Skip to content
DEFYNTA

Security guide

Data breach check: has your email or password leaked?

Breached credentials are replayed against banks and inboxes within days of a dump circulating. Check which breaches include you, see exactly what each one exposed, and work through the response plan below in order.

FREE TIER · 10 CHECKS PER DAY · PASSWORDS HASHED IN YOUR BROWSER

Last reviewed

The short answer

To check for a data breach, run every email address you own through a breach lookup, and check your passwords through a k-anonymity checker that never receives the password itself. Breach Box does both: it names the breaches your address appears in and what each exposed, and it hashes passwords in your browser so only a five character hash prefix is ever transmitted.

If you find a hit, the order of operations matters. Email password first, then banking, then app-based two-factor authentication, then a credit freeze if identity data was exposed.

The stakes

What actually leaks, and what it enables

Not all breach data is equal. What was exposed determines how urgent your response needs to be.

Email and password pairs

The most dangerous combination, because it is replayed automatically against banks, email providers, and retailers. One reused password turns a forum breach into an account takeover somewhere that matters.

Phone numbers

Fuel for SIM-swap attempts and targeted phishing. A leaked number paired with a people-search listing gives an attacker your name, address, and carrier-facing details in one sitting.

Home addresses and dates of birth

Rarely changed, so they stay valid for decades. These are the identity-verification answers that call centers still accept, which is why they show up in account recovery fraud.

Security questions and password hints

Older breaches leaked these in plain text. Because people reuse the same answers everywhere, a mother's maiden name exposed in 2013 is still an unlocked door today.

Response plan

What to do, in order

The first three steps are the ones that close active risk. Do them before anything else, ideally in one sitting.

  1. Check every email address you own, not just the main one

    Breach records are keyed to the address that registered the account, so checking only your current address leaves the majority of your history unexamined. Old university addresses and long-abandoned providers are exactly where the reused passwords of your past are sitting.

    Breach Box checks an address against known breach corpora and lists which incident it appeared in and what fields that incident exposed. The free tier covers 10 lookups a day, which is enough to sweep every address most people have ever used.

  2. Check your passwords without sending them anywhere

    Never type a live password into a site that receives it in plain text. A correct password check does the hashing locally and sends only a fragment of the hash, so the service learns nothing usable and still returns an accurate answer.

    That is how Breach Box works: your password is hashed in your browser, only the first five characters of the hash leave the page, and the matching is done against the returned range. If a password shows up at all, treat it as burned everywhere you used it.

  3. Change the reused passwords first, in blast-radius order

    Your email account is the master key, since it can reset almost everything else. Fix it first, then financial accounts, then anything holding a stored card or a shipping address.

    Every replacement must be unique. Reuse is the entire reason breach data has value: attackers do not crack your bank, they log in with a password you already gave to a hobby forum in 2019.

  4. Move two-factor authentication off SMS

    SMS is better than nothing and worse than everything else. If your phone number is in a breach, and it very likely is on a people-search site as well, a SIM swap puts your codes on someone else's device. An authenticator app takes two minutes per account and closes that path.

  5. Freeze your credit if identifiers leaked

    A security freeze is free, applies at each of the three nationwide bureaus separately, and blocks new-account fraud at the source. It does not affect your credit score, and you can lift it temporarily when you actually apply for something. If a breach exposed identity-grade data, this is the single highest-value hour you can spend.

  6. Assume the phishing follows, and check your broker listings

    Breach data makes phishing convincing. A message that names your real bank, your real address, and a real recent purchase clears most people's suspicion. Slow down on anything urgent, and verify through a number or app you already have, never a link in the message.

    Leaked details also feed the aggregation industry. Run a free Web Watcher scan to see whether your address and phone number are now published on people-search sites, and use the removal guides to take them down.

Why it escalates

Breach data and broker listings compound each other

A breach gives them credentials

An email address and a password that works somewhere else. On its own that is a bulk, untargeted problem, handled by rotating the password.

A broker gives them context

Your address history, phone numbers, age, and the names of your relatives. On its own that is exposure, handled by opting out.

Together they give them you

Enough to answer verification questions, pass a call center, and send a phishing message you would believe. Close both sides, not one.

Check what people-search sites publish about you →

FAQ

Frequently asked questions

How do I check if my email was in a data breach?

Enter the address into a breach lookup that indexes known incidents. Defynta Breach Box returns the breaches your address appears in and the data classes each one exposed, so you know whether you are dealing with a leaked password, a leaked phone number, or leaked identity data. Check every address you have ever registered accounts with, not only your current one.

Is it safe to type my password into a breach checker?

Only if the check uses k-anonymity. Breach Box hashes the password in your browser and sends just the first five characters of that hash, so the full password and the full hash never leave your device. Never enter a live password into a site that does not describe how it protects the input.

What should I do first if my data was breached?

Change the password on your email account, then on any account where you reused that password, starting with banking and payment. Turn on app-based two-factor authentication on those accounts. If identity data such as your date of birth or Social Security number was exposed, place a free credit freeze with all three bureaus.

Can leaked data be deleted from the internet?

No. Once a breach corpus is circulating it is copied endlessly across forums and archives, and no service can recall it. That is why the response is rotation and monitoring: make the leaked credentials useless, and watch for the leaked identifiers surfacing in new places.

Does a data breach mean I will be a victim of identity theft?

Not necessarily. Most breach records are used in bulk credential stuffing rather than targeted identity theft. The risk rises sharply when the breach exposed identity-grade data, when you reused the password, or when your address and phone number are also published on people-search sites, which is what makes targeted fraud easy.

How often should I check for new breaches?

New corpora surface constantly and a one-time check ages out within months. Check quarterly at minimum, and immediately after any company you use announces an incident. Continuous monitoring is better, since the useful window for changing a password is measured in days after the data starts circulating.

Get protected

Check your exposure in two minutes.

Breach Box tells you which breaches include your address and what each one exposed. Web Watcher shows you what data brokers publish. Both start free.

FREE TIER · NO CARD REQUIRED · CANCEL ANYTIME

Copyright © 2024-2026

All rights reserved.