Data Breaches and Your Email Address: What Leaks and What to Do

By Michael Goldsmith · Updated September 23, 2026

If you have used the internet for more than a few years, your email address is almost certainly sitting in at least one leaked database. That on its own is not a disaster, but it is the starting point for most spam, phishing and account takeovers. This guide explains how addresses leak, what criminals do with them, how to check your own exposure and how to limit the damage next time.

How email addresses end up in breaches

Every service that holds your real address is another place it can leak from. You cannot control their security, only how many of them have it.

What criminals do with a leaked address

Spam and targeted phishing

The simplest use is a mailing list. More dangerous is context: if a breach reveals that you are a customer of a particular shop, bank or streaming service, a phishing email pretending to be from that company is far more convincing. See How to Spot a Phishing Email for the warning signs.

Credential stuffing

When breaches include passwords (even hashed ones, many of which can be cracked), attackers feed email and password pairs into login pages of other sites automatically. This is called credential stuffing, and it works because people reuse passwords. One leak from a small forum can open an email account, a shopping account or a bank.

Extortion scams

"I know your password, and I recorded you through your webcam" emails quote a real old password from a breach to seem credible. The recording claim is invented. Do not pay; change that password anywhere you still use it.

How to check whether you were exposed

The free service Have I Been Pwned, run by security researcher Troy Hunt, lets you enter an email address and see which known breaches include it. You can also sign up to be notified about future breaches. Many password managers and browsers now run similar checks against your saved passwords.

Finding your address in a list is normal and not a reason to panic. What matters is what else was exposed with it, especially passwords, and whether you have reused those passwords anywhere.

What to do after a breach

  1. Change the password for the breached site, and anywhere else you used the same or a similar password.
  2. Use a password manager so every site gets a long, unique, random password. Then one breach can only ever unlock one account.
  3. Turn on two-factor authentication, starting with your email account. Whoever controls your email can reset almost every other password you have.
  4. Be extra suspicious of messages about the breached service for the next few months. Scammers love "your account was affected, click here to secure it" emails.
  5. If financial or identity details leaked, watch your bank statements and consider a credit freeze with the credit bureaus in your country.

Limiting the damage next time

You cannot stop companies being breached, but you can control what they hold about you:

Why EmailVanish keeps nothing

A privacy tool that stored your data would become a target itself. A free EmailVanish inbox is deleted ten minutes after its last message arrives, and we never ask who you are, so there is almost nothing about you on our systems to steal. (Premium subscribers choose to keep some addresses longer; that data is described separately.) Our privacy policy lists exactly what is and is not kept.