Skip to content
VaultPass

Breaches

How to check if your data has been leaked (and what each result means)

The VaultPass desk5 min read
A magnifying glass resting on a surface

Checking whether you are in a breach is free and takes a minute. What is usually missing is not the tool but knowing how to read the result: appearing in a breach from eight years ago and appearing in one from this month call for very different reactions.

Your data appearing in a breach does not depend on how careful you are. It depends on the security of every company you ever gave your email to. That is why almost anyone with more than ten years of online life appears in several.

The useful thing is not avoiding it — that is not in your hands — but finding out early and knowing what to do with the information.

The three ways to check

1. Your browser and your manager already do it

This is the most convenient route and plenty of people have it switched off without realising.

Chrome, Edge and Safari compare the passwords you save against lists of leaked credentials and warn you when there is a match. Password managers do the same, usually in a section called “security report” or “vault health”.

If you use a manager, start there: it gives you the complete list at once, without checking key by key.

2. Checking one specific password

For when you want to know whether one particular password has appeared in any breach, regardless of where you keep it.

How the tool does it matters a great deal here. The correct method is called k-anonymity and works like this:

  1. Your browser computes a hash of the password — an irreversible cryptographic digest.
  2. Only the first five characters of that hash are sent.
  3. The server returns every hash in its database starting with the same five: hundreds of results.
  4. Your browser looks for yours in that list, locally.

The server never learns which password you were checking, because the five characters it received correspond to hundreds of different passwords. That is how the VaultPass checker works.

The practical rule: if a site asks for the complete password and sends it to its server to check, do not use it. There is no way to know what it does with it.

3. Checking by email address

This tells you which specific breaches you appeared in. The reference services give you the affected company’s name, the date, and which kinds of data were exposed.

That last part is the most valuable information and the one almost nobody reads carefully.

How to read the result

Not all breaches mean the same thing. Read it along two axes: what leaked and when.

What leaked

  • Only the email address. Low risk. It translates into more spam and more targeted phishing. No password changes needed.
  • Email and a password hashed with a modern algorithm. Medium risk. Change it as a precaution, especially if it is short.
  • Email and password in the clear, or with outdated hashing (MD5, unsalted SHA-1). High risk. That password is burned. Change it everywhere you used it, today.
  • Personal data: phone, address, ID number, date of birth. These cannot be “changed”. Here the response is prolonged vigilance: this is the data used to impersonate you or to build very convincing phishing.
  • Banking data or cards. Tell the bank and ask for a new card.

When it happened

  • An old breach, password already changed. No action needed. Appearing in a 2012 forum leak means nothing today.
  • A recent breach. Act the same day.
  • An old breach but the password is still in use. This is the most dangerous case and the most common. Those lists keep being tried years later, through credential stuffing.

What to do with the answer

If a password you still use appears:

  1. Change it on the affected service, going to the official site yourself.
  2. Change it on every other site where you reused it.
  3. Turn on two-factor authentication, starting with email.
  4. Check open sessions and email forwarding rules.

If personal data appears, the response is different because there is nothing to change:

  • Expect phishing attempts using that data to sound credible. Someone knowing your address and your last order does not make them your courier.
  • Be especially wary of phone calls. Phone fraud using real leaked data is among the most effective there is.
  • If an identity document leaked, watch for odd activity for months: contracts, mobile lines or credit in your name.

How to reduce the damage from the next one

Because there will be a next one. What is in your hands:

Different passwords per site. This turns each breach into a local problem instead of a cascade.

Two-factor authentication on email and banking at a minimum.

Email aliases for minor sign-ups. Many providers let you create alternative addresses. If an alias starts receiving spam, you know exactly which service sold or lost your data, and you can switch it off without touching your main address.

Give less data. A shop does not need your date of birth to sell you trainers. Data you do not give cannot leak.

Delete accounts you no longer use. Every forgotten account is a future breach with your password from that era inside.

In short

  • Checking is free: your manager, your browser, or a checker using k-anonymity.
  • Never type your password into a site that sends it whole to its server.
  • What matters is not appearing, but what leaked and whether that key is still in use.
  • Personal data cannot be changed: there the answer is vigilance, not panic.
  • Unique passwords and two-factor turn the next breach into a notice with no consequences.

Frequently asked

The questions that keep coming up

Is it safe to type my password into a website to check whether it leaked?

Only if that site uses k-anonymity and does the work in your browser. In that case a hash is computed locally and only the first five characters are sent, so the server cannot know which password you were checking. If a site asks for the password in the clear, do not use it.

What is k-anonymity?

It is a technique for querying a database without revealing what you are looking for. You send a fragment of the hash matching hundreds of possible results and discard everything that does not match locally, so the server never learns which one interested you.

My email appears in several breaches. Is that serious?

It is normal and does not mean your accounts are compromised right now. What matters is what leaked in each case: if it was only the email, the risk is more spam and phishing. If the password went with it, change it everywhere you reused it.

Can I stop my data appearing in breaches?

Not entirely, because it depends on third parties' security. You can limit the damage: different passwords per site, two-factor authentication, and email aliases for minor sign-ups.

Keep reading