Check first, panic never: enter your email address at a breach-notification service — haveibeenpwned.com is the widely cited free option — and it lists every documented breach your address appears in, from mega-hacks like Collection #1 (773 million addresses) to single-site spills. If your address shows up, the response has a strict order: change that password where you used it (and everywhere you reused it), turn on two-factor authentication, watch the card you used there. The catch: past breaches can't be undone — the work is making the leaked data worthless.
How do these checkers know?
Breach databases come from publicly documented incidents — law-enforcement actions, security-researcher disclosures, and dumps posted by attackers themselves. Have I Been Pwned, run by security researcher Troy Hunt, documents its sources per breach on each listing page. It shows only breaches that are public; a site that's been breached quietly won't appear, which is why the checklist below matters even when the result is "no pwnage found."
What does exposure actually cost you?
- Password reuse is the real damage: attackers feed leaked email-password pairs into banks, email providers and retailers automatically — documented as "credential stuffing." One reused password turns a forum breach into a bank problem.
- Personal data doesn't expire: addresses, birthdates and partial card data from old breaches fuel phishing that knows your name, your bank and your last four digits.
- Card data usually gets rotated: networks detect and replace cards proactively; the FTC documents that liability protections on credit cards remain your backstop.
Related stories: How to Tell if a Website Is Secure Before You Enter Your Card Details · How to Recycle Old Phones, Tablets and Cables the Right Way.
The response checklist, in order
- Change the breached password everywhere it was reused — a password manager makes "everywhere" one afternoon instead of one weekend (see password-manager coverage elsewhere on Blog Daily).
- Turn on 2FA for email, banking and shopping first — email above all, because email resets everything else.
- Check card statements for the payment method used with breached services; dispute anything unfamiliar — the FTC documents this reporting path.
- Expect targeted phishing: a breach that includes your order history will produce convincing fake emails quoting it. Verify by going to the site directly, never through the link.
- For SSN exposure: the documented Federal Trade Commission identity-theft page walks through credit freezes at the three bureaus — free, and stronger than monitoring.
Should you pay for breach-monitoring services?
The documented free tools cover most needs: breach lookups, your card issuers' own alerts, and free credit reports from the three bureaus via the government-authorized annualcreditreport.com. Paid identity-protection services add insurance and recovery help — reasonable if your exposure was severe (SSN, medical, financial accounts), documented overkill for a single forum password from 2017 that you've already changed.
The habit that beats every checker
Unique password per account in a manager, 2FA on everything that matters, quarterly breach check — fifteen minutes of maintenance that makes each new headline someone else's problem.

