Skip to main content

Was Your Email Really Breached? How to Check Properly

Media Was Your Email Really Breached? How to Check Properly

 

You receive an alert saying:

“Your email was found in a data breach.”

Or Microsoft warns about an unfamiliar sign-in.

Perhaps a colleague says they received a strange message from your address.

These situations are all worth investigating.

But they do not all mean somebody has logged into your inbox.

The word breached is often used to describe several very different events:

your email address appeared in another company’s leaked database

a password associated with your address was exposed

somebody attempted to sign in

somebody successfully signed in

your address was spoofed

your mailbox was genuinely compromised


The correct response depends on which one actually happened.

First: What Does “My Email Was in a Breach” Usually Mean?

Suppose you registered with an online shop using:

name@example.com

The shop later suffers a data breach.

Its database may have contained:

email addresses

usernames

telephone numbers

postal addresses

passwords or password hashes

purchase history


A breach-checking service may then tell you that your email address appeared in the incident.

That means:

your address was present in the stolen data.

It does not automatically mean:

somebody accessed your actual email inbox.

Have I Been Pwned lets users check whether an email address appears in known breach datasets and identifies the types of information associated with those incidents.

The risk increases considerably if the exposed information included a password that you:

still use

reused elsewhere

also used for your email account


That can enable credential-stuffing attacks against other services.

Five Different Situations People Call an “Email Breach”

1. Your Address Appeared in Another Company’s Breach

This proves information associated with the address was exposed elsewhere.

It does not prove your mailbox was accessed.

Check what categories of data were involved.

An incident exposing only:

email address

is different from one exposing:

email + password + telephone number + recovery information.

If a reused password was involved, change it anywhere else you used it.

2. Somebody Tried to Sign In

Internet-facing accounts attract automated sign-in attempts.

A failed attempt means:

somebody tried

but:

the provider rejected the authentication.

That is not the same thing as successful compromise.

Still check:

whether any later attempt succeeded

whether your password is reused

whether MFA/2SV is enabled

whether recovery details are correct


3. Somebody Successfully Signed In

This is much stronger evidence.

For a personal Microsoft account, Microsoft's Recent activity page shows account activity from the previous 30 days, including when and where the account was used and the method used to access it.

For a Microsoft work or school account, users can view recent activity through the My Sign-ins area.

Look for:

unfamiliar devices

unexpected successful sign-ins

unfamiliar applications

password changes you didn't make

MFA changes you didn't make

recovery-information changes

sessions at times you were not using the account


Do not judge purely by location.

VPNs, mobile carriers and corporate internet gateways can make legitimate activity appear geographically unusual.

Look at the overall combination of:

time + device + application + authentication method + location.

4. Your Address Was Spoofed

Somebody can sometimes send email that appears to come from you without actually accessing your mailbox.

Think of it as putting somebody else's return address on an envelope.

Clues include:

messages absent from Sent Items

no unusual successful sign-ins

no mailbox rules or forwarding changes

headers showing the message originated elsewhere


So:

“Someone received spam from my address”

does not automatically mean:

“My mailbox was hacked.”

This is one reason SPF, DKIM and DMARC matter for business domains.

5. Your Mailbox Was Actually Compromised

Now the evidence becomes much stronger.

Possible indicators include:

messages you didn't send

missing messages

unexpected forwarding

unknown inbox rules

changed recovery information

unfamiliar MFA methods

unfamiliar connected applications

unexpected password resets

account lockouts

unexplained Sent or Deleted Items activity


At that point, treat it as an account-security incident rather than merely a breach notification.

Step 1: Verify the Warning Independently

Never trust a security-warning email simply because it contains Microsoft, Google or Apple branding.

A phishing message may claim:

your account was hacked

your password expires today

your mailbox is full

your account will be suspended

somebody signed in from another country


Instead:

1. Close the message.


2. Open the provider's official app or website yourself.


3. Navigate to the security section.


4. Check whether the same alert appears there.

 

Do not:

click the warning link

call a telephone number in the message

provide passwords

provide authentication codes


If the warning is genuine, the provider's own security dashboard should give you evidence.

Step 2: Check the Email Address Against a Breach Database

Use a reputable service such as Have I Been Pwned.

Review:

which organisation was breached

when it occurred

what classes of data were exposed

whether passwords were involved


HIBP makes an important distinction: a match tells you the address was found in breach data it has loaded. It does not tell you that somebody later used that data successfully.

Likewise:

“No pwnage found”

does not prove your account is safe.

It only means that address was not found in the breach datasets available to the service.

A private or undiscovered compromise would not necessarily appear there.

Step 3: Review Sign-In History

This is far more useful when deciding whether the mailbox itself was actually accessed.

Microsoft personal account

Check:

Security > Recent activity

Microsoft says this shows activity for the previous 30 days.

Microsoft 365 work account

Check recent activity in the work/school account portal, and ask IT to review Entra sign-in logs if deeper investigation is required.

Google account

Google recommends reviewing:

Security & sign-in > Recent security events

and marking unfamiliar activity as not yours.

The key question is:

Was there a successful session I cannot explain?

Step 4: Check Devices and Sessions

If compromise is possible, review devices signed into the account.

Google lets users review devices under Manage all devices and sign out individual sessions.

Microsoft provides a Sign out everywhere option for personal Microsoft accounts. Microsoft notes that completing sign-out across all sessions can take up to 24 hours.

For a business Microsoft 365 account, IT can revoke sessions through the relevant identity-management controls.

If you don't recognise a device or session:

remove it.

Step 5: Check MFA and Recovery Information

Attackers do not always stop at learning the password.

They may try to create persistence by adding:

their telephone number

their authenticator

another recovery email

another MFA method


Review all authentication and recovery information.

Remove anything you don't recognise.

Then make sure strong MFA or passkeys are enabled.

Step 6: Check Inbox Rules and Forwarding

This is especially important for Microsoft 365.

An attacker may create a rule that:

forwards messages

deletes warnings

hides replies

moves financial messages

monitors password-reset emails


Review:

inbox rules

automatic forwarding

mailbox delegates

shared mailbox access


If somebody had access to the account, changing the password alone may not remove these changes.

Step 7: Check Sent Items — But Don't Rely on Them Alone

Messages you didn't send are strong evidence.

But an attacker may delete them afterwards.

So inspect:

Sent Items

Deleted Items

archive folders

suspicious rules

provider audit information


Absence of strange Sent Items is reassuring.

It is not absolute proof that no one accessed the mailbox.

Step 8: Check Connected Apps

Modern accounts often grant access through OAuth or other connected-app permissions.

An attacker may authorise an application instead of repeatedly signing in interactively.

Review applications connected to:

Microsoft account

Microsoft 365

Google account


Remove anything you do not recognise or no longer need.

For business accounts, IT should review consent and audit activity where compromise is suspected.

Step 9: Secure the Account if You Find Evidence

If you confirm or strongly suspect unauthorised access:

1. Change the password.


2. Use a unique password.


3. Sign out other sessions.


4. Remove unknown devices.


5. Remove unknown MFA/recovery methods.


6. Review forwarding and inbox rules.


7. Remove suspicious connected applications.


8. Enable strong MFA.


9. Check other accounts where the same password was reused.

 

The NCSC's current hacked-account guidance specifically recommends changing passwords, logging out all devices/apps and enabling 2-step verification.

Change Passwords From a Trusted Device

If you suspect the computer itself has malware, do not immediately type the new password into that machine.

Use another trusted device.

Otherwise a keylogger, credential stealer or stolen browser session could undermine the password change.

Then investigate the original device separately.

Step 10: Check the Device

Account compromise may originate from:

phishing

password reuse

malicious browser extensions

malware

remote-access scams

infostealer malware


Run your organisation's normal endpoint security checks.

For Windows users, that may include:

Microsoft Defender

endpoint detection and response

browser-extension review

recently installed software

Microsoft Defender Offline where justified


A breach database cannot tell you whether the endpoint itself has been compromised.

Password Reuse Changes the Risk Completely

Suppose HIBP shows:

email + password exposed

five years ago.

If that password was unique and changed years ago, the current account risk may be relatively limited.

If you still use the same password across:

email

Microsoft 365

Amazon

social media

banking


the situation is much more serious.

One leaked credential can be tried across multiple services.

The NCSC recommends separate passwords, particularly for important accounts such as email.

What If You Get Constant Failed Sign-In Attempts?

Failed sign-in attempts can look alarming.

But the distinction matters:

failed authentication ≠ successful compromise.

If:

all suspicious attempts failed

your password is unique

MFA is enabled

no mailbox settings changed


then the account may still be secure.

You do not necessarily need to change your password every time an automated attacker guesses incorrectly.

But repeated failures are a good reason to review the account's overall security posture.

What If the Location Is Wrong?

Do not treat geography alone as proof.

For example, you may physically be in Leeds while the sign-in appears to originate in London because:

your ISP exits there

your company routes traffic through there

your VPN uses a London gateway


A better question is:

Do the device, browser/application, authentication method and time make sense?

Spoofing vs Compromise: The Quick Test

Someone says:

“I received a strange email from you.”

Check:

Message is in your Sent Items + unfamiliar successful sign-in

Strong compromise indicators.

Message isn't in Sent Items + sign-ins normal + headers show another system

Spoofing becomes more likely.

That distinction matters because the remediation is different.

Business Email Requires a Deeper Investigation

For Microsoft 365 business accounts, IT should go beyond the employee's own dashboard.

Investigate:

Entra sign-in logs

risky sign-ins

authentication-method changes

audit logs

inbox rules

mailbox forwarding

delegated permissions

OAuth consent

messages sent during the suspected period


A business mailbox may contain:

customer information

supplier invoices

payment details

password-reset links

internal discussions


So mailbox compromise can become:

fraud + data breach + identity compromise

rather than simply an email inconvenience.

Don't Assume a Password Change Ends the Incident

Changing the password is important.

But if the attacker already created:

forwarding

rules

delegated access

connected applications

additional MFA methods


the password change may not be enough.

That is why the correct sequence is:

secure identity → revoke access → remove persistence → investigate activity.

Don't Trust “You've Been Hacked” Websites Blindly

Some websites deliberately create alarming messages to sell:

antivirus products

VPN subscriptions

identity monitoring

recovery services


Use evidence from:

your provider

reputable breach databases

account sign-in history

mailbox audit information

trusted security tools


not a random popup.

A Simple Decision Tree

Use this:

Address appears in HIBP only
→ Check what data was exposed and whether any password was reused.

Suspicious sign-in attempt failed
→ Review account security; not proof of compromise.

Unknown successful sign-in
→ Secure the account immediately.

Strange message appears to come from you but account activity is normal
→ Investigate spoofing.

Unknown rules, forwarding, MFA or sent mail
→ Treat as genuine mailbox compromise.

Account and device both show suspicious activity
→ Treat as a broader security incident.

How Hamilton Group Can Help

Hamilton Group can help businesses determine whether an email address merely appeared in leaked data or whether the Microsoft 365 account itself was genuinely compromised.

We can assist with:

Microsoft 365 account compromise

Entra sign-in investigations

suspicious mailbox activity

mailbox forwarding and rules

MFA security

Microsoft Defender

endpoint investigations

phishing incidents

business email compromise

account recovery

cyber-security monitoring


The important question isn't simply:

“Has this email address ever appeared in a breach?”

It is:

“Is there evidence that somebody actually accessed or changed this account?”

Visit hgmssp.com or call 0330 043 0069 to discuss Microsoft 365 and email security.