Data breaches

Data breach check: how to see if your data was leaked

If a company you have an account with is breached, your email address, password or personal details can end up in a database that other people can buy or download. A breach check tells you whether that has happened to you. It takes a few minutes and the first checks cost nothing.

Last updated: 31 May 2026Independent guidance, Australia-first

The short answer

Run your email address through a public breach database such as Have I Been Pwned, then repeat the check on a second database such as the Cybernews personal data leak checker, because no single corpus holds every breach. Both searches are free. A positive result tells you an address was exposed somewhere, not which of your accounts are involved, so the third step is mapping the result back to the accounts you actually hold and fixing the ones that matter. Most people can complete all three steps in under fifteen minutes.

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.

Australian & independentThird-party security assessmentSources cited

Key takeaways

  • A breach check searches leaked databases for your email address or phone number. It is free and it does not require your password.
  • No checker holds every breach, so a clean result on one tool is not proof you are unaffected. Run two.
  • A breach name is not an action list: the database cannot tell you which of your own accounts sit behind it.
  • Reused passwords are what turn one breach into several, because attackers replay leaked pairs across other sites.
  • Checking once is a snapshot. Notifications or ongoing monitoring are what catch the next incident.

Why it matters

What a breach check actually tells you

A breach check searches collections of data that has already leaked from other companies. When an organisation is compromised, the records taken often circulate publicly, and services such as Have I Been Pwned and Cybernews index those records so you can search them for your own identifiers.

That gives you one specific, useful fact: whether your email address or phone number appears in a known leak, and often what kind of data sat alongside it. What it does not give you is the thing most people actually want, which is a list of the accounts you hold that are now at risk. The database knows the breach; it does not know you.

A checker never needs your password

Legitimate breach checkers search by email address or phone number. If a site asks you to enter a password to “see if it was leaked”, close it. The one safe exception is Have I Been Pwned's Pwned Passwords tool, which is purpose-built so the password itself is never sent.

In Australia, organisations covered by the Privacy Act must notify affected people about eligible breaches under the Notifiable Data Breaches scheme. That notification is worth acting on, but it only covers incidents that have been identified and reported, and it only reaches you if the company still has current contact details for you. Running your own check fills the gaps.

Step 1

Search a public breach database

Start with Have I Been Pwned, the best-known free checker. You enter an email address and it returns the indexed breaches that address appears in, along with the categories of data exposed in each one. Checked in July 2026 it listed 1,019 breached websites and 17,708,582,733 accounts.

Three parts of it are worth knowing about:

  • Email search is free and does not require an account. This is the check most people need.
  • Notify Me emails you if your address turns up in a future breach, which converts a one-off check into an ongoing one.
  • Pwned Passwords checks whether a specific password has appeared in a breach, without transmitting the password itself.

Paid tiers exist for people who want API access or domain-wide monitoring, starting at US$4.39 per month for the smallest Core plan (checked July 2026), but the search you came for is free. If you want the background on how the service works and what “pwned” means, see our Have I Been Pwned guide.

Step 2

Run the same check against a second database

No breach corpus is complete. Each service collects what it can verify, from different sources, at different times, which is why two reputable checkers can disagree about the same address. The Cybernews personal data leak checker is a good second opinion, and unlike most email-only tools it also accepts a phone number in international format. Cybernews states it does not collect or store the email addresses entered.

Coverage and inputs for two free breach checkers, checked July 2026
CheckerBreached sites indexedAccounts indexedAccepts
Have I Been Pwned1,019More than 17.7 billionEmail address
Cybernews leak checker36,030More than 18.6 billionEmail address or phone number

The gap between those totals is the point, not a discrepancy to resolve. They are counting different collections, so a breach missing from one may be present in the other. Treat a positive result from either as real, and treat two clean results as encouraging rather than conclusive. If you want a wider set of options, our Have I Been Pwned alternatives guide compares the tools side by side.

Counts move, and quickly

Every figure on this page is date-stamped because breach corpora grow continuously. Use the numbers as a sense of scale, not as a current reading, and check the source links for today's totals.

Step 3

Map the result back to your own accounts

This is the step people skip, and it is where a breach check becomes useful. A database can tell you that your address was in a particular leak. It cannot tell you that the leak was the streaming service you signed up to in 2019, forgot about, and reused a password on.

To close that gap manually:

  1. List the breaches your check returned and note what was exposed in each, especially passwords, phone numbers and identity documents.
  2. Work out whether you still hold that account. Searching your inbox for the service name is usually faster than trying to remember. Our guide on how to find accounts linked to your email covers the search terms that surface the most.
  3. Check whether the password was reused anywhere. This is the single highest-value question, because credential stuffing is how one breach becomes five.
  4. Close what you no longer use. A dormant account is still a place your data can leak from. See how to delete old accounts.

See which of your accounts are exposed

In The Event Of connects a supported inbox (Gmail or Outlook) and maps the accounts tied to your email, then shows breach exposure against the accounts you actually hold. Free to start, no credit card required.

Check my exposure free

Positive result

If a check comes back positive

Finding your address in a breach is common and not a reason to panic. The short version, in priority order: change the password on the affected account and anywhere you reused it, turn on multi-factor authentication, and expect a rise in phishing that name-drops the breached company. Report anything that tries to defraud you to Scamwatch.

The full sequence, including what to do when the exposed data includes identity documents, is a guide of its own:

Known incidents

Check a specific breach you have heard about

If your check flagged a company by name, or you have simply seen one in the news, we maintain a per-incident guide for each major breach covering what was exposed, who was affected and the exact steps to secure that account. The full list lives at our breach guides index. Frequently searched ones include:

If the breach that turned up is not on that list, the response steps are the same regardless of which company was involved.

Staying current

Turn a one-off check into ongoing cover

A breach check is a snapshot of a moving target. The address that comes back clean today can appear in a corpus next month, and you will not know unless something is watching. Two low-effort habits close that gap:

Using In The Event Of

How In The Event Of helps

A public breach database answers “was this address in a leak”. In The Event Of is built to answer the follow-up question: which of your accounts does that actually affect, and what do you do about each one.

You connect a supported inbox, Gmail or Outlook, and it scans account-related metadata, sender addresses, subject lines, labels and timestamps, rather than the body of your emails. From that it builds a map of the services tied to your address, including the ones you had forgotten, and shows breach exposure against those real accounts with guided steps for each.

The free tier covers discovering linked accounts from a supported inbox, the footprint map, guided checklists, progress tracking, baseline breach checks and essential alerts. The paid Protection plan is A$10 per month or A$99 per year, with a 14-day free trial on the monthly option, and adds multiple email addresses, deeper breach detail, priority alerts, richer remediation guidance and continuous monitoring. You stay in control of every change.

FAQ

Frequently asked questions

How do I check if my data was breached for free?
Enter your email address into a reputable free breach checker. Have I Been Pwned searches without asking you to create an account, and the Cybernews personal data leak checker accepts an email address or a phone number in international format. Both are free to search. To see which of the accounts you actually hold are affected, rather than a list of breach names, In The Event Of has a free tier that maps the accounts tied to a supported inbox.
Why do different breach checkers give different results?
Each checker maintains its own corpus of leaked data, and no corpus contains every breach. Checked in July 2026, Have I Been Pwned listed 1,019 breached websites and more than 17.7 billion accounts, while the Cybernews checker reported 36,030 breached websites and more than 18.6 billion accounts. A clean result on one tool is not proof you are unaffected, which is why it is worth running two.
Is it safe to enter my email into a breach check site?
With well-known checkers, yes. Have I Been Pwned lets you search without an account, and Cybernews states it does not collect or store the email addresses entered. The rule to hold onto is that a legitimate checker never asks for your password. Be wary of unfamiliar sites that request excessive personal detail or payment before showing a result.
Does a breach check tell me which of my accounts are exposed?
Not on its own. A breach database tells you that an address appeared in an incident, not which of the services you personally use are involved, and it cannot see the accounts you have forgotten about. Pairing a public check with a map of the accounts linked to your inbox is what turns a list of breach names into a list of things to fix.
Can I check a phone number instead of an email address?
Sometimes. Most breach databases index email addresses, because that is the field most commonly exposed. The Cybernews personal data leak checker accepts a phone number in international format, which makes it a useful second check if your number is the identifier you care about.
How often should I run a breach check?
Every few months is sensible for a manual check, plus any time a company you deal with announces an incident. The Have I Been Pwned Notify Me service emails you when your address appears in a new breach, and In The Event Of includes baseline breach checks and essential alerts on its free tier, with continuous monitoring on the paid Protection plan.

Disclaimer: Breach and account totals were checked in July 2026 and change continuously. Third-party tool features and pricing are summarised from the operators' own pages and may change. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.