BloomerBoomer

Life, money and technology after 55

Technology

Technology

Checking Whether Your Details Have Been Leaked

If you have had an email address for more than a few years, some of your details are almost certainly in a leaked database. That is not a statement about your carefulness — it is a statement about the companies you have accounts with.

The useful question is not whether it happened, but which accounts are affected and what to do first.

What a breach actually exposes

Email addresses and passwords. The combination that matters most, because it is fed into automated systems that try it everywhere else.

Names, addresses, phone numbers, dates of birth. Used to make impersonation calls convincing. This is why a caller can know your address and the last four digits of your card. See the call from your bank.

Security question answers. Mother's maiden name, first school, first pet — as damaging as passwords and far less often changed.

Payment details, less commonly, and usually partial.

How to check

Use haveibeenpwned.com. Enter your email address. It tells you which known breaches include it. The site is free, well regarded, run by a security researcher, and does not ask for a password.

Check every address you use, including old ones and the one you never look at.

Your password manager will also tell you. Most flag saved passwords that appear in known breaches, and this is more useful because it points at specific accounts. See password managers.

Your phone may tell you too. Both iPhone and Android now warn about saved passwords found in leaks. iPhone: Settings → Passwords → Security Recommendations. Android: Google Password Manager → Password Checkup.

Be sceptical of anything else. Sites offering to "scan the dark web" for a fee are largely selling anxiety. Some are worse than useless — a service that asks for your Social Security number to check whether your Social Security number has leaked deserves the obvious question.

What the result means

A long list is normal. It reflects the companies you have used, not anything you did.

What matters is whether passwords were included, and whether you reused them.

Old breaches still matter if the password is still in use somewhere.

"No results" is not proof of anything. Not every breach becomes public.

What to do, in order

1. Your email account first. Change it to a new unique password and turn on two-factor authentication. Whoever controls your email can reset everything else, which makes it the most valuable account you own. See two-factor authentication.

2. Anywhere you used that same password. Every account sharing it is exposed. This is the step that actually closes the risk.

3. Bank and payment accounts. New passwords, two-factor on.

4. Security questions. If answers were exposed, change them. You do not have to answer truthfully — a stored random phrase is safer than your real mother's maiden name.

5. Check for changes you did not make. In your email, look for forwarding rules — a rule silently copying your mail elsewhere is the standard first move after an account is compromised, and it is easy to miss. Also check recovery addresses and phone numbers.

6. Consider a credit freeze if identity details were exposed. Free with all three bureaus, and liftable when you need it.

Expect the follow-on contact

Breached details are sold, and one of the things they are used for is targeted approaches.

A caller who knows real details about you is not thereby legitimate. Knowing your address, your bank or part of a card number proves only that they bought a list.

A message saying "we noticed suspicious activity" shortly after a breach is frequently the fraud rather than the response to it.

Anyone offering to remove your data from the dark web for a fee is selling something that cannot be done. Once a database is circulating, it is circulating.

Reducing what is available next time

Breaches will keep happening. What is in them is partly within your control.

A different password for every account, which is what makes any single breach survivable.

Two-factor authentication, which makes a leaked password insufficient on its own.

Fewer accounts. Every service you sign up for is another company holding your details. Deleting accounts you no longer use genuinely reduces exposure.

Less information given. Date of birth, phone number and address are frequently optional and frequently requested anyway.

A separate email address for shopping and sign-ups, keeping your main address for banking, family and anything important.

The two minutes worth spending

  • [ ] Check your main email address at haveibeenpwned.com
  • [ ] If passwords were exposed, change your email password first
  • [ ] Then anywhere you used the same one
  • [ ] Turn on two-factor authentication for email and banking
  • [ ] Check your email for forwarding rules you did not create

The last item takes thirty seconds and is the one that catches an account that is currently compromised rather than one that might be.

For additional public information on consumer fraud and scam prevention, see Federal Trade Commission.