Identity Protection
How to Find Out If Your Information Was Stolen in a Data Breach
Bottom line: You can check whether your email address has ever shown up in a known data breach for free, in about two minutes, using a site called Have I Been Pwned. If it has — and for most adults over 55, it has — the fix isn't panic, it's five specific steps: change the exposed password, turn on two-factor authentication, watch your accounts for a few months, and consider a monitoring service that checks for you automatically going forward.
Here's the part that surprises most people: a data breach doesn't mean your computer was hacked. It means a company you trusted your information to — a retailer, a hospital, an airline, even a government agency — got hacked, and your name, email, or account details were part of what got stolen. You did nothing wrong. But you still need to respond.
Over 17 billion records have been exposed in data breaches since 2013, according to breach-tracking databases. If you've had an email address for more than a few years, the odds are extremely high that it appears in at least one of them. This guide walks you through exactly how to check, what the results mean, and what to do next — in plain English, no tech background required.
Last updated: 2026-07-07
What Is a Data Breach, Exactly?
A data breach happens when hackers break into a company's computer systems and steal customer information. That information can include:
- Email addresses and passwords
- Full names, home addresses, and phone numbers
- Social Security numbers (in serious breaches)
- Credit card numbers
- Medical records and insurance information
Think of it this way: you didn't leave your front door unlocked. The store where you shopped left their filing cabinet unlocked, and your file happened to be inside it.
This has happened to some of the biggest, most trusted names in business — Target, Yahoo, Equifax, Marriott, T-Mobile, and dozens of hospital systems. If a company that large can be breached, the odds that your information has been swept up in at least one incident over the years are very high, regardless of how careful you've personally been online.
How to Check If Your Email Was in a Data Breach (Free, 2 Minutes)
The most trusted free tool for this is Have I Been Pwned (haveibeenpwned.com), a well-established site used by security professionals, journalists, and even government agencies worldwide. "Pwned" is internet slang for "compromised" — an unusual name, but the tool behind it is legitimate and free.
Here's exactly how to use it:
- Open your web browser and go to haveibeenpwned.com
- Type in your email address in the search box
- Click the button (it may say "pwned?")
- Wait a few seconds for the results
If the screen turns green, your email hasn't appeared in any breach the site tracks — good news, though it's worth checking again every few months.
If the screen turns red, it will list every known breach your email address appeared in, along with what type of information was exposed in each one (just an email address, or something more serious like a password or Social Security number).
A safety note: Have I Been Pwned only asks for your email address — never your password, and never payment information. Be cautious of any breach-checking website that asks you to enter your password to "test" it. That is itself a common scam. Have I Been Pwned has been operated by the same well-regarded security researcher since 2013 and does not require an account or payment to check a single email address.
What to Do If Your Information Was Found in a Breach
Finding your email on that list can feel alarming. Take a breath — in most cases, especially older breaches, no further action is happening on your accounts right now. But you should still work through these steps.
1. Change the Password on That Specific Account
If the breach names a specific company (say, an old retailer or airline), log into that account directly — by typing the website address yourself, not clicking any link — and change your password there.
2. Change That Same Password Everywhere Else You Used It
This is the step people skip, and it's the most important one. If you used the same password on multiple sites — your email, your bank, Amazon — hackers count on that. A breach at one small company can lead to a break-in at your bank if you reused the password. Change it anywhere you used it.
3. Turn On Two-Factor Authentication
Two-factor authentication (sometimes called "2FA" or "multi-factor authentication") means that even if someone has your password, they still need a second code — usually sent to your phone — to get into your account. It takes about two minutes to set up per account and is, by far, the single best protection against a stolen password being used against you. Our two-factor authentication setup guide walks through this step by step for your email, bank, and Amazon accounts.
4. Watch Your Bank and Credit Card Statements Closely for 90 Days
Set a recurring reminder to review your statements weekly, not just when the bill arrives. Small test charges (often under $5) are a common early sign that a stolen card number is being tested by a criminal before a larger purchase.
5. Consider a Service That Checks for You Automatically
Checking Have I Been Pwned manually once is a great start. But new breaches happen every week, and most people don't think to check again. This is where a monitoring service earns its cost.
Why Manual Checking Isn't Enough Long-Term
Here's the honest limitation of the free approach: Have I Been Pwned tells you about breaches after they've been publicly reported and added to its database, which can take weeks or months. It also only covers your email address, not your Social Security number, driver's license, or other government ID numbers that show up on hacking forums and the dark web — the hidden corner of the internet where stolen data is bought and sold.
Aura is a monitoring service built to close that gap. It continuously scans the dark web for your email, Social Security number, and financial account information, and sends you a plain-English alert the moment something is found — often before a stolen identity is used to open a fraudulent account in your name. Aura also monitors your credit files at all three bureaus and includes up to $1 million in identity theft insurance if something does go wrong.
For seniors especially, the value isn't just the scanning — it's that Aura's alerts explain clearly what was found and what to do about it, and a real person is available by phone if you need to talk through next steps.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
Give out your email address less freely. Every store loyalty program, sweepstakes entry, and "10% off your first order" popup that asks for your email is another company that could eventually be breached. Consider keeping a separate, secondary email address just for these sign-ups, so a breach there doesn't touch your main account.
Frequently Asked Questions
Is Have I Been Pwned safe to use?
Yes. It's operated by a respected, independent security researcher and used by security teams, journalists, and the FBI's own training materials as a reference tool. It only requires an email address to search — never a password or payment.
I found my email in a breach from 2019. Do I need to do anything now?
If you've already changed your passwords since then and use unique passwords for each account, you're likely fine. If you've been using the same password since before 2019, change it now, especially if you reuse it elsewhere.
Does a data breach mean someone will steal my identity?
Not necessarily. Most breach exposure is minor — just an email address on a marketing list. But breaches that include your Social Security number, driver's license, or financial account numbers carry real risk and deserve prompt action, including a credit freeze. See our guide on warning signs of identity theft if you want to know what to watch for.
Should I be worried about breaches at hospitals or my doctor's office?
Medical data breaches are increasingly common and serious, because they often include Social Security numbers and insurance ID numbers. If you receive a breach notification letter from a healthcare provider, take it seriously and follow the steps in this guide, particularly setting up a credit freeze.
How often should I check Have I Been Pwned?
Every three to six months is a reasonable habit, or any time you hear in the news that a company you use has been breached.
The Bottom Line
A data breach notification is not a reflection of anything you did wrong — it's simply a fact of using email and shopping online in 2026. What matters is what you do next: check your exposure for free at Have I Been Pwned, change any reused passwords, turn on two-factor authentication, and consider a service like Aura if you want ongoing protection instead of having to remember to check yourself.
Five minutes today can save you months of cleanup later.
Get Our Free Senior Safety Checklist
Every week we send a short, plain-English tip to help seniors stay safe online. No spam, no tech jargon — just practical advice you can use. Drop your email below and we'll send you our 7-Step Credit and Identity Safety Checklist right away.