Data Breaches and Your Email Address: What Leaks and What to Do
If you have used the internet for more than a few years, your email address is almost certainly sitting in at least one leaked database. That on its own is not a disaster, but it is the starting point for most spam, phishing and account takeovers. This guide explains how addresses leak, what criminals do with them, how to check your own exposure and how to limit the damage next time.
How email addresses end up in breaches
- Company breaches. An attacker gets into a website's database and copies the customer table: email addresses, usually names, often password hashes, sometimes addresses and phone numbers.
- Misconfigured storage. A database or cloud storage bucket is accidentally left open to the internet and found by someone scanning for exactly that.
- Third-party leaks. A marketing platform, analytics vendor or support tool that a company shared your data with is breached instead of the company itself.
- Data brokers and scraping. Addresses published or collected from profiles, forums and old sign-ups are bundled and sold, no breach required.
Every service that holds your real address is another place it can leak from. You cannot control their security, only how many of them have it.
What criminals do with a leaked address
Spam and targeted phishing
The simplest use is a mailing list. More dangerous is context: if a breach reveals that you are a customer of a particular shop, bank or streaming service, a phishing email pretending to be from that company is far more convincing. See How to Spot a Phishing Email for the warning signs.
Credential stuffing
When breaches include passwords (even hashed ones, many of which can be cracked), attackers feed email and password pairs into login pages of other sites automatically. This is called credential stuffing, and it works because people reuse passwords. One leak from a small forum can open an email account, a shopping account or a bank.
Extortion scams
"I know your password, and I recorded you through your webcam" emails quote a real old password from a breach to seem credible. The recording claim is invented. Do not pay; change that password anywhere you still use it.
How to check whether you were exposed
The free service Have I Been Pwned, run by security researcher Troy Hunt, lets you enter an email address and see which known breaches include it. You can also sign up to be notified about future breaches. Many password managers and browsers now run similar checks against your saved passwords.
What to do after a breach
- Change the password for the breached site, and anywhere else you used the same or a similar password.
- Use a password manager so every site gets a long, unique, random password. Then one breach can only ever unlock one account.
- Turn on two-factor authentication, starting with your email account. Whoever controls your email can reset almost every other password you have.
- Be extra suspicious of messages about the breached service for the next few months. Scammers love "your account was affected, click here to secure it" emails.
- If financial or identity details leaked, watch your bank statements and consider a credit freeze with the credit bureaus in your country.
Limiting the damage next time
You cannot stop companies being breached, but you can control what they hold about you:
- Do not give your real address to sites you do not need. For one-off sign-ups use a temporary address. It cannot leak later because it no longer exists.
- Use a separate alias for each service you keep. When one leaks, you know which company it was and you can switch that alias off. Our comparison of aliases and disposable email explains the options.
- Close accounts you no longer use. An old account on a forgotten site is a leak waiting to happen. Many sites let you delete your data from the account settings.
- Share less. Leave optional fields such as phone number, date of birth and address empty unless the service truly needs them.
Why EmailVanish keeps nothing
A privacy tool that stored your data would become a target itself. A free EmailVanish inbox is deleted ten minutes after its last message arrives, and we never ask who you are, so there is almost nothing about you on our systems to steal. (Premium subscribers choose to keep some addresses longer; that data is described separately.) Our privacy policy lists exactly what is and is not kept.
