Email in a breach
Your email address appeared in a leaked dataset from a site you had an account with. Change that site's password if you haven't already.
No sign-up walls, no "free trial" that bills you later. These are the same tools security professionals use, run by the organisations that built them.
Generated in your browser and never sent anywhere, not to us, not to any server. Refresh the page and it's gone.
These tools measure different kinds of exposure. Knowing which one you're looking at changes what you should actually do next.
Your email address appeared in a leaked dataset from a site you had an account with. Change that site's password if you haven't already.
A specific password has been seen in leaked data. Stop using it anywhere, immediately, especially if reused.
Software on a device silently copied saved passwords and session cookies. This needs a device clean-up, not just a password change.
You were tricked into typing credentials into a fake page. The credentials are compromised even though no "breach" technically occurred.
Your name, address or phone number is for sale from public records and marketing lists, legally, separate from any hack. Opt-out processes exist per broker.
A clean result isn't a clean bill of health. These tools only know about what's been publicly catalogued. Not being listed doesn't mean an account was never compromised, it means it isn't in that particular dataset yet. Combine a clean check with good habits: a password manager, unique passwords, and multi-factor authentication everywhere it's offered.
The personal cybersecurity health check walks through identity, email, banking, devices and social media in about five minutes, and tells you the single highest-leverage fix for your situation.