Data breaches have become disturbingly common. A service you signed up for years ago gets hacked, and suddenly your email address — sometimes along with your password — is circulating in leaked databases. Here's exactly what to do if it happens to you, and how to reduce the damage.
Before panicking, verify whether your email was actually part of a known breach. Several reputable, free tools let you check if your address appears in leaked databases by searching breach-monitoring services. Many email providers also send automatic breach alerts if your address is detected in a known leak.
If the breach included passwords, change it right away — not just for the breached service, but for any other account where you reused the same password. This is the single most important step, since attackers commonly test leaked credentials across multiple platforms.
If you haven't already, turn on 2FA for the affected account and any other important accounts. Even if your password is compromised, 2FA adds a second barrier that blocks most unauthorized access attempts.
Leaked email addresses are often used in follow-up phishing campaigns, since attackers know the address is active and may pair it with other leaked details (like your name) to appear more convincing. Be extra cautious with unexpected emails for the following weeks.
Review recent login history, connected devices, and any account settings changes you didn't make. Many services provide a security or activity log for exactly this purpose.
If the breach involved a service connected to payment information, monitor your bank and credit card statements closely for unfamiliar charges over the following weeks.
While you can't control whether a company you trusted gets breached, you can control how much damage it causes:
A data breach involving your email is unsettling, but it's rarely catastrophic if you respond quickly: change passwords, enable 2FA, and stay alert for phishing. Just as importantly, adopting habits like using temporary emails for non-essential signups means that the next breach — and there will likely be one — has far less of your real identity to expose in the first place.