A free data breach check takes about five minutes, and it tells you two different things: which leaks your email address showed up in, and whether any password you still use is already in criminals’ hands. Those are separate checks, and most people only do the first one.
The short version
You can check your email at Have I Been Pwned and your saved passwords with Google Password Manager or the iPhone Passwords app, both free. What you do next depends on what leaked, not just whether you were in a breach.
- Have I Been Pwned listed 1,043 breaches covering about 17.8 billion accounts when we counted its public list on Oct. 10, 2026.
- Of the 108 breaches it added in 2026, only 20 included passwords, while 68 included phone numbers.
- A leaked password means changing it everywhere you used it and turning on two-factor sign-in.
- A leaked phone number or address means watching for scam texts, calls and fake delivery messages.
- Nobody legitimate will email you asking for money or a code to remove your data from a breach.
In plain terms: being “in a breach” sounds scary, but the damage depends on what was taken. In the breaches added this year, a phone number leaked far more often than a password. That changes what you should watch for.
How to run a data breach check on your email
Start with Have I Been Pwned, a free breach lookup created by Australian security researcher Troy Hunt. It does not ask you to sign in or pay.
- Go to haveibeenpwned.com and type one email address.
- Read the list of breaches it shows. Each one says when it happened and what was taken, such as names, phone numbers or passwords.
- Repeat for every address you use, including old ones you still have linked to bank, shopping or social accounts.
- Use the free “Notify me” option so you get an email if your address appears in a future breach.
A clean result is good news, but it is not a guarantee. The site only lists breaches whose data has been found and loaded. Some breaches involving sensitive data are hidden from public search and only shown to the verified owner of the address.
What our count of 2026 breaches shows
We pulled Have I Been Pwned’s public breach list on Oct. 10, 2026, and counted what was in each one. Here is what stood out.
- 108 breaches were added between Jan. 1 and Oct. 10, 2026, covering about 539.8 million accounts.
- 20 of those 108 (about 19%) included passwords.
- 68 of the 108 (about 63%) included phone numbers.
- Between Sept. 10 and Oct. 10, nine breaches were added, covering about 40.3 million accounts. One was a set of about 4.65 million Chess.com records posted online in August, with email addresses, names, usernames and locations. Have I Been Pwned says the data appears to have been scraped, and 99% of those email addresses were already in earlier breaches.

The takeaway is simple. For most people this year, the risk from a breach is less “someone has my password” and more “a scammer has my name, number and email, and can make a fake message look real.”
How to check if your password leaked
Your email check does not tell you whether a password you use today is out there. For that, use the password manager you already have.
- Chrome or Android: go to passwords.google.com, choose Go to Password Checkup, then Check passwords. It flags passwords that have been exposed, are weak, or are reused.
- iPhone, iPad or Mac: open the Passwords app and tap Security. It lists passwords that are weak, reused or have appeared in data leaks. To get alerts about new leaks on iPhone, go to Settings, then Apps, then Passwords, and make sure Detect Compromised Passwords is on.
- Another password manager: look for a section called Watchtower, Security or Health. Most paid managers run the same check.

Change any password marked as exposed first, then the reused ones. If you need a refresher on doing this in the right order, our guide to securing every account you own in one afternoon walks through it step by step.
What to do after a data breach, by what was taken
Match your next step to the data that leaked.
- Password: change it on that site and on every other account where you used the same one. Then turn on two-factor authentication, or switch to a passkey where the site offers one.
- Phone number: expect more scam texts and calls. Never read out or forward a one-time code, even to someone who says they work for your bank.
- Email address and name: watch for emails that use your real name and mention a service you really use. Those are the ones people fall for. Our guide on spotting a phishing email covers the signs.
- Home address or date of birth: watch for fake delivery and “account update” messages. In the US, a free credit freeze at all three credit bureaus stops new loans in your name.
- Bank or card details, or a government ID: call your bank using the number on your card, and ask what extra protection it offers.
The breach scam to watch for
Scammers know people search for breach news. Some send emails saying your data was leaked and offering to “remove” it for a fee, or ask you to confirm your password to “secure” your account. Real breach tools do not ask for your password or for payment. If a message pushes you to act fast, close it and go to the service’s own website or app instead.
Make it a habit
Set a reminder to run both checks every three months, and turn on breach alerts so you hear about new leaks without having to look. The whole routine takes less time than making a cup of tea, and it means you deal with a leak before a scammer uses it.




