Start with the sites where your data actually lives
The fastest way to know if your accounts have been hacked is to check the sites that hold your data directly — not through a third-party tool. Go to each account you care about, look for a "Security" or "Login Activity" section, and see what devices and locations have accessed it recently. If you see a login from a place you've never been or a device you don't own, that's a real sign something is wrong.
Most major services show this information in plain language. Gmail displays your recent login locations under "Your Google Account" > "Security" > "Your devices." Facebook shows login locations under "Settings & Privacy" > "Settings" > "Security and login." Microsoft accounts list recent activity under "Security" > "Recent activity." Twitter (now X) shows login history under "Settings and privacy" > "Security and account access" > "Sessions." Start with whichever accounts matter most to you — email, banking, social media, work accounts.
The reason to check the actual site rather than a breach-checking tool is simple: a breach-checking tool can only tell you if your password appeared in a known data leak. It cannot tell you if someone is actively using your account right now. A hacked account and a breached password are different problems that need different fixes.
Key Takeaways
- Check login activity directly on each account's security settings to see if someone else has accessed it recently.
- Breach-checking tools like Have I Been Pwned tell you if your password appeared in a known leak, but not whether your account is currently being used by someone else.
- If you find unfamiliar logins, change your password immediately and turn on two-factor authentication if the site offers it.
- A breached password does not mean your account is hacked — it means that password should never be used again on any site.
Use a breach-checking tool to see if your password is in a known leak
Have I Been Pwned is the most reliable free tool for this. Go to haveibeenpwned.com, type in your email address, and it will tell you whether that email appeared in any publicly known data breaches. The site is run by security researcher Troy Hunt and does not store your email or sell your data — it only checks against a database of breaches that have already been made public.
If your email shows up in a breach, the site will tell you which company or service was breached and roughly when. This does not mean your account is currently hacked. It means that at some point, that company's database was stolen or leaked, and your password may be in the hands of someone else. You should change that password immediately, especially if you use the same password on other sites.
You can also check individual passwords on Have I Been Pwned without entering your email. Click "Passwords" at the top, paste in a password you use, and it will tell you how many times that password has appeared in known breaches. If it has appeared even once, stop using it everywhere.
Understand the difference between a breach and active hacking
A data breach means someone stole a database from a company. Your password may be in that stolen database, sitting on the dark web or in a criminal's files. But that does not mean anyone has used it yet. A breach is a past event that happened to the company, not necessarily to you.
Active hacking means someone is using your account right now — sending emails from your address, changing your settings, accessing your files, or using your payment methods. This is what you see when you check login activity and find a location or device you do not recognize. Active hacking is urgent. A breach is a reason to change your password, but it is not an emergency unless your account is also actively being used.
Many people panic when they see their email in a breach database, but the real question is whether anyone is using that account. Check your login activity first. If it looks normal, change your password and move on. If you see unfamiliar logins, follow the steps in the next section.
What to do if you find unfamiliar logins
If you see a login from a location you do not recognize or a device you do not own, act quickly. First, change your password to something long and random — at least 16 characters, mixing letters, numbers, and symbols. Do not reuse a password you have used anywhere else. Use a password manager like Bitwarden, 1Password, or KeePass to generate and store it.
Second, turn on two-factor authentication (also called 2FA or multi-factor authentication) if the site offers it. This means that even if someone has your new password, they cannot log in without a second form of proof — usually a code from an app on your phone, a text message, or a hardware key. Most major services offer this: Gmail, Facebook, Microsoft, Apple, Twitter, and Amazon all have it. Turn it on immediately after changing your password.
Third, sign out all other sessions. Most services have a button to "sign out everywhere" or "end all other sessions." Use it. This forces anyone who was using your account to log in again — and they will not be able to, because you just changed the password.
Fourth, check what the intruder did. Look at your email forwarding rules, recovery email address, and phone number. If any of these have been changed, change them back. Check your payment methods and connected apps. If you see anything you did not authorize, remove it.
Check your email recovery settings and backup methods
Your email account is the master key to every other account you own. If someone gains control of your email, they can reset the password on your bank account, your social media, your work accounts — everything. So if you suspect your email has been hacked, check these settings first.
In Gmail, go to "Security" > "How you sign in to Google" and look at your recovery email and phone number. Make sure both are correct and belong only to you. If someone added a recovery email or phone number you do not recognize, remove it immediately. Then check "Your devices" to see if there are any unfamiliar logins.
In Outlook, go to "Security" > "Advanced security options" and check your recovery email and phone. In Apple ID, go to "Account" > "Security" and review your trusted phone numbers and recovery email. If any of these have been changed without your permission, change them back and change your password.
Set up alerts so you know if something changes
Most email and social media services can send you a notification when someone logs in from a new location or device. Turn these on. In Gmail, go to "Security" > "Your devices" and make sure "Suspicious activity" notifications are on. In Facebook, go to "Settings & Privacy" > "Settings" > "Security and login" and turn on "Get alerts about unrecognized logins." In Microsoft, go to "Security" > "Recent activity" and enable notifications.
You can also sign up for notifications from Have I Been Pwned. On the site, enter your email address and click "Notify me." If your email appears in a new breach in the future, you will get an email alert. This gives you a heads-up to change your password before the breach becomes widely known.
Frequently Asked Questions
What should I do if I find my password in a breach database?
Change that password immediately on the site where you used it. If you use the same password on other sites, change it there too. You do not need to contact the company that was breached — they usually already know. Just make sure you never use that password again.
Does Have I Been Pwned store my email address?
No. The site checks your email against its database of known breaches but does not save your email or any information about your search. If you want extra privacy, you can check passwords instead of email addresses, or use the site's API through a privacy-focused browser extension.
If my account was hacked, will the hacker know I changed the password?
Yes — they will be logged out when you change the password, and they will not be able to log back in. That is the point. Once you change your password and turn on two-factor authentication, they cannot access your account even if they still have the old password.
Should I use a password manager to store my passwords?
Yes. A password manager like Bitwarden, 1Password, or KeePass lets you use a different, random password on every site without having to remember them. This means if one site is breached, the hackers only have that one password — not the password to your email, bank, or other accounts.
What is the difference between two-factor authentication and a security key?
Two-factor authentication usually means a code from an app on your phone or a text message. A security key is a small physical device you plug into your computer or phone. Security keys are more secure because they cannot be intercepted or guessed, but they cost money. Start with two-factor authentication through an app like Google Authenticator or Authy.