When an email address appears in a data breach, immediate action is required to secure online accounts and prevent unauthorized access. Stolen credentials are involved in 88 percent of web application breaches, according to Verizon’s 2025 Data Breach Investigations Report , making leaked email addresses a primary target for attackers.
The first step is to confirm whether the email was actually exposed in a known breach. The free service Have I Been Pwned allows users to enter an email address and check against billions of leaked credentials from known data breaches, without sharing the password . The platform maintains a database of over 15 billion accounts across 917 known breaches, and also offers an optional notification feature for future leaks .
Change the password for the email account itself immediately, as it serves as the recovery method for most other online services . Any account that uses the same password as the breached email should also be updated, since credential-stuffing bots automatically test leaked combinations across hundreds of sites . Password managers with built-in breach reports, such as 1Password’s Watchtower or Bitwarden’s Exposed Passwords report, can identify reused or compromised passwords across all stored accounts .
Enable two-factor authentication (2FA) on all accounts that offer it, with priority given to banking, email, and cloud storage services . Hardware security keys like YubiKey provide the strongest phishing-resistant protection, followed by authenticator apps that generate time-based codes . SMS-based 2FA is considered the weakest option due to SIM swap and phishing risks .
Monitor financial accounts and statements regularly for unauthorized transactions or unusual activity . Services like IDCARE offer free support for identity theft victims in Australia, and the Cyber.gov.au ‘Have you been hacked?’ interactive tool provides tailored advice based on what information was leaked . For work email addresses, organizations should check authentication records including SPF, DKIM, and DMARC settings for anomalies and notify IT security teams immediately .
Once data is posted on the dark web, it cannot be removed due to the decentralized nature of criminal marketplaces . Instead, the focus should be on making the exposed data useless by changing passwords, enabling 2FA, and using unique credentials for every account . Continuous monitoring services, including built-in features on Apple devices and Google Password Manager, can provide ongoing alerts when new breaches are detected .