How to Check If Your Email Was Hacked
If your email address shows up in a data breach, criminals may have your password, personal details, or both. Checking whether you’ve been affected takes a few minutes and tells you exactly what to do next.
Check Breach Databases
The fastest way to know if your email appeared in a known breach is to search free, reputable breach-monitoring services.
Read also: Best Free Antivirus for Windows in 2026
Have I Been Pwned
Run by security researcher Troy Hunt, haveibeenpwned.com lets you type in your email and instantly see which breaches it appeared in. It lists the affected services and what data was exposed (passwords, phone numbers, and so on). You can also subscribe to be notified automatically if your address shows up in future breaches.
Built-In Browser and Manager Tools
- Google Password Checkup (passwords.google.com) flags saved passwords that were exposed in breaches.
- Firefox Monitor and the built-in checks in 1Password Watchtower or Bitwarden scan your stored credentials against breach data.
- Apple’s iCloud Keychain warns you about compromised passwords in Safari and iOS settings.
Signs Your Account Was Actually Hacked
A breach means data was exposed; a hack means someone is actively using your account. Watch for these warning signs:
- Login alerts or password-reset emails you didn’t request.
- Sent messages or social posts you didn’t write.
- Contacts reporting spam or strange messages from you.
- Missing emails or new forwarding/filter rules you didn’t create.
- Being locked out despite using the correct password.
Check your email account’s “recent activity” or “security” page, which lists devices and locations that have signed in. Unfamiliar entries are a strong indicator of compromise.
What to Do If You’ve Been Compromised
Act quickly and in this order to lock attackers out and limit damage.
- Change the password immediately to a long, unique one. If you can’t log in, use the account recovery process.
- Enable two-factor authentication so a stolen password alone is no longer enough.
- Review account settings: remove unknown forwarding addresses, filters, recovery emails, phone numbers, and connected apps.
- Change passwords on any other site where you reused the same password.
- Scan your device for malware, in case a keylogger captured your credentials.
- Warn your contacts if scam messages were sent in your name.
Prevent Future Breaches
You can’t stop companies from being breached, but you can make a breach harmless to you. Use a password manager so every account has a different password, meaning one leak never cascades. Turn on 2FA everywhere, prefer authenticator apps over SMS, and sign up for breach alerts so you learn about exposures as soon as they’re public. Periodically review and delete old accounts you no longer use, since each one is a potential weak point.
Step-by-Step: How to Check If Your Email Has Been Hacked in 2026
If you want a clear, repeatable routine, this is exactly how to check if your email has been hacked in 2026. Work through the steps in order and you will know within a few minutes whether your address has been exposed or is actively compromised.
- Search Have I Been Pwned first. Go to haveibeenpwned.com, enter your email address, and review every breach listed. Note which services were affected and what data leaked, since that tells you which passwords to change first.
- Run your password manager’s breach check. Open Google Password Checkup, 1Password Watchtower, or Bitwarden’s reports to see which saved logins were exposed or reused across sites.
- Open your account’s security dashboard. In Gmail visit the “Security” and “Recent security activity” pages; in Outlook use “Recent activity”. Both show every device, browser, location, and IP address that has signed in.
- Look for unusual login activity. Any sign-in from a country you have never visited, an unknown device, or a time you were asleep is a red flag that someone else has your password.
- Check for account security alerts. Search your inbox and spam folder for “new sign-in”, “password changed”, or “verification code” emails you did not trigger. These are often the first sign of a hack in progress.
- Confirm your recovery settings are still yours. Attackers frequently add their own recovery email, phone number, or forwarding rule so they keep access even after you change the password. Remove anything you do not recognise.
If any step turns up something suspicious, treat the account as compromised and follow the recovery steps above right away. For long-term protection, see our guide on how to protect your email from hackers.
Frequently Asked Questions
Is Have I Been Pwned safe to use?
Yes. It is a well-established, trusted service used by security professionals and even built into some browsers and password managers. It never asks for your password, only your email address, and it does not store or misuse what you enter.
My email is in a breach but I haven’t noticed anything wrong. What should I do?
Change the password for that service right away, especially if you reused it elsewhere, and enable two-factor authentication. A breach means your credentials may be circulating even if no one has used them yet, so don’t wait for visible signs of misuse.
Can someone hack my email if they only know my address?
Knowing your email address alone isn’t enough to break in; they also need your password or to trick you. However, your address lets them target you with phishing and check it against breach databases, which is why a strong, unique password and 2FA matter.
Should I delete my email account after a breach?
Usually no. Securing it with a new password and 2FA is more practical, since your email is tied to many other accounts. Deletion is only worth considering if the account is old, unused, or you’re migrating to a more secure provider.






