emcognito
Back to Blog

What to Do If Your Email Is in a Data Breach: Complete Guide

If your email shows up in a data breach, change that account's password and anywhere you reused it, turn on two-factor authentication, and expect phishing that references the breach. Your inbox itself is usually not hacked. Going forward, give every site its own email alias so the next leak is traceable and contained.

April 8, 2026

Updated

Data SecurityEmail PrivacyCybersecurity TipsDark Web

Keep your real inbox private.

Create unlimited aliases. The first 100 forwarded emails each month are free.

Create a free alias →

If Have I Been Pwned flags your email, change the breached account's password first, then anywhere you reused it. Turn on two-factor authentication, expect phishing that references the breach, and move future signups to unique email aliases so the next leak stays contained.

Updated 2026-07-02.

A breach notification is unsettling, but it is rarely an emergency inside your inbox. In most breaches, what leaked is your email address plus whatever that one company stored — sometimes a hashed password, sometimes just your name and address. Your email account itself usually was not touched. What you need is a calm, ordered checklist, so here it is.

First, read what actually leaked

Have I Been Pwned (and Mozilla's Firefox Monitor, which uses the same data) lists the data classes exposed in each breach: email addresses, passwords, phone numbers, physical addresses, purchase history, and so on. That list decides which steps below matter for you. A forum leak of emails and salted passwords is a different problem from a retailer leaking card numbers.

One important reassurance up front: appearing in a breach means a company you gave your data to was compromised — it does not mean someone is inside your email account. Signs of an actual account takeover are different: logins you don't recognize, messages in your Sent folder you didn't write, or recovery settings that changed. If you see those, treat the account as compromised and work through steps 2–4 immediately.

The aftermath checklist

  1. Change the password on the breached account. Even if the site says passwords were hashed, assume the worst. Use a long, unique passphrase — four or five random words beats a short "complex" password.
  2. Change it everywhere you reused it. This is the step that actually prevents damage. Attackers feed leaked email-and-password pairs into automated tools that try them on banks, PayPal, streaming services, and shops — a technique called credential stuffing. If the leaked password unlocks anything else you own, that account is exposed today. A password manager like Bitwarden or 1Password makes unique passwords sustainable.
  3. Turn on two-factor authentication. Start with your email account itself — it is the master key that receives every password-reset link — then your bank and main social accounts. An authenticator app or hardware key is stronger than SMS codes, which are vulnerable to SIM swapping.
  4. Sign out of all sessions and audit your settings. In your email provider's security page, use "sign out of all other sessions," then check recovery email, recovery phone, and forwarding rules for anything you didn't add. Attackers who do get into an inbox often plant a quiet forwarding rule to keep reading mail after you change the password.
  5. Expect phishing that references the breach. Criminals know you were in this breach, and they will use it: fake "secure your account" emails naming the breached company, and extortion emails that quote your old leaked password as "proof" they hacked your webcam. The quoted-password scare email is a bluff built from the same leak. Delete it. Never click security links in email — go to the site directly.
  6. Act on the sensitive data classes. If payment card numbers leaked, ask your bank for a replacement card and watch statements. If government ID or Social Security numbers leaked, freeze your credit with the bureaus and take any free monitoring the breached company offers. If your phone number leaked, be alert for smishing and SIM-swap attempts.
  7. Shrink the next breach before it happens. You cannot stop companies from being hacked, but you can stop one breach from exposing the address every other account uses. Give each site its own forwarding alias instead of your real email. Alias services — Emcognito, SimpleLogin, addy.io, Firefox Relay — all work on the same principle: mail to the alias forwards to your real inbox, and the site never learns your real address. Emcognito is built for exactly this aftermath: unlimited aliases free (metered at 100 forwarded emails a month), so the next time a service is breached, the attacker gets one alias you can suspend in a click — and the alias that starts receiving junk tells you precisely who leaked you.

What leaked → what to do

Data class in the breachYour move
Email address onlyExpect more spam and phishing; move future signups to aliases
Passwords (even hashed)Change it there and everywhere it was reused; enable 2FA
Payment cardsReplace the card; watch statements for small test charges
Government ID / SSNFreeze your credit; use offered identity monitoring
Phone numberWatch for smishing and SIM-swap attempts; prefer app-based 2FA

About the dark web

Breached databases end up bundled into "combo lists" and traded on dark-web forums. There is no way to remove your data once it circulates — no unsubscribe button exists. The realistic goal is to make the data worthless: rotate the passwords, add 2FA, and stop feeding your real address to new sites. Old leaked credentials that no longer open anything are just text.

Frequently asked questions

Does being in a breach mean my account was hacked?

No. It means a company holding your data was compromised. Your email account is only at risk if the leaked password (or one like it) also protects that account — which is exactly why steps 1–3 above come first.

Should I delete my email address after a breach?

Almost never. Password resets for everything you own flow through that address; abandoning it can lock you out of accounts permanently. Secure it — new password, 2FA, session sign-out — and keep it. Then stop handing it out: use one alias per site so the address that gets leaked next time isn't your real one.

Why am I getting more spam after a breach?

Your address was sold or shared along with the rest of the breached data, and spam operations buy those lists. Filters help, but the address is now permanently on marketing and fraud lists. If the flood started suddenly, our sudden-spam diagnostic walks through finding the likely source in five questions.

Can I find out which company leaked my address?

After the fact, Have I Been Pwned's breach list is your best evidence. Going forward you can know for certain: give every company a different alias, and the alias that starts receiving junk names the leaker. Here's the full method for finding out who sold your email address.

Turn the wake-up call into a setup

A breach you can't prevent is a good reason to change what you can control: how many sites know your real address. Compartmentalize — one private address for banking and identity, and a unique alias for everything else. If you want the alias route, an Emcognito account is free: unlimited aliases, 100 forwarded emails a month, replies from any alias, and one-click suspend for any address that starts misbehaving. Related reading: disposable email vs email alias and removing your email from data brokers.

Sources and further reading

Ready to protect your email?

100 forwarded emails a month at no cost, no credit card, passwordless sign-in.

Create anonymous email now →