📖 The Basics
What It Is
A data breach is any incident where your data gets exposed, stolen, or leaked, whether through a hack, a misconfigured database, or an insider. When that happens, the identifiers you handed over at signup like your email address, your phone number, and sometimes more like your password, name, or home address, end up in datasets that circulate, get traded, and sold.
Checking whether you've been breached means running your email address or phone number against databases of known, publicly disclosed breaches to see which ones included your information. It's free, normally takes a couple of minutes, and it's one of the most useful things you can do to understand your actual exposure.
One thing I do want to be clear about though: checking a breach is a response, not a prevention. It tells you something about the past. So while it's important to clean it up, the root issue of preventing it from recurring will be discussed later in this article as well.
How It Works
Why Your Phone Number Matters as Much as Your Email
For years, breach-checking was framed as an email-and-password problem. But your phone number is in many ways a worse thing to have leaked, because changing your phone number is a genuine hassle that ripples across every account, contact, and service tied to it. Would you rather change a password or change your phone number?
A leaked phone number is the raw material for SMS phishing ("smishing"), spam call floods, and even SIM-swapping attacks where an attacker convinces your carrier to port your number to their device and intercepts the SMS verification codes protecting other accounts. If your number is circulating in breach databases, that's the exposure that quietly enables a lot of downstream damage.
The Tools That Actually Work (2026)
There's no single tool that sees every breach, so the right approach is to run two or three reputable ones and combine the picture. These are the current, free options worth using:
- Have I Been Pwned is still the gold standard, run by security researcher Troy Hunt. It checks your email against a database of publicly disclosed, independently verified breaches.
- Proton takes a different, account-wide approach worth knowing if you're in its ecosystem. Rather than an open box you type an address into, Proton's Dark Web Monitoring watches the email addresses and aliases tied to your Proton account and alerts you when they surface in a breach. It covers your Proton addresses, your aliases, custom domains, and recovery emails (drawing on HIBP and other threat-intelligence data). It's a paid-plan feature and it's email/credential-focused rather than a phone-number checker, so think of it as "set it and forget it" monitoring for your own Proton identity rather than a universal lookup like Have I Been Pwned.
- DataBreach.com is the a useful option if you want to search by something other than an email address. It accepts an email, name, or phone number. Just go in with your eyes open about the free lookup existing partly to funnel people toward a paid removal product, which is normal but worth naming. I'd treat it as your second lookup after Have I Been Pwned, particularly if a phone number is the identifier you're worried about.
You Might Already Have This Built In
Here's something a lot of people don't realize: if you use a password manager, you may already have automated breach checking running quietly in the background.
- Apple Passwords (built into iPhone, iPad, and Mac) has a Password Monitoring feature that continuously checks your saved passwords against lists of leaked credentials and flags anything that "has appeared in a data leak." It's free and on by default for Apple users.
- Bitwarden offers a Data Breach Report (which uses Have I Been Pwned to check your email against known breaches) on all plans including free, plus an Exposed Passwords report on its premium tier that flags saved passwords found in leaks.
- Proton Pass includes Pass Monitor: free password-health checks for weak and reused passwords, and dark-web monitoring that alerts you when your credentials surface in a breach on its paid tier.
- Even some KeePass clients, like the open-source KeePassXC or Strongbox, have a built-in Have I Been Pwned report that checks your stored passwords against the leaked-password database, completely free.
I'm not steering you toward any one of these here, our options for you to select from live on the SPA Tools page. The real point to drive home is this kind of monitoring is increasingly a feature you already own and need to start utilizing rather than a service you have to hunt down, and if you're using a good password manager, you're probably already covered.
A Note on Prevention
Everything above is about responding to exposure that's already happened. But the real goal is shrinking how much of you is out there to leak in the first place, and a handful of habits cover the overwhelming majority of that.
- The single most powerful one is aliasing: instead of handing every service your real email and phone number, you give each one a unique, burnable alias that forwards to you, so when a company inevitably gets breached, the leaked identifier is a throwaway you can kill in one click rather than your real address tied to a hundred other accounts. Our full aliasing guide walks through how to actually set it up.
- Use a password manager with a unique password for every account (this alone neutralizes credential stuffing, the most damaging breach outcome), turn on two-factor authentication using an authenticator app rather than SMS wherever you can.
- If you're in the US, freeze your credit with the three major bureaus, it's free, reversible, and one of the most effective ways to stop leaked data from turning into actual identity theft. Some other countries offer a similar service, so check your region's credit freezing options!
- Finally, reduce your total footprint: every account you don't create is one that can never be breached, which is the whole logic behind digital minimalism, closing zombie accounts you forgot you had and being intentional about new signups steadily shrinks the target on your back. None of this undoes a past breach, but together it means the next one barely touches you.
🎯 Why It Matters
In 2012, LinkedIn was breached. The company disclosed that 6.5 million password hashes had been stolen, forced resets on the affected accounts, and moved on. Case closed. Except it wasn't. In 2016, four years later, a dataset appeared for sale on a dark web marketplace containing 117 million LinkedIn email-and-password pairs, not the 6.5 million originally disclosed. The real scope of the breach had been sitting in criminal databases for four years while everyone believed the incident was resolved.
Those 117 million credential pairs were immediately valuable for credential stuffing: automated attacks that try the same username-and-password combination across hundreds of other services. Anyone who had reused their LinkedIn password at their bank, their email, their health portal was suddenly at risk, years after an incident they'd completely forgotten.
Running a breach check is how you make the invisible visible, and how you find out which specific exposures need action before someone else finds them for you.
💡 Common Misconceptions
"If I haven't been notified, I'm probably fine."
Breach notification is wildly inconsistent, and as the LinkedIn story shows, the disclosed scope of a breach is often a fraction of the real one. Companies underreport, disclose late, or never find out the full extent themselves. Waiting to be told is not a strategy. Checking proactively is the only way to know, and prevention is the real solution which assumes the data will be breached, which I'll discuss shortly.
"Checking my data on these sites is itself a privacy risk."
This is a fair instinct, and the answer is: it depends entirely on which site. A legitimate breach checker only ever asks for an email address or phone number and uses it solely to compare against breach data...how else can it possibly know what data to search for? The red flags to walk away from are any site that asks for a password, an OTP code, ID photos, or payment to "clean up" your data, or a sketchy "phone leak checker" with no clear privacy policy, since a sloppy service can inadvertently cause more damage.
"I should pay for a premium dark-web scanning service."
You'll see a lot of paid services, often bundled with a VPN or antivirus, advertising "dark web monitoring" and "we'll scan the dark web for your data" for a monthly fee. But typically these core functions can be done for free with the tools above, or that your password manager may already do for you. There's also an inherent limit worth understanding: no service can actually remove your data from the dark web once it's out there, so any monitoring product is fundamentally telling you what happened, not undoing it. If a paid service genuinely bundles something you value and the monitoring is a bonus, fine, but paying a premium specifically for breach scanning is rarely money well spent—and probably better spent on prevention.
"I should buy identity theft insurance to cover this."
Identity theft insurance and "identity protection" plans are heavily marketed. These products typically don't prevent anything, they reimburse certain costs after something goes wrong, and the fine print often caps what's covered and excludes the losses people actually fear most. Much of what they offer, freezing your credit, monitoring, disputing fraudulent charges, you can do yourself for free (a credit freeze, for example, is free and is one of the single most effective protective steps available in the US!) I'm not telling you never to buy it, some people with higher risks and public presences may find value in these services, but I'd go in understanding you're mostly paying for convenience and reimbursement, not protection. Do the free foundational stuff first, and evaluate insurance as a distant, optional add-on rather than a substitute for it. And it's worth knowing that these companies are targets themselves...in March 2026, Aura, one of the more heavily marketed identity protection services, disclosed a breach of around 900,000 records after an employee account was compromised through a voice phishing call.
"A breach check will find everything about my exposure."
No single tool sees every breach, and none of them see private data that hasn't surfaced publicly. Many data breaches can happen for months or years before we even find about about them! So a clean result means "not found in the breaches this tool knows about," not "never exposed anywhere." But this is still valuable, since the highest risk breaches are the ones available to the public.
"There's nothing I can do once my info is out there."
You can't un-leak data, that's true. But you can neutralize most of the consequences: change and de-duplicate exposed passwords, move critical accounts off SMS-based 2FA (which a leaked number directly threatens), and stay alert to smishing. The breach already happened; your job is to close the doors it opened, and then reduce how much you're exposing next time.
🗣️ Henry's Take
In 2026, it's rare to find someone who hasn't been caught in at least one data breach. So rather than resorting to panic, I like to reframe this as just an inevitable part of navigating digital safety online. What I can say is that when you set up the proper systems of prevention like unique identifiers for each account, freezing your credit, a password manager + 2FA—you no longer really care too much about breaches. If you get caught in one, you'll be notified, and the breach will be compartmentalized to whatever alias information you gave that service and you won't be worried about other accounts being caught in the mix.
I also like the inherent risk of data breaches to be a part of what people consider when they think about the types of services they use. Services that are inherently more prone to collecting all your data are larger targets, that can expose a lot more about you. But when you compare this to zero-knowledge providers that actively do everything possible to know as little about you, it inherently makes their data breach risk and the scope of a breach much smaller. This to me is one of the most powerful reasons to use an encrypted provider like Proton instead of Google. If Google suffers a data breach, your emails have the possibility of being a part of it. If Proton suffers a breach, they are incapable of reading your emails, so those emails are inherently safe from the scope of the breach. Same goes for Notion vs Cryptee, or SMS vs Signal. So use this as another lesson to choose services that know as little about you as possible, since they are inherently resistant to the worst data breaches.
✅ Henry's Picks
- Have I Been Pwned: the essential first stop. Free, no account needed, run by a trusted security researcher.
- A password manager: the actual fix for the most dangerous breach outcome, and many now include breach monitoring built in, so the ongoing watching happens automatically.
- An authenticator app: move critical accounts off SMS 2FA, especially if your phone number has been exposed.
- Aliasing services: the real prevention. Give every service a unique, burnable identifier so a breach never touches your actual email or phone.
For the prevention side of this, read our guide on digital minimalism, and see the broader recommendation set at Techlore's SPA Tools.
Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.