Was Your Email Really Breached? How to Check Properly
You receive an alert saying:
“Your email was found in a data breach.”
Or Microsoft warns about an unfamiliar sign-in.
Perhaps a colleague says they received a strange message from your address.
These situations are all worth investigating.
But they do not all mean somebody has logged into your inbox.
The word breached is often used to describe several very different events:
your email address appeared in another company’s leaked database
a password associated with your address was exposed
somebody attempted to sign in
somebody successfully signed in
your address was spoofed
your mailbox was genuinely compromised
The correct response depends on which one actually happened.
First: What Does “My Email Was in a Breach” Usually Mean?
Suppose you registered with an online shop using:
name@example.com
The shop later suffers a data breach.
Its database may have contained:
email addresses
usernames
telephone numbers
postal addresses
passwords or password hashes
purchase history
A breach-checking service may then tell you that your email address appeared in the incident.
That means:
your address was present in the stolen data.
It does not automatically mean:
somebody accessed your actual email inbox.
Have I Been Pwned lets users check whether an email address appears in known breach datasets and identifies the types of information associated with those incidents.
The risk increases considerably if the exposed information included a password that you:
still use
reused elsewhere
also used for your email account
That can enable credential-stuffing attacks against other services.
Five Different Situations People Call an “Email Breach”
1. Your Address Appeared in Another Company’s Breach
This proves information associated with the address was exposed elsewhere.
It does not prove your mailbox was accessed.
Check what categories of data were involved.
An incident exposing only:
email address
is different from one exposing:
email + password + telephone number + recovery information.
If a reused password was involved, change it anywhere else you used it.
2. Somebody Tried to Sign In
Internet-facing accounts attract automated sign-in attempts.
A failed attempt means:
somebody tried
but:
the provider rejected the authentication.
That is not the same thing as successful compromise.
Still check:
whether any later attempt succeeded
whether your password is reused
whether MFA/2SV is enabled
whether recovery details are correct
3. Somebody Successfully Signed In
This is much stronger evidence.
For a personal Microsoft account, Microsoft's Recent activity page shows account activity from the previous 30 days, including when and where the account was used and the method used to access it.
For a Microsoft work or school account, users can view recent activity through the My Sign-ins area.
Look for:
unfamiliar devices
unexpected successful sign-ins
unfamiliar applications
password changes you didn't make
MFA changes you didn't make
recovery-information changes
sessions at times you were not using the account
Do not judge purely by location.
VPNs, mobile carriers and corporate internet gateways can make legitimate activity appear geographically unusual.
Look at the overall combination of:
time + device + application + authentication method + location.
4. Your Address Was Spoofed
Somebody can sometimes send email that appears to come from you without actually accessing your mailbox.
Think of it as putting somebody else's return address on an envelope.
Clues include:
messages absent from Sent Items
no unusual successful sign-ins
no mailbox rules or forwarding changes
headers showing the message originated elsewhere
So:
“Someone received spam from my address”
does not automatically mean:
“My mailbox was hacked.”
This is one reason SPF, DKIM and DMARC matter for business domains.
5. Your Mailbox Was Actually Compromised
Now the evidence becomes much stronger.
Possible indicators include:
messages you didn't send
missing messages
unexpected forwarding
unknown inbox rules
changed recovery information
unfamiliar MFA methods
unfamiliar connected applications
unexpected password resets
account lockouts
unexplained Sent or Deleted Items activity
At that point, treat it as an account-security incident rather than merely a breach notification.
Step 1: Verify the Warning Independently
Never trust a security-warning email simply because it contains Microsoft, Google or Apple branding.
A phishing message may claim:
your account was hacked
your password expires today
your mailbox is full
your account will be suspended
somebody signed in from another country
Instead:
1. Close the message.
2. Open the provider's official app or website yourself.
3. Navigate to the security section.
4. Check whether the same alert appears there.
Do not:
click the warning link
call a telephone number in the message
provide passwords
provide authentication codes
If the warning is genuine, the provider's own security dashboard should give you evidence.
Step 2: Check the Email Address Against a Breach Database
Use a reputable service such as Have I Been Pwned.
Review:
which organisation was breached
when it occurred
what classes of data were exposed
whether passwords were involved
HIBP makes an important distinction: a match tells you the address was found in breach data it has loaded. It does not tell you that somebody later used that data successfully.
Likewise:
“No pwnage found”
does not prove your account is safe.
It only means that address was not found in the breach datasets available to the service.
A private or undiscovered compromise would not necessarily appear there.
Step 3: Review Sign-In History
This is far more useful when deciding whether the mailbox itself was actually accessed.
Microsoft personal account
Check:
Security > Recent activity
Microsoft says this shows activity for the previous 30 days.
Microsoft 365 work account
Check recent activity in the work/school account portal, and ask IT to review Entra sign-in logs if deeper investigation is required.
Google account
Google recommends reviewing:
Security & sign-in > Recent security events
and marking unfamiliar activity as not yours.
The key question is:
Was there a successful session I cannot explain?
Step 4: Check Devices and Sessions
If compromise is possible, review devices signed into the account.
Google lets users review devices under Manage all devices and sign out individual sessions.
Microsoft provides a Sign out everywhere option for personal Microsoft accounts. Microsoft notes that completing sign-out across all sessions can take up to 24 hours.
For a business Microsoft 365 account, IT can revoke sessions through the relevant identity-management controls.
If you don't recognise a device or session:
remove it.
Step 5: Check MFA and Recovery Information
Attackers do not always stop at learning the password.
They may try to create persistence by adding:
their telephone number
their authenticator
another recovery email
another MFA method
Review all authentication and recovery information.
Remove anything you don't recognise.
Then make sure strong MFA or passkeys are enabled.
Step 6: Check Inbox Rules and Forwarding
This is especially important for Microsoft 365.
An attacker may create a rule that:
forwards messages
deletes warnings
hides replies
moves financial messages
monitors password-reset emails
Review:
inbox rules
automatic forwarding
mailbox delegates
shared mailbox access
If somebody had access to the account, changing the password alone may not remove these changes.
Step 7: Check Sent Items — But Don't Rely on Them Alone
Messages you didn't send are strong evidence.
But an attacker may delete them afterwards.
So inspect:
Sent Items
Deleted Items
archive folders
suspicious rules
provider audit information
Absence of strange Sent Items is reassuring.
It is not absolute proof that no one accessed the mailbox.
Step 8: Check Connected Apps
Modern accounts often grant access through OAuth or other connected-app permissions.
An attacker may authorise an application instead of repeatedly signing in interactively.
Review applications connected to:
Microsoft account
Microsoft 365
Google account
Remove anything you do not recognise or no longer need.
For business accounts, IT should review consent and audit activity where compromise is suspected.
Step 9: Secure the Account if You Find Evidence
If you confirm or strongly suspect unauthorised access:
1. Change the password.
2. Use a unique password.
3. Sign out other sessions.
4. Remove unknown devices.
5. Remove unknown MFA/recovery methods.
6. Review forwarding and inbox rules.
7. Remove suspicious connected applications.
8. Enable strong MFA.
9. Check other accounts where the same password was reused.
The NCSC's current hacked-account guidance specifically recommends changing passwords, logging out all devices/apps and enabling 2-step verification.
Change Passwords From a Trusted Device
If you suspect the computer itself has malware, do not immediately type the new password into that machine.
Use another trusted device.
Otherwise a keylogger, credential stealer or stolen browser session could undermine the password change.
Then investigate the original device separately.
Step 10: Check the Device
Account compromise may originate from:
phishing
password reuse
malicious browser extensions
malware
remote-access scams
infostealer malware
Run your organisation's normal endpoint security checks.
For Windows users, that may include:
Microsoft Defender
endpoint detection and response
browser-extension review
recently installed software
Microsoft Defender Offline where justified
A breach database cannot tell you whether the endpoint itself has been compromised.
Password Reuse Changes the Risk Completely
Suppose HIBP shows:
email + password exposed
five years ago.
If that password was unique and changed years ago, the current account risk may be relatively limited.
If you still use the same password across:
Microsoft 365
Amazon
social media
banking
the situation is much more serious.
One leaked credential can be tried across multiple services.
The NCSC recommends separate passwords, particularly for important accounts such as email.
What If You Get Constant Failed Sign-In Attempts?
Failed sign-in attempts can look alarming.
But the distinction matters:
failed authentication ≠ successful compromise.
If:
all suspicious attempts failed
your password is unique
MFA is enabled
no mailbox settings changed
then the account may still be secure.
You do not necessarily need to change your password every time an automated attacker guesses incorrectly.
But repeated failures are a good reason to review the account's overall security posture.
What If the Location Is Wrong?
Do not treat geography alone as proof.
For example, you may physically be in Leeds while the sign-in appears to originate in London because:
your ISP exits there
your company routes traffic through there
your VPN uses a London gateway
A better question is:
Do the device, browser/application, authentication method and time make sense?
Spoofing vs Compromise: The Quick Test
Someone says:
“I received a strange email from you.”
Check:
Message is in your Sent Items + unfamiliar successful sign-in
Strong compromise indicators.
Message isn't in Sent Items + sign-ins normal + headers show another system
Spoofing becomes more likely.
That distinction matters because the remediation is different.
Business Email Requires a Deeper Investigation
For Microsoft 365 business accounts, IT should go beyond the employee's own dashboard.
Investigate:
Entra sign-in logs
risky sign-ins
authentication-method changes
audit logs
inbox rules
mailbox forwarding
delegated permissions
OAuth consent
messages sent during the suspected period
A business mailbox may contain:
customer information
supplier invoices
payment details
password-reset links
internal discussions
So mailbox compromise can become:
fraud + data breach + identity compromise
rather than simply an email inconvenience.
Don't Assume a Password Change Ends the Incident
Changing the password is important.
But if the attacker already created:
forwarding
rules
delegated access
connected applications
additional MFA methods
the password change may not be enough.
That is why the correct sequence is:
secure identity → revoke access → remove persistence → investigate activity.
Don't Trust “You've Been Hacked” Websites Blindly
Some websites deliberately create alarming messages to sell:
antivirus products
VPN subscriptions
identity monitoring
recovery services
Use evidence from:
your provider
reputable breach databases
account sign-in history
mailbox audit information
trusted security tools
not a random popup.
A Simple Decision Tree
Use this:
Address appears in HIBP only
→ Check what data was exposed and whether any password was reused.
Suspicious sign-in attempt failed
→ Review account security; not proof of compromise.
Unknown successful sign-in
→ Secure the account immediately.
Strange message appears to come from you but account activity is normal
→ Investigate spoofing.
Unknown rules, forwarding, MFA or sent mail
→ Treat as genuine mailbox compromise.
Account and device both show suspicious activity
→ Treat as a broader security incident.
How Hamilton Group Can Help
Hamilton Group can help businesses determine whether an email address merely appeared in leaked data or whether the Microsoft 365 account itself was genuinely compromised.
We can assist with:
Microsoft 365 account compromise
Entra sign-in investigations
suspicious mailbox activity
mailbox forwarding and rules
MFA security
Microsoft Defender
endpoint investigations
phishing incidents
business email compromise
account recovery
cyber-security monitoring
The important question isn't simply:
“Has this email address ever appeared in a breach?”
It is:
“Is there evidence that somebody actually accessed or changed this account?”
Visit hgmssp.com or call 0330 043 0069 to discuss Microsoft 365 and email security.