prevents problems later.

What is the difference between a fraud alert and a credit freeze?

A fraud alert tells lenders to verify your identity before opening accounts, but they can still open them. A credit freeze blocks lenders from seeing your credit report at all, which is stronger protection. A freeze is better if you have been a victim of identity theft or if a breach exposed your Social Security number.

Can I get my money back if someone used my information to make purchases?

If someone used your credit card number, you are usually not liable for unauthorized charges — contact your card issuer to dispute them. If someone opened accounts in your name, you will need to dispute those accounts with the lender and the credit bureaus. The FTC's identitytheft.gov site has a recovery plan that walks you through the steps.

Is it safe to use Have I Been Pwned?

Yes. Have I Been Pwned does not store your password — it only searches its database of breached emails. The site is run by security researcher Troy Hunt and is widely trusted by security professionals. You can also check the site's privacy policy to see exactly what it does with the information you enter.