The short answer: what counts as proof of a data breach?

For a consumer, the strongest evidence is a notice from the company involved that identifies your account or says your information was included in a specific incident. Verify that the notice is genuine before trusting it. A result in Have I Been Pwned can support the warning by showing that your email address appears in a breach record, but it doesn't prove every detail.

An unfamiliar login, charge, or account is evidence of possible misuse. It doesn't show which breach caused the activity, or even prove that a breach was the source.

If a warning seems credible, act before you finish investigating:

  1. Save the notice and verify it through the company's official website or app.
  2. Change the affected password and every reused or similar version.
  3. Turn on multifactor authentication and sign out of unfamiliar sessions.
  4. Review bank, card, and credit-report activity.
  5. Consider a credit freeze if your Social Security number or other identity information was exposed.
  6. Keep dated records of the warning and anything suspicious that follows.

You don't need a forensic report to start protecting your accounts.

What each type of evidence shows

Evidence What it reasonably supports What it does not prove
Official company notice The company reports that your account or information was involved That every listed data field was exposed or that anyone misused it
Have I Been Pwned result Your email address appears in a breach record known to the service That the listed company was the original source, or that your account is currently compromised
Pwned Passwords match The password appears in a known collection of exposed passwords That it belongs to the account you're investigating, or that it came from this incident
Unfamiliar login or security alert Someone may have tried to access or may have accessed the account Where the attempt came from or which breach enabled it
Unknown charge or new credit account Possible financial fraud or identity theft That the activity resulted from the breach in question
Unrecognized credit-report entry Possible identity theft Which breach exposed the information

Exposure and identity theft aren't the same thing. A breach can put information at risk without anyone using it. Conversely, suspicious activity may have another cause. The evidence helps you choose the right response; it may not answer the entire forensic question.

How to verify a breach without creating another problem

Check the notice through an independent channel

Unexpected breach emails can be phishing attempts. Don't click their links or call their phone numbers until you've checked the message another way. Type the company's address into your browser, use its official app, or call a number printed on a bill or payment card.

Look for details such as:

Treat a message as suspicious if it asks for your password, a payment, cryptocurrency, or your full Social Security number. A legitimate company may ask you to sign in, but you should reach the sign-in page yourself rather than using the message link.

Keep the original email, letter, or online notice. Record when you received it and which company or service it names. If the notice is online, save a copy or screenshot.

Use Have I Been Pwned as corroboration

Enter your email address on Have I Been Pwned and note the breach name, date shown, and categories of information listed. A positive result means the address appeared in a data set recorded by the service. It doesn't establish that the associated account is still active, that someone logged into it, or that the named company was the original source of the data.

A negative result isn't an all-clear. Have I Been Pwned can only report records it has received and processed. Some sensitive breaches are handled differently from public results. Its frequently asked questions explain the limits of the search.

Don't enter your current password into an unfamiliar breach-checking website. If you want to see whether a password appears in a known collection, use the official Pwned Passwords service. The service hashes the password locally and uses only the first five characters of the hash for the lookup. A match still doesn't identify the account or incident involved. Replace that password everywhere you use it.

Inspect the affected account directly

Sign in by entering the service's web address yourself. Check for changes you didn't make, including:

Save screenshots of relevant pages and note the date and time. Before sharing them, cover your email address, security codes, payment details, and other personal information.

If you can't sign in, use the company's official account-recovery process. Don't pay someone who contacts you unexpectedly and promises to recover the account.

Check financial accounts and credit reports

When payment information may have been exposed, review bank and card statements. Contact the financial institution through a number you obtained independently, report unauthorized activity promptly, and ask what replacement or account-protection steps apply.

If the breach involved your Social Security number or enough information to open accounts in your name, consider a U.S. credit freeze. The Federal Trade Commission's guidance on credit freezes and fraud alerts describes both options.

A credit freeze is free and restricts access to your credit file for new credit applications. You must place it separately with Equifax, Experian, and TransUnion. It stays in place until you ask the bureaus to remove it. According to USAGov's credit-freeze guidance, online and telephone requests must generally be processed within one business day; requests sent by mail can take up to three business days.

A fraud alert asks businesses to take additional steps to verify your identity before opening new credit. Neither a freeze nor a fraud alert secures an existing online account, so you still need to change passwords and review account access.

What to do once exposure is credible

Replace passwords and close off access

Change the password for the affected service through its official website. Then change every other account that used the same password or a similar variation. Start with email, banking, payment, shopping, and social media accounts. Access to one of those accounts can make it easier to reset or take over another.

A password manager can generate unique passwords so you don't have to reuse or memorize them. Don't reuse a replacement password across services.

Turn on multifactor authentication. An authenticator app or security key may be available in addition to a password. Review active sessions, sign out unfamiliar devices, and check recovery details and connected applications. Changing the password alone may not remove every existing access method.

Monitor for identity theft

Continue checking your credit reports for unfamiliar accounts, collection activity, or inquiries. If you find an entry you don't recognize, contact the creditor through an independently verified channel and keep copies of your dispute and any response.

Signs of identity theft can include an unfamiliar card charge, a debt-collection call about a bill that isn't yours, or an account opened in your name. If someone has used your information, report it through the FTC's IdentityTheft.gov recovery guidance. The report can help organize the recovery process and explain the problem to businesses.

Expect follow-up scams

A follow-up message may mention the company involved, your name, or part of the exposed information. Those details can make a fake support or password-reset message seem convincing.

Don't give one-time authentication codes, full passwords, or recovery codes to anyone who contacts you. Open the company's app or website directly and handle the issue there.

Clues that need context

A password-check result is a reason to replace the password, not proof that the account you're investigating was compromised. The password could have been exposed through another service or included in a separate data set.

A dark-web scan is not a definitive incident report. Results may be duplicated, outdated, incorrectly labeled, or fraudulent. Searching stolen-data forums or downloading files also creates avoidable risks, including scams and malware. You don't need to inspect stolen files before changing passwords or freezing your credit. If you see a credible listing that appears to contain your information, record the source without opening unnecessary files and report it to the affected company.

An unfamiliar login or security alert can reflect an attempted attack, a location mismatch, or a stolen session. Review the account activity and ask the provider to investigate instead of assuming the alert identifies the breach.

Finally, the absence of immediate fraud doesn't mean the information is harmless. Stolen data may be used later. Keep watching the affected accounts, credit reports, password-reset messages, collection notices, and new-credit inquiries.

Keep records that are useful later

Create a private folder or paper file with:

Keep original files unchanged when possible, and store copies somewhere an attacker can't access. Redact passwords, full account numbers, Social Security numbers, authentication codes, and similar details before sending documents to anyone.

For a personal account, a clear dated record is usually more useful than trying to create a technical forensic timeline. If you're considering a legal claim, ask a qualified attorney how to preserve evidence before deleting messages or handing over devices. U.S. breach-notification requirements can vary by state and by the type of information involved, so a public breach result alone doesn't show whether a company met its legal obligations.

Questions to send the company

Use the company's official privacy, security, or support channel. Ask:

The company may not know every detail while its investigation is still underway. Ask for written updates and keep them with your other records. If identity theft has occurred, use the FTC recovery process and contact each affected financial institution directly.

The practical rule

A verified company notice is the clearest consumer confirmation that your account or information was included in a reported breach. Have I Been Pwned can add useful corroboration, but neither a positive nor a negative result is a final ruling on what happened.

If you only have a few minutes, open the affected service directly, change that password and every reused version, and turn on multifactor authentication. If identity information was exposed, check whether a credit freeze is appropriate.