Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

How to Check if Your Business Email Has Been Breached

In short

When a website you use gets hacked, your email and password can end up on lists criminals trade and reuse. Free tools like Have I Been Pwned let you check whether your business email has appeared in a known breach. If it has, change the password, turn on MFA, and set up ongoing monitoring so you're warned early next time.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Somewhere out there, on lists that criminals buy, sell and swap, sits a huge pile of leaked email addresses and passwords — billions of them, harvested from years of website hacks. There’s a reasonable chance one of your business email addresses is on it. That sounds alarming, but you can check in under a minute, for free, and take a few simple steps to shut down the risk. Here’s how.

How your email ends up in a breach

You don’t have to do anything wrong to end up in a data breach. It usually works like this: you sign up to some website — a supplier portal, an online shop, a forum, a marketing tool — using your work email and a password. Months or years later, that website gets hacked. The attackers make off with its user database, and your email address and password are in it. That data then gets leaked publicly or traded among criminals.

The real danger is what they do next. People reuse passwords. If the password leaked from that hacked shop is the same one — or close to the same one — you use for your email or Microsoft 365, criminals will try it there too. This is exactly how many account takeovers happen: not by cracking your account directly, but by walking in with a password you leaked somewhere else entirely.

The real danger isn’t the hacked website you’d half forgotten about — it’s that criminals will try the leaked password on your email, your Microsoft 365 and everything else you own.

How to check, for free

The best-known tool is Have I Been Pwned (haveibeenpwned.com), a free and well-respected service that catalogues known data breaches. To use it:

  1. Go to the site and enter your business email address — just the address, never your password.
  2. It tells you whether that address has appeared in any breaches it knows about, and lists which ones.
  3. Each result names the breached service and roughly what was exposed — email, password, phone number and so on.

Check each address your business uses, including shared mailboxes like info@ or accounts@. If nothing comes up, that’s reassuring but not a guarantee — no tool knows about every breach. If addresses do appear, don’t panic: it’s common, and the steps below deal with it.

A related check some tools and password managers offer is telling you whether a specific password you use has appeared in a breach. If it has, that password is effectively public and should be retired everywhere you’ve used it.

What to do if your email appears

Finding your address in a breach is a prompt to act, not a cause for alarm. Work through these steps in order.

1. Change the password — everywhere you reused it. Start with the breached service if you still use it, then, more importantly, change the password anywhere else you used the same or a similar one. This is the moment to stop reusing passwords for good: every account should have its own long, unique password. A password manager makes that painless — see our pick of the best password manager for a UK small business. Tools like Proton Pass generate and store a different strong password for every site, so a single leak can never unlock the rest.

2. Turn on multi-factor authentication (MFA). This is the big one. Even if a criminal has your correct, current password, MFA stops them getting in without the second factor on your phone. Switch it on for your email, Microsoft 365 and anything holding money or customer data. Our step-by-step MFA guide walks you through it, and Cyber Essentials requires MFA on all cloud services anyway — so this ticks two boxes at once.

3. Check your account for signs of misuse. Look at your inbox and, crucially, your sent items and deleted items for messages you didn’t send. Review your email rules and forwarding settings — a classic attacker trick is to quietly forward or auto-delete certain messages so you don’t spot fraud. Check recent sign-in activity if your provider shows it. If anything looks off, secure the account and treat it as a live incident.

4. Stay alert to follow-on scams. Leaked details are often used to make phishing emails more convincing — a criminal who knows a service you genuinely used can impersonate it well. Treat any “there’s been a breach, click here to reset” email with suspicion, and go to the website directly rather than through a link.

Set up ongoing monitoring

Checking once tells you about today. The bigger win is being told automatically the next time something leaks, so you can act within hours rather than discovering it months later.

  • Register for free breach notifications. Have I Been Pwned lets you sign up an email address to be alerted whenever it appears in a new breach it processes. Do this for your key business addresses.
  • Monitor your whole domain. The same service offers free domain-wide monitoring for a verified domain owner, showing which addresses across your business have been exposed and flagging new ones. That covers every staff mailbox in one place — your IT provider can verify the domain and set it up.
  • Use your password manager’s built-in monitoring. Many now watch for breached passwords and warn you to change them, which turns a scattered manual chore into a quiet background check.

A note on shared and generic mailboxes

Don’t overlook addresses like sales@, support@ or your old “catch-all”. These are often used to sign up to dozens of services, rarely have MFA, and may be accessible to several members of staff — a tempting target. Make sure they’re covered by your monitoring, protected with MFA where possible, and that only current staff can reach them.

The bigger picture

Appearing in a breach isn’t a personal failing — it’s the near-inevitable result of using the internet for a few years. What separates a secure business from a vulnerable one isn’t whether their details have ever leaked, but what they’ve done about it: unique passwords, MFA everywhere, and monitoring that gives early warning. Get those three in place and a leaked password becomes a minor annoyance rather than the first domino in a costly attack.

If you’d like someone to check every mailbox across your business, set up domain monitoring and make sure MFA is switched on properly, that’s exactly what we do. Get in touch for a straightforward conversation, or explore our cyber-security services.

Frequently asked questions

What does it mean if my email 'appears in a breach'?

It means a website or service where you used that email address was hacked, and the stolen data — which may include your password — was leaked or sold. It doesn't necessarily mean your email account itself was broken into, but it does mean the leaked details are in criminal hands and any password involved should be treated as compromised.

Is Have I Been Pwned safe and free to use?

Yes. Have I Been Pwned is a well-respected free service that lets you enter an email address to see whether it has appeared in known data breaches. You only enter the address, not your password. It's widely used and referenced across the security industry, and it also offers free notifications if your address turns up in a future breach.

My email showed up in a breach — have I been hacked?

Not necessarily, but treat it as a warning. It means credentials linked to your address were exposed somewhere. The immediate risk is that criminals try that leaked password on your other accounts. Change the password anywhere you reused it, turn on multi-factor authentication, and watch for anything unusual in your inbox and sent items.

How often should I check?

Rather than checking manually every few weeks, register your business email addresses for free breach notifications so you're alerted automatically when something new appears. A quick manual check every few months is a sensible top-up, especially for your most important accounts.

Can I check my whole company's domain, not just one address?

Yes. Have I Been Pwned offers a free domain-monitoring service that lets a verified domain owner see which addresses across their business have appeared in breaches, and get notified of new ones. It's a simple way to keep an eye on every staff mailbox at once — your IT provider can set this up for you.

Does a breach mean I've broken GDPR?

Appearing in someone else's breach isn't your compliance failure — it's theirs. But how you respond matters. If leaked credentials lead to a compromise of personal data you hold, that could become a reportable incident, so acting quickly to secure accounts is both good security and good data-protection practice.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.