Your Email Was in a Data Breach. Here Is What to Do Next
Your email is in a data breach. Find what leaked, fix reused passwords, expect phishing, then contain the next one with one alias per site.
The breach notice is probably in your spam folder. Check there before you assume you never got one.
Your email address is in a data breach. That address might be ten years old, so of course this feels bad. The leak itself is rarely what costs you, though. What costs you is the week after: your reused password getting tried on a hundred sites, and phishing that quotes your own data back at you.
The last section is the one I'd read twice. One email alias per site, which is what AliasFleet is for. It's the part that protects you next time.
Find out what leaked
How do I check what a breach exposed about me?
Type your address into Have I Been Pwned. It lists every known breach containing it, and what each one took.
Then read paragraph four of the company's notice. Paragraph one says "we take security seriously." Paragraph four says what was taken.
While you're there, turn on its breach notifications. Next time, you'll hear about it from Troy Hunt's database before the company's PR gets around to you.
What leaked decides everything below. An email alone is mostly a spam problem. If passwords or ID numbers were in the dump, keep reading carefully. I wrote a longer piece on tracing which website leaked your email if you want to go deeper on finding the source.
Change the passwords
Which passwords do I change first?
The breached site's. Then every site where you reused it.
This is called credential stuffing. Attackers feed the leaked pair into software that tries it on site after site, while they sleep. It works for one reason: most people reuse passwords. Bitwarden's 2025 survey put the figure at 78%.
I've done this twice. The first time I changed them by hand and it took a weekend I won't get back. The second time I had a password manager and it took twenty minutes.
Start with your email. Every password reset flows through it, so it gets a unique password and two-factor authentication first. Then the bank. Forty unique passwords is not a memory task. Get a manager. Where a site offers passkeys, take it. Nothing to stuff.
Expect the phishing
What does breach phishing look like?
It knows your name, your old password, and the site that leaked it. The classic is the extortion email: "we have your password, it's hunter2, pay up." The password is real. It came from the breach. It's still a bluff. Delete it.
This is what one looks like in the wild, documented by Brian Krebs. Note the real password in the opening line. That is the whole trick.
A week after a big breach, inboxes fill with this stuff. That's the dump being worked through, address by address. The fakes copy the company's real follow-ups, so don't click links in any of it. If an email tells you to act, get there yourself. Fresh tab, type the address.
I don't know how long it lasts. Months, in my experience.
Don't make it worse
Two mistakes I see every time. First: replying to the phishing to tell them off. All that does is confirm the address is live, and the mail gets worse. Delete, don't engage.
Second: posting the breach notice on social media with your address visible in the screenshot. Now it's in two dumps. Crop it or don't post it.
Lock it down if ID data leaked
When do I need a credit freeze?
If the dump included your national ID number, passport number, or bank details. Then someone can try to open accounts as you, and this stops being an email problem.
In the US, IdentityTheft.gov builds you a recovery plan for exactly what was exposed. Ask one credit bureau for a fraud alert; it notifies the other two. A freeze is stronger, and it stays until you lift it.
Outside the US, call your bank's fraud team first. Faster than any guide.
Keep the breach notice somewhere. Dates, company name, what was taken. You'll want it if you ever dispute a fraudulent account.
Make the next breach harmless
How do I stop the next breach hurting me?
You can't. Every company you sign up for is a database waiting its turn.
What you can decide is what the next breach gets. Give every site its own email alias, and the next leak exposes an address that belongs to one site only. The spam arrives on that alias. Pause it. Done.
Six months from now another notice lands in your spam folder. You check which alias the mail is hitting, pause it, and get on with your day. That is the whole system.
It takes thirty seconds per site. The full method is in the leak-tracing piece; five aliases are free, and the steps are in the docs.
One honest limitation
No step on this list un-leaks your address. It's in the dump and it's staying there. What you did is limit what it can do, and set things up so the next one matters less. Anyone selling you a service that scrubs your data from a breach dump is selling you nothing.
You can't undo this breach. You can make the next one irrelevant.



Top comments (0)