Personal Reputation

Have I Been Pwned? How to Check and What to Do After a Data Breach

How to use Have I Been Pwned to see if your email or phone number was in a data breach, what the results mean, and the steps to take next, from passwords to credit freezes.

By Editorial Team 9 min read
A combination lock rests on a computer keyboard

Have I Been Pwned is a free service, created by security researcher Troy Hunt, that tells you whether your email address or phone number appears in known data breaches. Enter your email on the site and it lists each breach it has found your address in, with the date and the types of data exposed. If you appear, change the password for that service and anywhere you reused it, turn on two-factor authentication, and take extra steps such as a credit freeze if sensitive data like your Social Security number was involved.

Being listed is common and doesn’t mean you’ve been hacked. It means some of your data was exposed at some point, and you should make sure that exposure can’t be used against you now.

What Have I Been Pwned is (and isn’t)

“Pwned” is internet slang for being compromised or beaten. Have I Been Pwned, often shortened to HIBP, collects data from publicly leaked breaches and makes it searchable, so ordinary people can find out whether they were affected without trawling through leaked files themselves.

  • It is a breach notification service. It shows which breaches your email address (and, for some breaches, your phone number) appeared in, and what kind of data each breach included.
  • It isn’t a hacking tool or proof that you are safe. It only knows about breaches that have been made public and loaded into its database. A clean result doesn’t mean your data has never been exposed.
  • It doesn’t show the leaked data itself. You’ll see the breach name and data types, not your old password.

Some password managers and browsers have their own breach alerts, and some draw on HIBP’s data. They are worth turning on as well. Our guide to a dark web scan compares these free checks with paid monitoring.

How to check your email or phone number

  1. Go to the official site by typing its name into your browser rather than clicking a link in an email. Look-alike sites exist.
  2. Enter your email address. Check every address you use or used to use: personal, work, old school or university addresses, and any you set up for shopping or newsletters.
  3. Check your phone number in international format if the site offers it. Phone numbers are only included for breaches where they were part of the leaked data.
  4. Read each breach entry. Note the service, the date of the breach and the “compromised data” list, such as email addresses, passwords, phone numbers, physical addresses or dates of birth.
  5. Sign up for notifications. HIBP’s notify option emails you if your address appears in a future breach it loads. You confirm by clicking a link sent to that address.

Some breaches are classed as sensitive, for example from adult sites, and don’t appear in a public search. They are only shown to someone who has verified they own the email address, through the notification service. That protects people from having their membership of a sensitive site revealed by someone else searching their email.

If you run a business, HIBP also offers a domain search. Once you verify you control a domain, you can see which addresses on it appear in breaches, which is useful for spotting staff accounts that need attention.

Checking your passwords

HIBP also runs Pwned Passwords, a database of passwords that have appeared in breaches. You can check whether a password has been seen before. It’s designed so your full password isn’t sent: only a short fragment of a scrambled (hashed) version is sent, and the check is completed on your device. Some password managers run this kind of check automatically.

If a password you use shows up, stop using it everywhere, even if the account it appeared with isn’t yours. Attackers try known leaked passwords against many sites.

What to do after a data breach

What you need to do depends on what data was exposed. Work from the breach entry’s list.

Data exposed What to do
Email address only Expect more spam and phishing. Be wary of messages that reference the breached service.
Password (even hashed) Change it on that service and on every other account where you used the same or a similar password.
Phone number Watch for scam texts and calls. Ask your mobile carrier about adding a PIN or port-out protection to your account to reduce the risk of a SIM swap.
Home address, date of birth Watch for targeted phishing and mail fraud. These details are often used to answer security questions, so update those.
Security questions and answers Change the answers wherever you used them. Consider giving answers that aren’t true facts but that you store in a password manager.
Payment card details Contact your card issuer, ask about a replacement card, and check statements for charges you don’t recognize.
Social Security number or government ID Freeze your credit with all three bureaus, check your credit reports, and consider an IRS Identity Protection PIN. See below.

1. Fix your passwords

The biggest risk from most breaches is password reuse. Attackers take leaked email and password pairs and try them on banks, email providers, social networks and shopping sites. Change the breached password first, then any account using the same one, starting with email (because it can reset everything else), banking and social media.

Use a unique password for every account. A password manager makes this practical: it generates and remembers long, random passwords so you don’t have to.

2. Turn on two-factor authentication

Two-factor authentication (2FA) means a stolen password alone isn’t enough to get in. An authenticator app, a passkey or a security key is stronger than a code sent by text message, but any 2FA is far better than none. Prioritize your main email account, then financial accounts and social media.

3. Freeze your credit if your SSN was exposed

If a breach included your Social Security number, place a security freeze with each of the three nationwide credit bureaus: Equifax, Experian and TransUnion. A freeze stops most new lenders from seeing your credit report, which makes it much harder for someone to open accounts in your name. Freezes are free under federal law, don’t affect your credit score, and can be lifted temporarily when you need to apply for credit.

Also check your credit reports for accounts you don’t recognize. You can get free reports from the official site, AnnualCreditReport.com. Our guide on what to do if your Social Security number is stolen goes through the full list.

4. Report misuse at IdentityTheft.gov

If you see signs your data is actually being used, such as accounts you didn’t open, tax returns filed in your name or debt collectors calling about debts that aren’t yours, report it at IdentityTheft.gov, the Federal Trade Commission’s site. It creates a personal recovery plan and an identity theft report you can use with creditors. Our guide to what to do if your identity is stolen covers the recovery steps.

5. Watch for follow-up scams

Breaches are followed by scams that use the leaked data to seem credible. Two to know about:

  • Fake breach notices asking you to “verify your account.” Go to the service directly instead of clicking links.
  • Extortion emails quoting an old password and claiming the sender has hacked your device or recorded you. These are almost always bluffs built from breach data. Our guide to the “you’ve been hacked” email scam explains how to handle them.

Not sure where to start?

Get a free audit of your search results and review profiles, with a prioritized fix list.

Get a free audit

A worked example

This is illustrative, not a real client. Keiko, a freelance designer, checks HIBP after a friend mentions it. Her personal email appears in four breaches: two old forums, a fitness app and an online retailer. The forum breaches included passwords, and she realizes one of them is the same password she still uses for her client-facing email.

She changes that email password first, turns on an authenticator app, and signs out of other sessions. She then installs a password manager and replaces reused passwords on her bank, portfolio site and social accounts over the next week. The retailer breach included her address and phone number but no SSN, so she doesn’t need a credit freeze, but she adds a PIN to her mobile carrier account and updates two security questions that used her old street name. Finally, she signs up for HIBP notifications on both her personal and business addresses.

A few weeks later she gets an email quoting one of her old forum passwords and demanding payment. Because she knows where the password came from, she recognizes the scam and deletes it.

When a breach becomes a reputation problem

Most breaches stay private problems. They become reputation problems when someone takes over your email or social accounts and posts or messages as you, or when leaked personal details are used to harass or impersonate you. If that happens, secure the accounts first (our hacked Gmail guide is a good starting point), then tell your contacts what happened. For ongoing impersonation, exposed personal details or search results you need cleaned up, our personal reputation management service can help. And for prevention going forward, see our list of ways to prevent identity theft.

If you run a business that has been breached, the priorities are different: see our guide to data breach communication.

Common mistakes

  • Changing only the breached password. If you reused it, every account with that password is exposed.
  • Checking one email address. Old addresses are often the ones in the most breaches.
  • Assuming “not pwned” means safe. HIBP only knows about breaches that have been made public and loaded into it.
  • Paying a “breach removal” service. Leaked data can’t be pulled back from criminal forums. Spend the effort on passwords, 2FA and freezes.
  • Relying on text message codes alone for your most important accounts when an authenticator app or passkey is available.

Frequently asked questions

Is Have I Been Pwned safe to use?

Yes, it’s a long-running, widely used service created by security researcher Troy Hunt. Searching only needs your email address or phone number, never a password. Make sure you’re on the real site by typing the address yourself.

Can Have I Been Pwned remove my data from a breach?

No. It reports breaches; it doesn’t hold or control the leaked data. Once data has been leaked it can’t reliably be pulled back, which is why changing passwords and adding 2FA matter.

I've been pwned. Does that mean I've been hacked?

Not necessarily. It means your data was included in a breach of a service you used. Your accounts are at risk mainly if you reused the exposed password or if sensitive data like your SSN was included.

Do I need a credit freeze after every breach?

No. A freeze matters most when your Social Security number or similar identity data was exposed. Many people choose to keep credit frozen anyway, since it is free and can be lifted when needed.

How do I find out about future breaches?

Sign up for HIBP’s free notification service with each email address you use, and turn on breach alerts in your password manager or browser if they offer them.

Editorial Team

The 123 Reputation Management editorial team writes practical guides on reviews, search results and online reputation.

Start with step 1

See what people see when they search for you.

Get a free, no-obligation reputation audit covering search results, review profiles and social mentions, with clear next steps.