Account exposure guide
Was my email in a breach?
A breach match means information tied to your address appeared in a known incident. It does not prove that someone currently controls your account—and a clean result is not a guarantee.
Check directly with Have I Been Pwned
Privacy boundary: HackProof does not provide an email field. The button opens Have I Been Pwned, where you decide whether to enter your address. HackProof never receives it.
If a match appears
- Read the breach date and exposed data types. A leak of email addresses alone calls for extra phishing caution; exposed passwords require credential changes.
- Change any password that was used on the affected service. If you reused it, change every account that shared it—starting with your primary email and financial accounts.
- Turn on multifactor authentication. Prefer passkeys, security keys, or an authenticator app where offered.
- Review recent sessions and recovery methods. Sign out unknown devices and remove recovery addresses or phone numbers you do not recognize.
- Watch for targeted messages. Breached profile details can make phishing more convincing. Open official apps directly instead of using unexpected links.
What a result cannot tell you
Public breach data is incomplete and can appear long after an incident. A match does not identify who has the data or whether they used it. No match does not prove that an account, device, or password is secure.
Check a password separately
Return to the HackProof password exposure check. The password is hashed in your browser and only a five-character hash prefix is sent to the Pwned Passwords range service.