Your data has already leaked. Here is what you can still do.
Check your address on Have I Been Pwned. And before changing any password, read the section on order: almost everyone starts with the one that matters least.
If you have used the internet for more than five years, your email is in some breach. That is not alarmism, it is arithmetic. The useful question is not whether it happened, but what exactly leaked and how much of it still works today.
The uncomfortable part, first
A breach cannot be undone. Once a company's data is circulating, it exists in dozens of copies at once. There is no delete button, no company to call to have it withdrawn, and no paid service that removes it, however loudly one advertises otherwise.
That sounds like bad news and partly is. But it has a very useful consequence: stop spending effort trying to erase what leaked and spend it making it useless. That is the whole point of this guide.
Where to check
- Have I Been Pwned. The reference. Enter your email and it tells you which breaches you appear in, when, and what kind of data was exposed in each. Free, no sign-up.
- Your browser's or password manager's checker. Chrome, Firefox, Safari and the password managers flag a saved password that appears in a known breach. This is the most useful form, because it names which password rather than just telling you something happened.
- The security section of your Google or Apple account. Both review saved passwords and flag compromised and reused ones.
A warning about sites that ask for more than they should. Some services want you to register, hand over a phone number or buy a monitoring subscription in order to "check your data". Before giving anything, ask whether you are handing over fresh data in exchange for learning that old data leaked.
What appearing on the list means, and what it does not
This is where people get confused, and the confusion leads them to do the wrong thing.
- It means a company you had an account with lost data, and yours was in it.
- It does not mean anyone got into that account, or is using it now.
- It does not mean your computer or phone has a virus. The breach was theirs, not yours.
- It does mean that if you reused that password elsewhere, those other sites are the real problem.
Look at what kind of data each breach exposed, because they do not weigh the same. Your email and a sign-up date leaking is annoying. Passwords, security answers or your phone number leaking is a different category.
The right order, which almost nobody follows
The instinct is to go to the breached site and change the password there. That is the least urgent step of all. This is the order that actually reduces risk:
- 1. Your main email, before anything else. It is the account that can reset every other one. If it falls, the strength of the rest stops mattering. How to secure it is in someone is in your email.
- 2. Every site where you reused that password. This is the step that counts. Attackers take the email and password pair from one breach and try it on fifty other services. It is called credential stuffing and it works precisely because people reuse.
- 3. Your bank and anything holding money. Even if they appear in no breach, if they shared a password with something that did, they no longer count as safe.
- 4. Turn on two-factor where you can, starting with email. It is worth more than any long password: even holding yours, they cannot get in without the second step. Explained in multi-factor authentication.
- 5. And last, yes, the account on the breached site.
Why changing the password is rarely enough
Because the problem was never that password: it was that it existed in more places.
If you change it on the breached site and leave the same one on your email, your shop account and your social network, you have fixed nothing. You closed the door they were no longer coming through and left the rest open.
The only realistic way to stop this recurring is for every site to have a different password, and that does not survive on memory: it survives on a manager. Which one to pick is in the password manager comparison.
The data you cannot change
Here is the part no tool solves. A password changes in thirty seconds. These do not:
- Your phone number. Changing it is a serious nuisance, and it happens to be the recovery key to half your digital life.
- Your national ID, date of birth, address. They do not change, full stop.
- Security answers like "mother's maiden name", which are public to anyone who looks for two minutes.
What you can do is strip them of power:
- Stop using SMS as a second factor wherever an alternative exists, and use a code app. The reason is in SIM swap attacks: with your number leaked, cloning your line is a well-trodden path.
- Replace security answers with invented text. It does not have to be true. "Mother's maiden name" can be a random word stored in your manager.
- Assume your name and number are circulating, and treat any call or text "from your bank" that uses them as what it is: somebody reading from a list.
Watching from here on
- Subscribe to Have I Been Pwned's notifications. It emails you if your address turns up in a new breach. Free, and the highest-value two minutes available.
- Act on your manager's reused-password warnings. That list everybody ignores is exactly the map of what breaks in the next breach.
- Review active sessions on your email and social accounts periodically. A device you do not recognise is a far more reliable signal than any hunch.
What you can demand from the company
This gets overlooked: the company that lost your data has obligations too, not just you.
- It has to tell you when the breach poses a high risk to you, and notify the data protection authority.
- You can complain to your regulator if you believe it failed to do so, or failed to protect your data properly. In Spain that is the AEPD.
- You can ask it to delete your data if you are no longer a customer. That does not recover what leaked, but it reduces what leaks next time.
What to take away
That "has my data leaked?" nearly always has the same answer, which is why it is the wrong question. The good one is: how much of what leaked still gets someone into something of mine?
If the answer is "nothing, because every account has its own password and email has two-factor", a breach is an annoyance. If the answer is "the password I use everywhere", it is a serious problem, and no checking website fixes it: you do, in an afternoon.
