Data Breaches Are Common
Data breaches — when hackers steal user information from companies — happen constantly. Major companies like Facebook, LinkedIn, Marriott, Equifax, and countless others have all been breached. If you've used the internet for any length of time, your information has almost certainly been exposed in at least one breach.
The question isn't whether your data has been leaked, but what you can do about it.
Check If You've Been Affected
You can check if your email address or personal information has been exposed in known data breaches:
haveibeenpwned.com is safe and widely recommended by security professionals. It doesn't store or share your information — it simply checks if your email appears in publicly known breach databases.
- Visit haveibeenpwned.com — this free, trustworthy service (run by a Microsoft security expert) checks your email address against all known data breaches.
- Enter your email address and it will tell you which breaches included your information.
- You can also sign up for alerts to be notified if your email appears in future breaches.
What Gets Exposed in a Breach
Different breaches expose different types of information:
- Email addresses and usernames — the most commonly exposed data.
- Passwords — sometimes in encrypted form (hashed), sometimes in plain text.
- Names, phone numbers, and physical addresses.
- Dates of birth.
- Payment card information (less common but more serious).
- Social Security numbers or national ID numbers (rare but very serious).
Steps to Take After a Breach
When you learn your information was exposed:
- Change the password for the breached service immediately.
- If you used the same password anywhere else (now you know why not to), change it on those services too.
- Enable two-factor authentication on the affected account.
- Watch for phishing emails that reference the breach — scammers often send fake "breach notification" emails with malicious links.
- Monitor your bank statements for unusual activity.
- Consider a credit freeze if sensitive financial information was exposed (Social Security number, etc.).
Credit Freezes and Fraud Alerts
If your Social Security number (US), National Insurance number (UK), or equivalent ID was exposed, consider:
If your Social Security number or government ID was exposed, a credit freeze is strongly recommended. It's free and can prevent identity thieves from opening accounts in your name.
- Credit freeze: Contact each credit bureau (in the US: Equifax, Experian, TransUnion) and request a freeze. This prevents anyone from opening new credit accounts in your name. You can temporarily lift the freeze when you need to apply for credit.
- Fraud alert: A fraud alert tells creditors to verify your identity before opening new accounts. In the US, placing a fraud alert with one bureau automatically applies it to all three.
- Credit monitoring: Many breached companies offer free credit monitoring to affected users. Take advantage of this — it will alert you if someone tries to use your identity.
Long-Term Protection
After a breach, stay vigilant:
- Be extra cautious of emails mentioning the breach — scammers send fake "update your password" emails that look like legitimate breach notifications.
- Use unique passwords for every service (a password manager makes this manageable).
- Enable 2FA on all important accounts.
- Check haveibeenpwned.com periodically or sign up for their email alerts.
- Consider using email aliases or a service like Apple's "Hide My Email" so each site has a different email address.