Companies get breached constantly, and your email address has probably shown up in at least one leaked database without you ever being told directly. Here’s how to actually check, and what to do if it has.
Use a breach-checking service
Have I Been Pwned (haveibeenpwned.com) is the most widely trusted free tool for this. Enter your email address and it will show every known breach that included it, along with what kind of data was exposed — passwords, phone numbers, physical addresses, and so on. It’s run by a security researcher and used by browsers and password managers as a data source, not a company trying to sell you something.
Check your browser’s built-in tool
Chrome, Safari, and Firefox all include password breach monitoring now. In Chrome, go to Settings > Autofill and passwords > Google Password Manager > Password Checkup. It flags any saved password that appears in a known leak.
If you’re in a breach, do this
Change the password for that specific account immediately, and change it anywhere else you reused it — this is the step people skip most often, and it’s the one that actually matters, since breached credentials get tried against other sites automatically by attackers. Turn on two-factor authentication wherever it’s offered, so a leaked password alone isn’t enough to get in.
Stop reusing passwords going forward
A password manager (built into your browser or a dedicated app) that generates and stores a unique password per site is the single biggest thing you can do to limit how much damage any one breach can cause.