Data breaches and exposed credentials
A data breach is an incident in which data held by an organisation is exposed, often including email addresses and passwords. You cannot recall the exposed data, but you can make it less useful. Check which breaches include your email at Have I Been Pwned, change the affected password everywhere you reused it, turn on multifactor authentication, and consider a free credit freeze if identity details were exposed.
- Written by
- UltoPulto Editorial
- Published
- Last reviewed
General information, not legal advice. This page has not yet been reviewed by a lawyer; check the linked primary sources before relying on it.
Key takeaways
- Checking your email address at Have I Been Pwned is free.
- Change an exposed password on every account where you used it.
- Multifactor authentication protects an account even when its password is known.
- A credit freeze costs nothing and lasts until you lift it.
- No service can pull your data back out of a breach.
What is the problem?
Have I Been Pwned (HIBP), a free breach lookup service, defines a breach as an incident where data is inadvertently exposed in a vulnerable system, usually due to insufficient access controls or security weaknesses. The organisation that held your data is the one breached.
The lasting risk comes from reuse. HIBP notes that password reuse is extremely common and puts accounts at risk: a password exposed at one service can open your accounts at others.
How does it happen?
Data leaves a system that was not adequately protected, and copies are then passed on. HIBP gathers breaches so that people can see where their personal data has been exposed. It says it loads email addresses without the matching passwords, and that some breaches are flagged as sensitive and can be searched only by the verified owner of the email address.
What was exposed decides what to do next. A password calls for a password change. A Social Security number calls for checking your credit reports.
What laws may apply?
- EU. Under Article 34 of the GDPR, when a personal data breach is likely to result in a high risk to people's rights and freedoms, the organisation must tell the people affected without undue delay.
- California. State law requires businesses and state agencies to notify California residents whose unencrypted personal information was acquired, or is reasonably believed to have been acquired, by an unauthorised person. If a single breach leads to notices to more than 500 residents, a sample notice must also be submitted to the Attorney General.
- United States, credit. The Federal Trade Commission (FTC) confirms there is no cost to place or lift a credit freeze. An initial fraud alert lasts one year and can be renewed.
- Elsewhere. Notification duties and remedies depend on where you live and on who held the data.
What you can do yourself
These steps are free and do not need UltoPulto.
- Search your email address at haveibeenpwned.com and sign up for its notifications of new breaches.
- Change the password on the breached account, then on every account where you used the same one.
- Check whether a password has appeared in a breach with HIBP's Pwned Passwords. Only the first five characters of a hash of the password are sent.
- Turn on multifactor authentication for every account that offers it.
- If your Social Security number was exposed, order your free credit reports and look for accounts you do not recognise.
- Consider a credit freeze or a fraud alert. If the breached company offers free credit monitoring, the FTC suggests taking it.
- If someone is misusing your information, report it at IdentityTheft.gov.
What UltoPulto can do
- The Exposure Scan checks known breaches as one of its sources.
- An email check before results. Details stay hidden until you confirm a code sent to the email you entered, and the same name can only be scanned a few times a day. This makes it harder to look up someone else; it does not prove the name is yours.
- An Exposure Score from 0 to 100 with a published method.
- Scheduled re-scans that compare with the last scan and tell you about anything new.
What UltoPulto cannot do
- Remove your data from a breach. Once data has been copied out of a system, no one can recall every copy.
- Change your passwords, turn on multifactor authentication or freeze your credit. Those steps are yours to take.
- Tell you who holds or has used the exposed data.
- Act as credit monitoring or identity theft insurance.
Sources
- 1Frequently Asked QuestionsHave I Been Pwned
- 2Pwned PasswordsHave I Been Pwned
- 3What To Do After a Data BreachFederal Trade Commission
- 4Credit Freezes and Fraud AlertsFederal Trade Commission
- 5Turn On MFACybersecurity and Infrastructure Security Agency (CISA)
- 6Art. 34 GDPR: Communication of a personal data breach to the data subjectGDPR text, gdpr-info.eu
- 7Data Security Breach ReportingCalifornia Office of the Attorney General
Questions
How do I find out whether I was in a data breach?
Search your email address at Have I Been Pwned, which is free. Organisations may also have to notify you directly, depending on the law where you live.
Is it safe to enter my email or password into Have I Been Pwned?
HIBP says no password is stored next to personally identifiable data such as an email address. Its password check sends only the first five characters of a hash, and the comparison is completed on your side.
Can breached data be removed from the internet?
Generally no. Neither you nor any service can recall copies that have already been made. The practical response is to make the data less useful by changing passwords, adding multifactor authentication and checking your credit reports.
Does a credit freeze cost money?
No. The FTC says there is no cost to place or lift a credit freeze, and that a freeze lasts until you lift it.
Does a company have to tell me about a breach?
Often, but it depends on the law. The GDPR requires notice to individuals when a breach is likely to result in a high risk to them, and California requires notice to residents whose unencrypted personal information was acquired.