Disposable email Guides

Your email address was in a data breach: what to do, in order

Updated 23 September 2026

Almost everyone has seen their address turn up in a data breach. It is not a disaster if you react in the right order: here is what to do.

What a breach means

A data breach happens when a site's database is hacked or poorly protected. What leaked depends on the site:

Data exposedMain risk
Email address onlySpam and targeted phishing
Address plus name, phone, postal addressConvincing scams quoting your real details
Address and passwordAccess to your accounts, especially if the password is reused
Payment detailsFraudulent payments

An email address alone is not a secret: it circulates anyway. The real danger comes from the password and the scams that follow.

Step 1: check what leaked

The Have I Been Pwned service (haveibeenpwned.com), run by a security researcher, lists public breaches: enter your address to see which databases include it and what data was involved. Be wary, on the other hand, of emails that "warn" you about a breach and ask you to click: that is a classic phishing scenario.

Step 2: change passwords, in the right order

  1. Your email account first: whoever controls your inbox can reset all your other accounts.
  2. The account on the breached site.
  3. Every account that used the same password: this is where most break-ins happen, with bots trying address-password pairs everywhere.
  4. Bank, shops with a saved card, social networks.

A different password for each site, generated and remembered by a password manager, makes the next breach almost harmless.

Step 3: turn on two-step verification

On your email and important accounts, turn on two-step verification: an authenticator app, a security key or a passkey. Even with your password, an attacker will not be able to sign in. SMS is weaker, but still far better than nothing.

Step 4: expect targeted phishing

After a breach, scammers send messages that mention the hacked site, your name, sometimes a real order. For several months:

Step 5: monitor and reduce future exposure

Get a disposable address

Frequently asked questions

Should I change my email address after a breach?

Rarely. Changing passwords and turning on two-step verification is usually enough. If the address then gets a flood of spam, filters or an alias for new accounts solve it without moving everything.

Can an attacker use my address to send emails?

They can forge the sender of a message without access to your inbox, but providers' SPF, DKIM and DMARC protections block much of this. If they have your password, however, they can really write from your account: change it right away.

How do I know if someone else used my account?

Most email services show the history of sign-ins and devices. Sign out every session you do not recognise, then change the password.

Read next