The Email I Almost Ignored
I want to tell you about an email I received last year.
It was from a service I'd used maybe twice, years ago. The subject line was something like "Important Security Update." I almost deleted it. I get so many of these notifications that I'd started ignoring them.
But something made me open it.
The message said: "We recently discovered that your account information may have been exposed in a data breach affecting one of our vendors. We recommend that you change your password immediately."
I went to Have I Been Pwned—a free service that tracks data breaches—and typed in my email address.
Five breaches. Five different services I'd used over the years. And in one of them, my password had been exposed in plain text.
I changed the password on every account that used it that night. It took about 20 minutes. But here's the thing: I'd been using that password for years. I'd reused it across multiple sites. The exposure had happened three years earlier, and I never knew.
That's the thing about data breaches—they're happening all the time. And most of the time, you don't find out until it's too late.
The Reality: You've Probably Been in a Breach
Let me be direct about this.
If you've had an email address for more than a few years, it's almost certainly appeared in at least one data breach.
According to the 2024 Digital Privacy Survey Report, over 60% of U.S. adults have had their data breached. And that number is likely low—many breaches aren't disclosed, and many people don't know they've been affected.
The breaches we know about are massive. According to Have I Been Pwned (HIBP), they've indexed over 700 confirmed data breaches, representing more than 12 billion records. That's just the known breaches.
The question isn't whether your email has been in a breach. The question is: what was exposed, and what did you do about it?
What Happens When Your Email Is Exposed
When your email address is exposed in a breach, it can lead to a chain of problems.
Increased Spam and Phishing
Your email address becomes a target. Attackers know it's real and active. You'll likely see more spam and phishing emails—often disguised as legitimate messages from the company that was breached.
Credential Stuffing
If your password was exposed alongside your email, attackers will automate attempts to use that same combination on other services. This is called credential stuffing. It works because most people reuse passwords. An old breach from a forum you forgot about can put your current bank account at risk.
Account Takeover
If attackers gain access to your email inbox, they can reset passwords for your bank, social media, and other accounts. Your email is the master key to your digital life. Once they control it, every "forgot password" link becomes a backdoor.
Identity Theft
If the breach exposed personal details like your name, address, or date of birth, attackers can use that information to open credit accounts or commit fraud in your name.
How to Check: The Five-Minute Process

Here's the good news: checking takes less than five minutes. And the tools are free.
Step 1: Go to Have I Been Pwned
The most trusted free breach checker.
Have I Been Pwned (HIBP) is maintained by security researcher Troy Hunt. It's widely considered the most comprehensive public database of known data breaches. It's free, doesn't require an account, and has indexed over 12 billion leaked records from more than 700 confirmed breaches.
Go to haveibeenpwned.com. Type your email address into the search box and click "pwned?".
Step 2: Read the Results
If your email appears in zero breaches, you'll see a green result: "Good news — no pwnage found".
If your email appears in breaches, you'll see a red result listing each breach, the date it occurred, and what data was exposed.
Pay attention to what was exposed. This determines your response:
What Was Exposed | Risk Level | Response |
|---|---|---|
Email only | Low | Expect more spam; no emergency |
Email + password | High | Change that password immediately on every site where you used it |
Email + password + personal details | Highest | Full identity theft potential—take immediate action across all accounts |
Financial data | Highest | Contact your bank, request new card numbers, consider a credit freeze |
Step 3: Check Every Email You Use
Attackers don't treat your emails separately. They link everything. Your old Hotmail address from 2005 could still be the recovery address on your current bank account.
Check:
Your primary personal email
Your work email (current and past)
Old email addresses you no longer use
Emails used for social media or online shopping
Any email tied to financial accounts
What to Do If Your Email Was Exposed
If the breach checker shows your email in one or more breaches, don't panic. But do act. Here's a prioritized action plan.
Immediate Actions (Within 1 Hour)

1. Change the password on the breached service(s)
Start with the specific sites listed in the breach results. If a service was breached and your password was exposed, that password is now public.
2. Change your email password
If your email account itself was in a breach, this is priority #1. Your email is the master key to all your other accounts via password reset links.
3. Enable two-factor authentication (2FA)
Turn on 2FA for your email account and any breached services. Use an authenticator app (not SMS) when possible. According to Microsoft, enabling multifactor authentication blocks more than 99.9% of automated account-compromise attacks.
Within 24 Hours
4. Check for password reuse
If you used the same password on other sites, change it everywhere. This is the most important step. A leak from a forum you forgot becomes a bank account risk if you reused the password.
5. Review account activity
Log into breached services and check for unauthorized activity: unfamiliar logins, changed settings, unknown linked accounts.
6. Check your email's sent folder
If your email was compromised, attackers may have sent messages or password reset requests from your account.
7. Monitor financial accounts
Keep an eye on your bank statements and credit reports for unusual activity or unauthorized transactions.
Within the Week
8. Use a password manager
If you're not using one, start. A password manager generates strong, unique passwords for every account and stores them securely. Most include built-in breach monitoring to alert you when a password appears in a new breach.
9. Update security questions
Avoid answers that are easy to guess or based on public information (like your pet's name, if you've mentioned it on social media).
10. Consider a credit freeze
If financial data or Social Security details were exposed, consider placing a fraud alert and credit freeze with all three credit bureaus. This prevents someone from opening new accounts in your name.
Ongoing Monitoring: Don't Just Check Once
Data breaches aren't slowing down. The question isn't whether your email has been in a breach, but how many breaches it's appeared in.
Security experts recommend checking at least every 3 months, or immediately after a major breach makes the news. Set up breach notifications so you're alerted automatically:
Have I Been Pwned offers free email alerts when your address appears in new breaches
Your password manager likely includes built-in breach monitoring
Google Password Checkup flags compromised, reused, or weak passwords
Apple's Security Recommendations does the same for iCloud Keychain users
The Bottom Line
Checking whether your email was in a breach takes five minutes. Not checking could take weeks of dealing with the aftermath.
Data breaches are becoming routine, but they're only dangerous if you don't act. The exposure itself isn't the problem—it's the reused password, the missed notification, the unmonitored account.
Protect the front door before you build a taller fence.
The front door here is your email address and the passwords attached to it. If you're waiting for a notification from a company to tell you about a breach, you're already late. Companies can take months to discover and disclose a breach. By then, your credentials may already be circulating on the dark web. And once your data is out there, you can't remove it. But you can make it useless.
Change the locks before someone tries the old key.
Dave C. — Five minutes now beats five hours later.
No notes on this sheet yet.