After a breach, you can secure
- Make compromised passwords or sessions unusable.
- Enable additional protections on affected accounts.
- Keep evidence and report fraudulent use.
Loading page…
Email, password, phone number, IBAN or identity document: the right response depends on the data exposed. Identify the breach, secure affected accounts and watch for unusual activity.
Focus your response. First secure access that could be used immediately, then organise monitoring and further action.
Read the affected service's official notice and check the address used. Avoid links in alarming messages: open the website or app directly.
Choose a unique password. If you reused it elsewhere, change it on those accounts too, starting with your email and sensitive services.
Revoke devices or connections you do not recognise, then enable two-factor authentication using an app or security key where possible.
Monitor sign-ins, resets, messages and transactions. Be especially wary of calls or emails that use accurate information about you.
The size of a breach does not tell the whole story. One sensitive detail may need a faster response than a long list of already public information.
Phishing, text scams, targeted spam and fraudulent calls become more credible when an attacker already knows part of your identity.
Stay alert and strengthen your account filters.Reused credentials can unlock other accounts through credential stuffing. An old security answer can also help someone take over an account.
Immediately change affected or reused credentials.This information can support fraud, bank impersonation or an attempted direct debit. If complete card details are exposed, contact your bank promptly.
Contact your bank and monitor transactions.An identity document, administrative number or health information can enable identity theft or cause lasting, sensitive harm.
Keep evidence and follow the appropriate official process.One isolated detail is not always enough to act. Risk increases when it is reused, combined with other sources or turned into a convincing pretext.
Automated tools test email and password combinations on other services. This is why every account needs a unique password.
Real information stolen in a breach can make a fake email, text or call much more convincing. Stay alert.
Breached data can be combined with the public web, social networks or broker databases to fill out your profile.
An attacker may pose as a bank, phone provider or service you use to obtain a code, payment or more information.
A database that has already been copied or shared usually cannot be erased everywhere. You can still disable compromised access and act against organisations, sites or brokers that hold or publish your data.
Data Knight makes Have I Been Pwned results easier to read: see incidents linked to your contact details, the types of data affected and actions to prioritise.
The scan does not need your password to look for a match in known breaches.
The search covers incidents recorded and documented by this international reference database.
Your report identifies the affected service, the known breach date and the categories of exposed data to help you prioritise.
Content reviewed against official resources and the documentation of the source used by the scan.
First check official notifications from services you use and unusual activity on your accounts. You can also check your email address or phone number in a recognised database such as Have I Been Pwned. The Data Knight scan brings known matches and the categories of exposed data together in one report.
Change the password for the affected account immediately. If you reused it, change it on every other account using the same combination, starting with your email and financial services. Sign out unfamiliar sessions and enable two-factor authentication.
Not necessarily. Prioritise the affected service and every account using the same password or a close variation. A password manager can then help you create a strong, unique password for each account.
Not everywhere once a database has been copied or shared. You can still make compromised credentials unusable, secure your accounts and request deletion of data still held or published by an organisation, website or broker. A removal request cannot guarantee that every copy from a breach disappears.
No. It only means that no match was found in the known breaches checked at the time of the search. A breach may not yet have been discovered, may not be public or may be added to the database later.
For an IBAN or payment details, contact your bank and monitor unusual transactions. For an ID document, keep evidence, watch for signs of identity theft and follow the appropriate official reporting process if fraudulent use appears. Do not send another document to an unverified contact.
Have I Been Pwned is an internationally recognised database of documented breaches and the categories of data affected. It cannot know about every breach, so treat a result as a useful signal rather than an absolute guarantee of security.
No. The Data Knight breach scan does not need your password. It uses the contact details you provide, such as your email address or phone number, to look for matches in recorded incidents and display useful information in your report.