Dana got the notice on a Tuesday. A chess site she had joined in 2019 had leaked its member list, and her email address was in a data breach for the first time. No password, the notice said, just the address and a username. So she read it twice, decided it sounded harmless, and went back to work.
Eleven days later she got a second email. This one knew the name of the site, quoted the breach, and asked her to “confirm her account” through a link. It looked more official than the real notice had. That is what an email address in a data breach is for. The address is not the loot. It is the delivery route for everything that comes after.
This guide is the page for the day after the notice. It walks the sequence in the order it actually happens, then names the one move that ends it. In short: the address will be tried, then targeted, then sold. So each of those has a defense, and the defences stack.
What an email address in a data breach is actually worth
An email address by itself opens nothing. But it is the username on most of your accounts, and it is the reset route for the rest. So the attacker’s job is to find the second half of the pair, and there are three ways to do that.
The first is to look it up. Because most people reuse passwords, an address from one breach can be matched against passwords from older ones. The second is to ask you for it, in a message built to look like the breached company. The third is to sell the address to someone who will do the first two at scale.
That is the timeline. Each stage feeds the next, and the whole thing runs on one fact: your address still works.
Stage one after an email address in a data breach: credential stuffing, within days
Credential stuffing is the automated part. Software takes the leaked list, pairs each address with every password that leaked alongside it before, and tries the pairs against banks, shops and email providers. For example, the OWASP description of the attack notes that it works because people reuse passwords across sites.
You will not see it happen. The tries hit other companies’ login pages, not your inbox, and a success looks like you signing in. Because a password from a leak years ago still sits in the lists, a breach that “only” exposed your address puts your older passwords back into play.
What to do: change the password on the breached site, then on every other site where you used the same one. Then turn on two-factor authentication anywhere it is offered. Do it today, because the automated tries start before the notice reaches you.
Stage two: phishing that quotes the breach, within weeks
This is the stage Dana hit. Once your address carries a company’s name, a phishing message can use that name, and a message that quotes a real event convinces far more people than a generic one. The FTC’s guidance on phishing lists the tells: urgency, a link to “verify”, a request for a password or a payment.
The breach posts on this blog record the pattern over and over. Chess.com leaked addresses and no passwords, which made the address the whole risk. CenterPoint Energy leaked billing details, so the fake bill became the obvious next message. McKesson put 6.4 million addresses out, each one now attachable to a healthcare story.
What to do: treat any message that mentions the breach as suspect, even a helpful one. Because the real company already told you, a second message asking you to act is the tell. So go to the site by typing the address, not by clicking. Report the message as phishing, then delete it.
Stage three: list resale, for years
The last stage is the quiet one. Brokers combine breach files, de-duplicate them and sell them, so your address ends up in lists you cannot trace back to any one company. That is why spam volume climbs months after a breach and stays up. In short, the address is now a commodity, and commodities get resold.
You can check which breaches hold your address at Have I Been Pwned, which indexes public breach files by email address. Most people who look find more than one. For example, an address used since 2010 is typically in five or more.
What to do: there is no recall. Nothing you do at the breached company gets the file back. So the defences at this stage are about the address itself, not the account. Give new sites an alias instead of your real address, which we covered in the spam guide, and watch your accounts through the FTC’s identity theft site if anything more than the address leaked.
The three moves after a data breach, in order
If you do nothing else this week, do these, in this order. First, change the reused passwords and turn on two-factor, because the automated tries are already running. Second, refuse every link that mentions the breach and go direct instead. Third, stop handing out the address that is now on the lists.
Those three moves cover the account, the message and the address. Together they take an evening. But notice what they have in common: each one is you, cleaning up, after a company you trusted let the file out. The next breach will ask you to do it again.
The one move that ends the data breach sequence
Every stage above needs the same two things: a password that exists for the attacker to guess, and an inbox that accepts mail from anyone who has the address. Change those two facts, and the sequence stops at stage one.
OptMsg changes both. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. Credential stuffing needs a password to try. Your OptMsg account doesn’t have one. It uses passkeys instead, so when another company gets breached, the login they leak isn’t the login to your inbox. Your email is how most accounts get reset. Keep that door shut and the rest stay shut with it.
The phishing stage stops for a different reason. OptMsg uses patent-pending opt-in technology, so only people you approve can reach your Inbox. Everyone else goes to Trash, where it sits for thirty days in case you want it, then deletes itself. A message quoting the breach from a sender you did not approve lands in Trash, not in front of you at 6 a.m. We wrote about the password half of this in Your Password Was in a Breach Last Month, and the Secure page has the design in plain language.
Dana’s second email would have gone to Trash. Her older passwords would have had nothing to open. If your email address in a data breach has you reading this on the day after the notice, the fastest way out of the sequence is an inbox the sequence cannot use: create your account and forward your existing mail to it.
Create Your Account
Your Inbox. Your Rules.
Frequently asked questions
My email address was in a data breach. What should I do first? Change the password on the breached site and on every site where you reused it, then turn on two-factor authentication. Credential stuffing tries leaked pairs within days, so this is the step with a clock on it.
Is it dangerous if only my email address was leaked? Yes, in a specific way. The address alone opens nothing, but it lets an attacker match it against older leaked passwords and send you phishing that quotes the breach by name. Treat any message mentioning the breach as suspect.
How can I find out which breaches contain my email? Have I Been Pwned indexes public breach files by email address. Enter your address and it lists the breaches it appears in, with the data types each one exposed.
Should I change my email address after a data breach? Usually not; too much depends on the address. Instead, stop giving the leaked address to new sites and use aliases, so the copy on the resale lists stops growing. If you move, move to an inbox that only approved senders reach.
How does OptMsg help after a breach? Your OptMsg account has no password, so a password stolen from another site can’t open your inbox, and credential stuffing has nothing to try. Only people you approve can reach your Inbox. Everyone else goes to Trash, so phishing that quotes the breach does not land in front of you.
Sources
- OWASP — Credential stuffing
- FTC — How To Recognize and Avoid Phishing Scams
- FTC — IdentityTheft.gov
- Have I Been Pwned
- OptMsg — Chess.com Data Breach
- OptMsg — CenterPoint Energy Data Breach
- OptMsg — McKesson Data Breach
Next in Privacy Guides: OptMsg Release Notes v1.1.3
