Checking whether your email showed up in a data breach is free. Go to Have I Been Pwned, type the address, and read either “Good news — no pwnage found!” or “Oh no — pwned!” with a timeline of incidents. A hit is not automatic identity theft. The FTC’s 2022 consumer alert (Ari Lazarus, Oct. 24) is blunt: don’t ignore old-account notices because password reuse is the risk. Change that password and any similar one, turn on multi-factor authentication (authenticator app or security key), then follow IdentityTheft.gov/databreach for the data type that leaked. Paid identity monitoring is optional. If a Social Security number was exposed, a credit freeze is still the FTC-aligned lock — that is a different job from this email check; see credit freeze vs identity monitoring.
How to check your email on Have I Been Pwned
Have I Been Pwned lets you check whether an email address is in a data breach; using the site is subject to its terms of use.
- Open Have I Been Pwned yourself. Type haveibeenpwned.com in the address bar. Do not follow a pop-up, text, or search ad that says it will “check if you were hacked.”
- Enter the email address you want to check — an old gaming login, a shopping account, or the one you use every day.
- Read the result. You will see Good news — no pwnage found! if that address is not in the breaches loaded there, or Oh no — pwned! with a timeline of data breaches affecting it.
- Optionally choose Notify Me if you want to get notified of future breaches involving that address.
- Do not type your current password into random “breach check” ads or lookalike sites. Have I Been Pwned’s public check is an email lookup, not a place to paste the password you still use.
Email in a breach vs identity theft
A Have I Been Pwned hit means that email appeared in one or more known breaches; it does not by itself mean someone is opening accounts in your name.
The FTC says next steps depend on what was exposed — a reused password is a different problem from a Social Security number or a card. Checking the email is free. A credit freeze, if an SSN was in the mix, is the lock — not a paid monitoring plan. Use credit freeze vs identity monitoring for that decision; this page stays on the email check.
| What was exposed | What a HIBP hit usually means | FTC-aligned next step |
|---|---|---|
| Email + password | Login reuse risk, not automatic identity theft | Change the password on that company and anywhere you used a similar one; consider a password manager for unique passwords; turn on MFA (authenticator app or security key) |
| Social Security number | Higher new-account fraud risk | FTC points you to IdentityTheft.gov/databreach for steps based on what leaked. Freeze is still the lock if an SSN was exposed — see credit freeze vs identity monitoring. Paid monitoring is optional, not required |
| Card or bank details | Purchase or account-takeover risk | If someone is opening accounts or making purchases, report and get help at IdentityTheft.gov (FTC staff also cites 1-877-438-4338). For the first hour after a bad charge, use credit card fraud first hour |
What to do if the result is pwned
If Have I Been Pwned returns “Oh no — pwned!,” follow the FTC’s October 24, 2022 alert instead of buying monitoring first.
- Don’t ignore old accounts. Hackers know password reuse is common. An old gaming login can be the same string as a bank or email password.
- Change passwords right away on the company in the breach and on any account where you used a similar password.
- Consider a password manager so new passwords can be unique without memorizing each one. (That is the FTC’s advice; it is not a product pitch.)
- Turn on multi-factor authentication where the account offers it — an authenticator app or a security key, not only a reused password.
- Check what was exposed, then act by data type. The FTC points people to IdentityTheft.gov/databreach for steps based on whether it was a password, an SSN, bank information, or something else.
- If someone is already opening accounts or making purchases, report it and get help at IdentityTheft.gov. FTC staff also cites 1-877-438-4338.
- Watch for phishing that pretends they “found your data.” After a breach, scammers send mail and texts that look like a cleanup notice. Don’t click those links. Use a site you typed yourself. Pair with how to spot a phishing email.
FAQ
How do I check if my email was in a data breach?
Go to Have I Been Pwned, enter the address, and read “Good news — no pwnage found!” or “Oh no — pwned!” with a timeline. The check is free. Using the site is subject to its terms of use.
Does a Have I Been Pwned hit mean I have identity theft?
No. It means that email appeared in known breach data. Identity theft is when someone uses your information to open accounts or make purchases. The FTC’s next step depends on what was exposed, not on the word “pwned” alone.
My old unused account was in a breach — can I ignore it?
Don’t. The FTC’s 2022 alert is specifically about this: password reuse is the risk. Change that password and any similar one, then turn on MFA.
Should I pay for identity monitoring after I see “pwned”?
No, it is not required. Buy-nothing is valid. Change reused passwords and turn on MFA first. If an SSN was exposed, a credit freeze is the FTC-aligned lock — that comparison lives on credit freeze vs identity monitoring, not on this page.
I got an email saying they found my data in a breach. Should I click it?
No. The FTC’s phishing guidance: after a breach, watch for messages that pretend to be “we found your data.” Don’t click those links. Type Have I Been Pwned, your bank, or IdentityTheft.gov yourself. See how to spot a phishing email.
Is it safe to enter my email on Have I Been Pwned?
Type haveibeenpwned.com yourself and follow its terms of use. We do not invent how the site stores addresses. Never paste your current password into a random “breach check” ad.
If you still want a paid suite
You do not need a paid suite to check Have I Been Pwned or to change passwords.
A free check, unique passwords, MFA, and — if an SSN leaked — a credit freeze cover the FTC-aligned path. Paid identity monitoring is optional. Norton LifeLock-style identity add-ons are a different comparison than this email lookup; use credit freeze vs identity monitoring if that is the question, and do not treat monitoring as required.
If you later want a household security suite for other reasons, compare on-site paid pages only: TotalAV, Norton, Bitdefender, McAfee, Avast. Do not run a second real-time antivirus next to Defender.