Use a dedicated pw manager, 1 random unique pw per service. Bitwarden, keepass, protonpass etc. Activate totp 2fa whenever possible. Ente auth, 2fas, keepass etc. Use a dedicated email alias service, 1 unique address per service. Simplelogin, addy.io, duck.com, firefox relay etc. Basically to clean up your digital opsec. Answer from Stunning-Skill-2742 on reddit.com
🌐
Reddit
reddit.com › r/cybersecurity_help › my email has been pwned from the internet archive.
r/cybersecurity_help on Reddit: My email has been pwned from the internet archive.
October 10, 2024 -

My email has been pwned wtf do I do now?

If this is something either really stupid or really serious please don't give me shit for not knowing I have no idea about tech stuff. But apparently my email was pwned from the internet archive or sth? I only used the site like once😭. What do I do now? Already changed my email password. Anything else I should do? I'm pretty attached at the email but willing to delete if absolutely necessary

Screenshot-2024-10-10-17-38-00-406-com-android-chrome.jpg.

Not sure what that changes but im using my phone (redmi note 8)

🌐
Reddit
reddit.com › r/cybersecurity_help › my email has been pwned 17 times, should i make a new one at this point?
My email has been PWNED 17 times, should I make a new one at this point? : r/cybersecurity_help
August 6, 2024 - Being pwned (in this case) means that someone has hacked your account, and taken it over. I can't tell from your description if you knew that. Never, ever, unsubscribe from a spam email. That lets the spammers know that your email is live, and they'll send you even more!
🌐
Reddit
reddit.com › r/cybersecurity_help › my email con pwned two years ago. people are using my email to subscribe to things, now what?
r/cybersecurity_help on Reddit: My email con pwned two years ago. People are using my email to subscribe to things, now what?
November 29, 2021 -

Hi all,

I use a secondary email to subscribe to things I am not extremely interested in but I eventually use occasionally. It's basically a trash email. It got pwoned a couple of years ago.

I've had people use my email to create Walmart accounts (this one was weird, because I had access to PERSONAL information of these people and their credit card, lol). I simply changed their password and I solved it . Also, someone using it in Brazil where I get this person's private information too, credit card, address and even bank information. It's being used in Nigeria too. It's all over the place. I don't understand the reasoning behind this, If I were a bad person, I would be able to cause some serious damage.

I finally understood why was happening when someone subscribed to CrunchyRoll (I have been subscribed to hundreds of stuff once even a dating site, sometimes a simple email to the company clears up the situation and account gets deleted).
However, I got an interesting reply from CrunchyRoll:

"It seems like an unauthorized 3rd party has created an account using your email address. We have deleted the account in questions. However, we cannot guarantee that anyone attempts to create an account with your address again. Sorry about that.

The account was likely created by accident by someone who is checking stolen credentials against our login to find accounts that have premium subscriptions."

I have several questions:

1.- Was my email password compromised? I have already changed it multiple times since that leak.
If I had had a premium subscription with my email, would they have had access to it?

2.- Someway to make it stop? Am I screwed for the rest of my life?

3.- If I delete the gmail account, will this go away? Does this protect me somehow? Will this stop people using my email to subscribe to stuff? I doubt they have access to my inbox.

4.- What can I do to protect my personal information worldwide and avoid misuse? I already have LifeLock by Norton but I doubt it's doing anything

Thank you

Top answer
1 of 2
2
Okay, so I am definitely not a complete expert in the field but I can throw some general tips and tricks your way to help you in the matter. Have I been pwned is an amazing tool. It will look at your email and see what breaches it showed up in. https://haveibeenpwned.com/ this should let you know if the email password was compromised. Password managers are available to help you generate secure passwords. If all you did was change the password for a variation on a theme, it is pretty easy to re-compromise. I personally am a fan of bitwarden, but find one that fits your needs, maybe even paying for it. If you are worried about the password being compromised, two factor authentication is a wonderful thing to turn on. This helps ensure someone with *just* the password can't access your email account It depends on the service. Some will send emails to the account, others will just check for the @ sign and a domain they recognize. It doesn't necessarily have to exist for them to accept it. This could be the cause of the issue to begin with, if its an email with a random string of characters it could be people just punching it in assuming it doesn't exist. This happens a few times and it might be malicious. Otherwise could be used to obfuscate transactions done via stolen credit card if your information did appear in a breach. Strong passwords are big (I know everyones heard it, but its true. If I want to hack someone, I go for the guy with a stickynote on his computer to remember his password.) If you don't already, use an AV. I personally don't like norton, but thats *my* opinion. All windows machines come with Windows Defender, it is free and fairly effective. If you want to pay for one, malwarebytes and Bitdefender tend to be recommended in the community. There are entire channels dedicated to testing AV effectiveness, but don't stress out too much about it. Find a password manager. They can generate random and secure passwords, as well as securely store them. They require a master password to access all the other ones (so make sure its strong!). Finally, turn on two factor authentication as much as possible. Its yet another security thing making your life more annoying, but it means that if someone has your email password, they can't just go willy nilly and reset all your passwords for everything else you have. There's probably more, but thats kind of the baseline I recommend. Please ask me questions, I will try to respond
2 of 2
2
Hey one I can half way answer. Not sure. Your email is definitely in a database somewhere, probably along with the password used to login to a site that was breached. If you use a unique email password then chances are that one is still okay. They are using the email/password combination from whatever site got breached. If you use a common password for your email then you should change it anyway! There is no way to make them stop. Just mark the messages as spam and move on. If it's bad enough then you could abandon the email. DO NOT attempt to unsubscribe from them all. Opening suspect emails is a quick way to lose a lot more than your email. You can't stop them from entering your email in a site. As long as they don't have access to your email account though there's not really much they can do with the actual email and many sites require verification links to be emailed and clicked on. There's probably some good articles out there that can handle this better than me. Your email should be using a unique password. This allows it to be insulated from breaches in websites you visit. They can type your email into sites but they can't get any thing the site sends back unless they have your password and thus access to your account. It's probably exactly what Crunchyroll says, they're trying to see if you're signed up for anything good. At which point they could try to use that sites customer service to change the associated email; send you a phishing email to compromise you further; or engage in some other type of theft. For example I had a situation awhile ago where Fitbit sent me an email thanking me for updating my account details. I got in touch with them and it turns out someone talked their way into my account and tried to get a warranty replacement sent to them. Also, it's never too early to change your email password.
🌐
Reddit
reddit.com › r/techsupport › my email appeared on haveibeenpwned.com.
r/techsupport on Reddit: My email appeared on haveibeenpwned.com.
August 13, 2023 -

Hey guys. So today I found out about this site and wanted to see if I have any data breaches. And it turned out that my account was one of the 140 million pwned accounts on Canva on May 2019 which was a huge data breach if you remember it. So it's been 4 years and today I changed my Canva password and enabled 2 factor authentication. Is there anything else I can do in this situation? And why when I run my email through the site, it still shows that I got pwned? And it's the same thing, the canva breach. How do I remove it completely from that tab? Or is it supposed to? And also I wanted to point out that I don't actually really use the app, I used it like two times when I needed it. So maybe the best thing for me to do will be deleting the Canva account itself? Will it disappear then?

🌐
Reddit
reddit.com › r/technews › have i been pwned adds 183 million more emails from major new breach
r/technews on Reddit: Have I Been Pwned adds 183 million more emails from major new breach
October 25, 2025 - YSK: HaveIBeenPwned will tell you if your email address and passwords have ever been compromised, so change them right now if they have!
Find elsewhere
🌐
Reddit
reddit.com › r/youshouldknow › ysk there is a website called haveibeenpwned.com that tells you if your email address has been involved in data breaches.
r/YouShouldKnow on Reddit: YSK There is a website called haveibeenpwned.com that tells you if your email address has been involved in data breaches.
January 6, 2019 -

https://haveibeenpwned.com/ allows you to check if your email address has been involved in a data breach. It can tell you if your password has been exposed as well as many other personal details such as your name, IP address, age, gender and even financial details. Scammers can then use this information to their advantage.

This website was a huge eye-opener for me and it saved me from trouble following a recent data breach. Make sure your information is safe!

🌐
Reddit
reddit.com › r/youshouldknow › ysk you can check if your email or phone number are compromised for free at haveibeenpwned.com, and it will tell you exactly how the leak occurred
r/YouShouldKnow on Reddit: YSK You can check if your email or phone number are compromised for free at haveibeenpwned.com, and it will tell you exactly how the leak occurred
July 25, 2024 -

Why YSK: Hundreds of millions of online accounts have their details leaked every year, including username and (usually hashed) passwords. These lists are sold for millions of dollars on the darknet, and hackers use these credentials to access your accounts on various platforms. If you share passwords between accounts, they may be able to access accounts which are unrelated to the leak. Beyond credentials, credit card and social security numbers may be leaked. Your credit history, and your identity as whole, are paramount and you should be aware of its possible use by bad actors.

🌐
Reddit
reddit.com › r/cybersecurity_help › i found my email in have i been pwned
r/cybersecurity_help on Reddit: I found my email in have i been pwned
November 30, 2024 -

Basically this morning I was subscribed to a youtube channel I wasn’t subscribed to and it was like a bot channel. I do some digging and my email was in one data breach but no pastes in have i been pwned and my google account doesn’t look like there’s suspicious activity, but i checked that dark web alert thing and it says one thing was found on the dark web (maybe my email?) didn’t exactly tell me what, but i’m terrified and not really sure what to do, so far i just changed my password on my email.

🌐
Reddit
reddit.com › r/cybersecurity_help › just found out my old email was pwned 5 years ago, do i have to be concerned?
r/cybersecurity_help on Reddit: Just found out my old email was pwned 5 years ago, do i have to be concerned?
March 30, 2025 -

So i used to have an email (lets call it email1) and i used it for pretty much everything, but at some point, like a year ago i made a new email and new password and switched emails of most my accounts to the new one. I still used email 1 on some of my snapchat, reddit and twitter, but everything else has my newer email. Today i tried to make an account for something, and since its nothing important, i tried to use email1, but it said it has suspicious activity. I opened that email, only devices connected to it were mine, no suspicious alerts or behaviours, no transactions, payments or subscripitons. I put it in the have i been pwned website and it says it was involved in 1 breach in like 2020 on wattpad. My other 2 emails didnt have any breaches and i have never experienced anything weird in since 2020. All of my accounts already use the new email and password except for snapchat. I have deleted that email now and all accounts connected to it. Shall i still be concerned? I mean its been 5 years without anything happening, i deleted that email, ive been using new email and password on everything for the last like year, but im just asking to be 100% sure. Sorry for the long post

Top answer
1 of 3
2
HIBP should come with a disclaimer about what it actually means. Seeing your email address and password doesn't mean your email account was compromised. It means that specific email address and password combo were leaked in some service compromise (LinkedIn.com for example). If you used the same password in multiple places, then you could have a problem. So when you said you changed your password, it sounded like you meant the one password for all of your accounts. If that is the case, you will need to create unique and randomly generated passwords for every site with 2FA enabled. This way when the next leak happens, your impact is limited to just that one site.
2 of 3
1
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers ( example? ). Here's how to stay safe: Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit ( how to report chats? how to report messages? how to report comments? ). Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.' Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security. Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki . I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
🌐
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Oh no — pwned! This email address has been found in multiple data breaches.
🌐
Reddit
reddit.com › r/techsupport › i saw my email address has been breached on haveibeenpwned.com. what does this mean?
r/techsupport on Reddit: I saw my email address has been breached on haveibeenpwned.com. What does this mean?
June 22, 2017 -

I can't for the life of me figure out if just my email address was leaked, or the password as well? And I hear people say that its not a big deal. How can that be? They can see all my emails.

Top answer
1 of 19
141

Sites listed on HIBP have been hacked, and their user list stolen. Usually these lists have your email address and a representation of a password called a hash. In some cases, where the person who programmed the website is a complete idiot not following best practices, it may be a weak hash or it may be in clear text. In those cases the hackers (and anyone with the database) has access to your password for that website.

This affects you in two ways:

1: On that website. If they can log in as you and get access to things like your full name, address, parts of your credit card number they can use that to compromise your identity further to steal from you or use you to steal from others. This is why it's important that hacks are disclosed publicly quickly.

2. On any other website you use that password on. They're going to try your email + password combo everywhere. If you used the same password on your account for Bob's Pizza and for your bank account, that may mean someone now has access to your online banking.

The big takeaway from this - the #1, I'm going to put in big letters rule is:

NEVER EVER EVER RE-USE PASSWORDS

ESPECIALLY bank and email accounts! Use a password management tool, use a notepad, use mnemonic tricks but never use the same password in two places.

Regarding your email address / email account, being on HIBP doesn't mean anyone has or ever had access to your email - unless one of the sites listed there had the same password as your email account.

2 of 19
19

I can't for the life of me figure out if just my email address was leaked, or the password as well?

It tells you in the info for the breach what was leaked, at least on most of them.

They can see all my emails.

Only if they somehow got into your email account.

If you mean email address then that's nothing to worry about, email addresses are not private.


Either way the basic guidelines for passwords are:

  • NEVER re-use the same password, every site/service needs a unique strong random password.

  • Use 2FA on important things like your email.

  • Use a password manager, there's no way to remember all your passwords otherwise.

  • Use 2FA on your password manager, use a very strong master password, and make backups of your passwords periodically and store them in an encrypted format.

On sites that let me I aim for a 30 character password randomly generated by my password manager.

Ironically the only sites that don't allow passwords that long are pretty much all of my banking/financial services.

🌐
Reddit
reddit.com › r/privacy › how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
🌐
Reddit
reddit.com › r/youshouldknow › ysk if you think your email account could be compromised you can check at haveibeenpwned.com
r/YouShouldKnow on Reddit: YSK If you think your email account could be compromised you can check at haveibeenpwned.com
April 17, 2017 -

We hear about data breaches so often, it can be a pain to figure out if you are vulnerable. You can use the site https://haveibeenpwned.com/ to find out if your email account may be compromised. You will have to submit your email address to check. Also the website can notify you if your email account may have been compromised.

Edit1: If you do find out you email account is compromised, see if you can still access the account, then change the password as soon as possible to something strong and use a password manager like Last Pass or Keepass to store you passwords.

Also if possible, disable security questions, they tend to be a weakness not a strength in many cases.

Edit2:Also it should be obvious but never tell anyone or any site your password, ever!