Account exposure guide

Was my email in a breach?

A breach match means information tied to your address appeared in a known incident. It does not prove that someone currently controls your account—and a clean result is not a guarantee.

Check directly with Have I Been Pwned

Privacy boundary: HackProof does not provide an email field. The button opens Have I Been Pwned, where you decide whether to enter your address. HackProof never receives it.

If a match appears

  1. Read the breach date and exposed data types. A leak of email addresses alone calls for extra phishing caution; exposed passwords require credential changes.
  2. Change any password that was used on the affected service. If you reused it, change every account that shared it—starting with your primary email and financial accounts.
  3. Turn on multifactor authentication. Prefer passkeys, security keys, or an authenticator app where offered.
  4. Review recent sessions and recovery methods. Sign out unknown devices and remove recovery addresses or phone numbers you do not recognize.
  5. Watch for targeted messages. Breached profile details can make phishing more convincing. Open official apps directly instead of using unexpected links.

What a result cannot tell you

Public breach data is incomplete and can appear long after an incident. A match does not identify who has the data or whether they used it. No match does not prove that an account, device, or password is secure.

Check a password separately

Return to the HackProof password exposure check. The password is hashed in your browser and only a five-character hash prefix is sent to the Pwned Passwords range service.