What to do when a data-breach alert mentions your email
Verify a breach alert, understand which data was involved and secure the right accounts without trusting alarming links or fake recovery offers.
A breach alert is a reason to check, not a reason to click the first urgent button in the message. Start by opening the affected service through its official website or app. Confirm the notice independently and work out what information was actually involved.
An exposed email address, a reused password and a stolen active session call for different responses. A useful reaction focuses on the affected accounts and data instead of changing random settings everywhere.
Keep a calm record of the notice and the actions you take. You do not need to download stolen data or search criminal forums to protect your own account.
Verify the message outside the message
Do not use a login link in an unexpected warning until you have checked it. Open a saved bookmark or type the known service address, then look for its official security notice or account alerts.
The FTC's phishing guidance recommends contacting a company through a route you know is genuine rather than the details supplied in a suspicious message. Apply that rule even when the email contains your name or an old password.
Check the date. A newly discovered dataset may describe an older incident. The discovery date, breach date and notification date are not necessarily the same.
If the message asks for payment to remove your details from a breach, do not assume that payment can retrieve copies already distributed. Verify any legitimate support options through the provider.
Read the data categories, not just the headline
Look for the specific information involved: email addresses, profile details, passwords, payment information, documents or session tokens. Do not assume every breach includes all of them.
Have I Been Pwned explains its records and classifications in the official FAQ. A listing is evidence about a reported exposure, not a live test that somebody currently controls your account.
Likewise, a search returning no match does not prove an address has never been exposed. Coverage is incomplete, and some incidents are not publicly known. Use a breach checker as one source of information, not a clean bill of health.
Keep the result private. Posting a screenshot of every affected account can reveal more about your online activity than the original notification.
Change exposed or reused passwords first
If the affected password is still in use, change it through the official account settings. Use a unique replacement rather than a small variation of the old one.
If you reused that password elsewhere, prioritize those accounts too, especially email, cloud storage and services containing sensitive information. A breach at one site becomes more serious when the same secret opens several others.
Use the password-manager setup guide to generate and store unique credentials. Do not paste passwords into unfamiliar “strength checkers” or send them to a support person.
Where the service supports passkeys or a suitable second factor, review those options after regaining control. Avoid changing so many recovery settings at once that you lose your own working access.
Review sessions, recovery and forwarding
A password change is not the only account control worth checking. Review active sessions, recovery addresses, phone numbers and connected applications for changes you did not make.
For email accounts, inspect forwarding rules, filters and delegated access. An unwanted rule can redirect or hide messages even after the visible inbox appears normal.
Google's compromised-account guide provides a provider-specific recovery process. Follow the equivalent official procedure for the service involved rather than assuming every account revokes access in the same way.
Our active-session checklist and email recovery review give a practical order for those checks. Keep a trusted session available while establishing a safe replacement login route.
Respond to the information that cannot be changed
An email address or name does not become secret again because you changed a password. Be alert for more convincing messages that use the exposed context.
If payment or identity information is involved, contact the relevant bank, issuer or institution through its official channel and follow the guidance for your location. The appropriate action depends on the data and jurisdiction, so avoid applying a generic checklist as though every incident were identical.
Do not send a full identity document in response to an unsolicited “verification” email about the breach. Confirm the process independently and share only what the legitimate recipient requires.
For public contact information, the digital footprint audit can help reduce unnecessary exposure you control, but it cannot erase copies already taken in an incident.
Check the device when there are signs of compromise
A breach at a website and malware on your own device are different events. If the notice specifically concerns stolen browser data or you see unexplained software and account activity, use the device maker's or organization's security process.
Update the operating system and security software, and run an appropriate scan. On a work device, contact the security team rather than trying to conceal the issue or improvise a cleanup.
Change important credentials from a device you trust when compromise is suspected. Do not keep entering new passwords into a system you have reason to believe is still capturing them.
A single unfamiliar location in an account log is not enough to diagnose malware. Consider the evidence together and use official recovery guidance rather than alarming social-media claims.
Record the outcome and stop repeating the same work
Keep a short list of affected services, password changes, session reviews and unresolved questions. Do not store the old passwords or a copy of a leaked dataset in that record.
If you enable breach notifications, use a service whose process you understand and an email address you can maintain. Review future notices by incident and data type rather than treating every reminder as a new compromise.
The Privacy / Security directory provides relevant resources, while the Account security topic covers stronger sign-in and recovery habits.
The useful end state is clear: the notice was verified, affected secrets were replaced, unwanted access was removed and recovery still works. That is a much better response than clicking urgently through every warning that arrives.
Sources and further reading
- Have I Been Pwned: Frequently asked questions Consulted 28 September 2026.
- Google Account Help: Secure a compromised account Consulted 28 September 2026.
- FTC Consumer Advice: Recognize phishing scams Consulted 28 September 2026.
Consult the linked documentation for current details. Settings, availability and interface labels may change.
Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.