Was Your Email Really Breached? How to Check Properly
You receive a message saying:
Your email was found in a data breach.
Or perhaps Microsoft, Google or Apple warns you about an unfamiliar sign-in. A colleague says they received a strange email from your address, or a website claims that your account has been “pwned”.
It is reasonable to be concerned—but these situations do not all mean that somebody has accessed your inbox.
The word breached is often used to describe several very different events:
- Your email address appeared in data stolen from another company.
- A password associated with your address was leaked.
- Somebody unsuccessfully tried to sign in.
- A criminal successfully accessed your email account.
- A sender forged your address without accessing the mailbox.
- Malware stole a logged-in session from one of your devices.
The correct response depends on which of these actually happened.
The proper investigation combines four sources of evidence:
Breach records, account sign-in history, mailbox changes and device security.
What “Your Email Was in a Breach” Usually Means
Suppose you created an account with an online shop using:
carl@example.com
The shop later suffers a data breach that exposes:
- Email addresses
- Names
- Usernames
- Password hashes
- Telephone numbers
- Addresses
- Purchase information
A breach-checking service may then report that your email address was found in that incident.
That normally means the shop’s records were exposed. It does not automatically mean criminals logged into your actual email inbox.
Have I Been Pwned allows users to search whether an email address appears in breaches loaded into its database and shows the affected organisations and categories of exposed data. It can also notify verified users when their address appears in future breaches.
However, the risk becomes much more serious when:
- The exposed data included a password.
- You still use that password.
- You reused it for your email account.
- The breach included security questions or recovery information.
- The data has appeared in password-stealing malware records.
An attacker may try leaked email-and-password combinations against Microsoft, Google, banking, shopping and social-media services. This is why the NCSC recommends a separate password for email and warns against password reuse.
Five Different Situations That People Call an Email Breach
1. Your address appeared in another company’s breach
This is evidence that information associated with the address was exposed elsewhere.
It is not proof that the email account itself was opened.
Check what data the incident contained. An exposure containing only an email address presents a different risk from one containing a reusable password, telephone number, postal address and security answers.
2. Somebody attempted to sign in
Internet-facing email accounts are frequently targeted by automated sign-in attempts.
A failed attempt means somebody tried a password or authentication method, but the provider refused access.
It should still prompt you to check:
- Whether the attempt succeeded later
- Whether your password is reused
- Whether multi-factor authentication is active
- Whether recovery details are secure
But one failed attempt is not proof that the mailbox was compromised.
3. Somebody successfully signed in
A successful unfamiliar sign-in is far stronger evidence.
You may see:
- An unknown device
- An unfamiliar application
- A sign-in from an unexpected network
- A password or MFA change you did not make
- New account-recovery information
- A session created at a time you were not using the account
Microsoft’s Recent activity page shows Microsoft account activity from the previous 30 days, including information about how and where the account was accessed. Users can mark unfamiliar activity and begin securing the account.
Location alone is not always conclusive. Mobile networks, corporate gateways and VPNs can make a legitimate sign-in appear to come from somewhere unexpected. Microsoft recommends considering the application, device, location, IP address, user agent and the user’s normal activity together.
4. Your address was spoofed
A criminal can sometimes place your address in the visible From field without logging into your mailbox.
This is similar to writing somebody else’s return address on an envelope.
Recipients may therefore receive spam that appears to come from you even though:
- It is absent from your Sent Items.
- Your sign-in history is normal.
- No mailbox settings changed.
- The message did not pass through your email provider.
Internet message headers contain technical information about the systems through which a message travelled. Outlook and Gmail both provide options for viewing full headers, which can help distinguish a genuine message from one using a forged sender address.
5. Your mailbox was genuinely compromised
A compromised mailbox may show evidence including:
- Messages you did not send
- Missing or unexpectedly deleted messages
- Unknown inbox rules
- Automatic forwarding to another address
- Changed signatures
- Unfamiliar recovery information
- New applications connected to the account
- Unexplained password resets or lockouts
Microsoft identifies suspicious Sent and Deleted Items, forwarding rules, missing email, changed contact information and unexplained account lockouts as common signs of Microsoft 365 mailbox compromise.
Step One: Verify the Warning Independently
Do not select a sign-in or password-reset link merely because the email looks convincing.
A fake security warning may claim:
- Your mailbox was hacked.
- Your password will expire today.
- Messages are being held.
- Your storage is full.
- A sign-in occurred from another country.
- Your account will be closed.
Instead:
- Close the message.
- Open the provider’s application or website yourself.
- Navigate directly to its security settings.
- Check whether the same warning appears there.
Do not telephone a number contained in the warning or reply with passwords, authentication codes or recovery details.
A genuine provider should never need you to disclose a one-time verification code to someone who contacted you unexpectedly.
Step Two: Check the Address in a Reputable Breach Database
Have I Been Pwned can show whether an email address appears in breaches it has recorded.
Review each result carefully.
Look for:
- The organisation involved
- The breach date
- The date the breach became public
- The categories of exposed information
- Whether passwords were included
- Whether the incident involved malware or credential-stealing data
A result tells you that the address appeared in that data. It does not, by itself, prove that somebody used the information successfully.
Likewise:
No pwnage found
does not guarantee that the account is safe.
It means the address was not found in the breaches available to that service at the time of the search. A private, undiscovered or unreported incident would not necessarily appear there.
Some sensitive breach information is visible only after the user verifies control of the email address. Verified users can also access a dashboard and receive alerts about future exposure.
Be careful when checking passwords
Never enter your current password into an unknown “breach checker”.
Have I Been Pwned’s Pwned Passwords service uses a privacy model called k-anonymity: the password is hashed locally and only the first five characters of that hash are sent for comparison, rather than the complete password or complete hash.
Even so, when you know a password has been reused or exposed, the safest response is normally to replace it—not continue testing it on several websites.
Step Three: Review Official Sign-In Activity
Microsoft and Outlook.com
Open your Microsoft account security dashboard and review Recent activity.
Check:
- Successful sign-ins
- Unsuccessful attempts
- Devices
- Browsers and applications
- Approximate locations
- Security-information changes
- Password changes
Expand unfamiliar entries and use This wasn’t me or Secure your account where offered. Microsoft’s activity records cover the previous 30 days for consumer Microsoft accounts.
Google and Gmail
Open your Google Account and go to:
Security & sign-in
Review:
- Recent security events
- Your devices
- Recent sign-ins
- Third-party connections
- Recovery information
- Two-step verification
Google advises users who suspect compromise to review Recent security events and identify activity they do not recognise.
Apple and iCloud Mail
Review your Apple Account security information and connected devices.
Apple lists unfamiliar devices, unexpected verification codes, messages you did not send, deleted items you did not delete, unknown account changes and purchases you do not recognise as possible compromise indicators. It recommends changing the password and removing unfamiliar devices or security details.
Step Four: Inspect the Mailbox Itself
Do not stop after reviewing login history.
Attackers commonly change mailbox settings to preserve access, monitor conversations or hide security warnings.
Check Sent, Deleted and Draft folders
Look for:
- Messages you did not write
- Replies to conversations you do not recognise
- Fake invoices
- Requests for money or gift cards
- Password-reset messages
- Messages moved directly into Deleted Items
- Drafts containing unusual links or threats
Remember that an attacker may delete messages after sending them, so an empty Sent folder does not conclusively prove nothing happened.
Check inbox rules
In Outlook on the web or Outlook.com, review:
Settings > Mail > Rules
Look for rules that:
- Forward or redirect messages
- Delete incoming security alerts
- Mark messages as read
- Move messages into RSS, Notes, Archive or Junk
- Act on messages containing words such as invoice, payment, password or bank
Outlook rules can forward, redirect, delete, move or mark messages automatically. Microsoft specifically identifies rules forwarding to unknown addresses or hiding mail in unusual folders as compromise indicators.
Check automatic forwarding separately
In Outlook, forwarding may be configured independently of inbox rules.
Review:
Settings > Mail > Forwarding
Remove any address you do not recognise. Microsoft documents forwarding as a separate mailbox setting capable of sending incoming messages to another account.
For Gmail, review:
- Forwarding and POP/IMAP
- Filters and blocked addresses
- Mail delegation
- Connected accounts
Check automatic replies and signatures
An attacker may add:
- A fraudulent bank account
- A new telephone number
- A malicious link
- A message telling contacts not to telephone you
Review the account’s signature and automatic-reply settings.
Check contacts and delegates
Look for:
- Unknown mailbox delegates
- Changed contact details
- New recovery contacts
- Unfamiliar shared-mailbox permissions
- New calendar delegates
Step Five: Review Account Security Settings
A password change is important, but it is not the complete recovery process.
Check every way somebody could regain access.
Review:
- Recovery email addresses
- Recovery telephone numbers
- MFA devices
- Authenticator registrations
- Passkeys
- Backup codes
- App passwords
- Trusted devices
- Connected applications
- OAuth permissions
- Mail clients using IMAP or POP
- Third-party browser extensions
Remove anything you do not recognise.
Microsoft recommends reviewing connected accounts, forwarding and automatic replies after recovering a compromised personal account.
An attacker who added their own authenticator method or recovery address may be able to regain control even after you change the password.
Step Six: Determine Whether Messages Were Sent or Spoofed
When somebody says they received spam from you, ask them not to forward the message normally. Forwarding can remove or alter some useful diagnostic information.
Instead, ask for:
- The original message as an attachment
- The complete message headers
- The time it arrived
- The recipient address
- The subject
- Any links or attachments
In Outlook, the recipient can open View message details or the equivalent internet-header option. In Gmail, they can use Show original.
For Microsoft 365 businesses, an administrator can use Message trace to determine whether a message passed through Exchange Online and what happened to it.
The evidence may point towards spoofing when:
- The message did not pass through your provider.
- There is no corresponding sign-in or sending activity.
- The headers show a different originating system.
- Authentication checks identify a forged sender.
It may point towards real account access when:
- The message appears in provider logs.
- It was sent through an authenticated session.
- Suspicious sign-ins occurred at the same time.
- Inbox rules or account settings changed.
- Related messages appear in Sent or Deleted Items.
Do not rely on the visible From address alone.
Step Seven: Secure the Account
When compromise is confirmed—or cannot reasonably be ruled out—act from a trusted device.
Change the password
Use a completely new, unique password.
Do not merely add a number to the previous password or reuse one from another service.
Where the computer may contain malware, scan or clean the device before using it to create replacement credentials. Microsoft recommends scanning a potentially affected PC before changing a compromised Microsoft account password.
Sign out other sessions
Changing the password does not always end every existing browser or application session immediately.
For a personal Microsoft account, use Sign out everywhere under Advanced security options. Microsoft notes that completing the sign-out across devices can take up to 24 hours.
Other providers offer similar device or session-management controls.
Enable stronger authentication
Turn on multi-factor authentication, two-step verification or a passkey.
The NCSC describes 2SV as one of the most effective protections for important accounts because it can prevent access even where the password is known. It also identifies passkeys as phishing-resistant because they cannot be intercepted or reused like passwords.
Review existing MFA methods before registering new ones. Remove any method you did not add.
Remove persistence
Delete:
- Unknown forwarding
- Malicious inbox rules
- Unfamiliar delegates
- Unknown recovery methods
- Suspicious app passwords
- Unrecognised connected applications
- Unknown devices
Then sign out other sessions again.
Update and scan devices
Check every device that accesses the mailbox:
- Windows computers
- Macs
- Phones
- Tablets
- Browser profiles
- Email applications
Install security updates and run an appropriate malware scan.
A password change will not solve the problem if malware or a malicious browser extension continues stealing credentials or session data.
What If You Cannot Sign In?
Use the provider’s official account-recovery process.
Do not pay an unexpected “recovery expert” who contacts you through social media, messaging applications or a search advertisement.
Prepare information such as:
- Previous passwords
- Recovery telephone number
- Recovery email address
- Devices normally used
- Approximate account-creation date
- Recent legitimate correspondence
For an Apple Account, Apple directs users who cannot reset the password normally to its account-recovery service.
For a business account, contact the organisation’s Microsoft 365 or Google Workspace administrator immediately rather than repeatedly attempting self-service recovery.
Microsoft 365 Business Accounts Need a Deeper Investigation
A business mailbox can provide access to more than email.
Compromised Microsoft Entra credentials may also allow access to:
- OneDrive
- SharePoint
- Teams
- Business applications
- Customer information
- Internal documents
Microsoft’s compromised-account guidance recommends disabling the affected account during the investigation, resetting its password and addressing possible persistence mechanisms.
An administrator should investigate:
Entra sign-in logs
Review:
- Successful and failed sign-ins
- Application
- Device
- IP address
- User agent
- Authentication requirement
- Conditional Access outcome
- Risk detections
- Token activity
Microsoft advises checking sign-in logs and comparing the application, device, location, IP address and user agent with the employee’s normal activity.
Sessions and tokens
Block new sign-ins where necessary and revoke the user’s sign-in sessions.
Microsoft Entra allows administrators to disable an account and revoke refresh tokens, although some application-issued sessions may remain active until that application reevaluates access or its token expires.
Mailbox audit records
Search for:
- Messages accessed
- Attachments accessed
- New or modified inbox rules
- Folder-permission changes
- Mail moved or deleted
- Delegate changes
Microsoft 365 audit logs can record mailbox access and actions such as creating or modifying inbox rules and adding permissions.
Mail flow
Use Message trace to confirm whether suspicious messages were transmitted through the organisation’s Exchange Online service.
Wider cloud access
Review access to:
- SharePoint sites
- OneDrive files
- Teams
- Connected enterprise applications
- OAuth application consent
- Administrative roles
Contact the employee through a trusted method other than the potentially compromised mailbox or Teams account.
What Does Not Prove Your Mailbox Was Hacked?
None of the following, by itself, is definitive proof:
- Your address appearing in a breach database
- A failed sign-in alert
- Spam displaying your From address
- An unfamiliar location
- A password-reset email you did not request
- An unexpected MFA prompt
- A phishing message claiming the account is compromised
Each is a reason to investigate.
The strongest conclusions come from combining several pieces of evidence:
- Successful unfamiliar sign-in
- Unknown security-information change
- Malicious inbox rule
- Unauthorised forwarding
- Suspicious message in provider logs
- Unknown device or connected application
- Mailbox audit evidence
- Confirmed stolen password or session
Common Mistakes to Avoid
Changing the password but leaving malicious rules
The attacker may continue receiving forwarded mail or hiding security warnings.
Reusing a familiar password
A replacement password should be unique to the email account.
Trusting the location field alone
VPNs, mobile networks and corporate gateways can affect apparent location.
Ignoring failed sign-in attempts
A failed attempt is not a successful compromise, but repeated targeting may show that a password or address is circulating.
Checking only Have I Been Pwned
Breach databases provide useful exposure information but do not replace the email provider’s sign-in and audit records.
Assuming no Sent Items means spoofing
An attacker may delete sent messages. Check Deleted Items, audit logs and provider mail-flow records.
Approving an unexpected MFA prompt
Reject it and change the password. Somebody may already possess the first authentication factor.
Investigating a company mailbox alone
Report it to IT immediately. Delaying can allow business email compromise to spread to invoices, customers and colleagues.
A Practical Email-Breach Checklist
When you suspect your email has been compromised:
- Do not select links in the warning.
- Open the provider’s official security page independently.
- Check whether the address appears in known breaches.
- Review what data was exposed.
- Identify whether a password was included.
- Check recent successful sign-ins.
- Review connected devices and applications.
- Inspect recovery email addresses and phone numbers.
- Review MFA methods and passkeys.
- Check Sent, Deleted and Draft folders.
- Review inbox rules.
- Check automatic forwarding.
- Inspect signatures and automatic replies.
- Review delegates and connected accounts.
- Ask for full headers from suspicious messages.
- Use Message trace for Microsoft 365 business mail.
- Change the password from a trusted device.
- Sign out other sessions.
- Enable MFA or a passkey.
- Scan every device used to access the account.
- Warn contacts if fraudulent messages were sent.
- Contact your IT provider when a business account is involved.
How Hamilton Group Can Help
Seeing an email address in a breach is concerning, but it does not automatically tell you whether somebody entered the mailbox.
Hamilton Group’s experienced IT team can establish what actually happened.
Breach and Exposure Checks
We can identify:
- Which services were breached
- What data was exposed
- Whether passwords were involved
- Whether credentials were reused
- Whether the exposure creates a current risk
Sign-In Investigation
Hamilton Group can review:
- Microsoft Entra sign-ins
- IP addresses
- Devices and applications
- Authentication methods
- Risk detections
- Conditional Access results
- Session and token activity
Mailbox Investigation
We can inspect:
- Sent and deleted messages
- Inbox rules
- Automatic forwarding
- Mailbox delegates
- Signatures
- Message headers
- Exchange message traces
- Microsoft 365 audit records
Account Recovery and Containment
Where compromise is confirmed, we can:
- Block the affected account
- Reset credentials securely
- Revoke active sessions
- Remove unauthorised MFA methods
- Delete malicious rules and forwarding
- Review connected applications
- Scan affected computers
- Protect other users in the organisation
Business Email Compromise Protection
Hamilton Group can also help businesses implement:
- Multi-factor authentication
- Passkeys
- Microsoft Defender for Office 365
- Conditional Access
- Anti-phishing policies
- Secure email configuration
- Staff awareness training
- Alerting for suspicious rules and sign-ins
Hamilton Group aims to make first contact on IT support requests within 15 minutes, helping businesses contain suspicious email activity before it leads to fraudulent payments, lost information or wider account compromise.
Exposure Is Not the Same as Access
An address found in a breach database may mean that another organisation lost information connected to you.
A successful unfamiliar sign-in, malicious forwarding rule or unauthorised account change is evidence of something more serious.
Check the breach record—but also check the email provider’s sign-in activity, mailbox settings, devices, authentication methods and message logs.
That is how you determine whether your address was merely exposed or your mailbox was genuinely compromised.
Call 0330 043 0069, book a meeting with one of our experts or visit hgmssp.com for experienced help investigating breached credentials, compromised email accounts and Microsoft 365 security.