A leaking pipe dripping drops onto a keyboard, drawn in blue binary digits on a dark background, beside the headline Password in a Data Breach? What to Do.

Password Found in a Data Breach? Check and Fix It

Got a "password found in a data breach" alert in Malaysia? How to check your email and passwords safely, what to change first, and fake alerts to ignore.

11 min read
Short answer

It usually means a password you saved was published after another website was breached, not that Google, Apple or Meta was hacked. Change that password everywhere you used it, starting with your email account, and give every account its own password. Then turn on two-step verification, and ignore messages asking you to click or type your password to check.

Summary
  • A leaked password alert usually means a password you saved was published after some other website was breached, not that Google, Apple or Meta was hacked.
  • Open Password Checkup or your phone's password settings yourself, never through a link in a message, to see which accounts use the exposed password.
  • Change that password everywhere you used it, starting with your email account, and give every account its own password from now on.
  • Then turn on two-step verification with an authenticator app, a prompt or a passkey, so a leaked password alone cannot open the account.
  • Ignore emails and pop-ups that say your data leaked and ask you to click, log in or type your password to check it, and never share a login code.
  • No tool can delete your details from a breach, and a clean result does not prove you were never exposed, so unique passwords matter more than any check.
Table of contents11 sections
  1. 01What Does "Your Password Was Found in a Data Breach" Mean?
  2. 02Which Alert Did You Get?
  3. 03Is the Alert Real or a Scam?
  4. 04How to Check Whether Your Own Details Were Exposed
  5. 05What to Change First: A Priority Order
  6. 06Add a Second Step So a Leaked Password Is Not Enough
  7. 07Signs the Leak Has Already Been Used
  8. 08Mistakes That Leave You Exposed After a Breach
  9. 09Malaysia: Breach Notices, Scams and Where to Report
  10. 10When a Security Review Makes Sense
  11. 11Frequently Asked Questions

Chrome, your iPhone or Facebook has just told you a password you use was found in a data breach. Or a breach checker listed your email against websites you barely remember joining.

The short answer: this is a warning, not a break-in. Somewhere, a website you signed up to lost its user data, and your email or password ended up in a published list. Change that password everywhere you used it, starting with your email account, then add a second sign-in step so the old password is useless on its own.

This guide explains each alert, how to check your own details safely, what to change first, and the fake "your data was leaked" messages to ignore.

Last checked: 29 September 2026.

#What Does "Your Password Was Found in a Data Breach" Mean?

It means a password saved in your browser or phone matches one that has been published online after a breach, usually of some other website or app. Google's Password Checkup page says compromised password and username combinations are unsafe because they have been published online, and recommends changing them as soon as you can. The alert does not mean Google, Apple or Meta was hacked, and it does not prove anyone has logged in. The risk is reuse: if one password opens your email, Instagram and banking, one leak opens all three.

#Which Alert Did You Get?

Several tools raise breach alerts, and they check slightly different things. Match yours below. The wording on your screen can vary by app version, language and region, so go by the key words.

Breach alerts and first steps, from the Google, Apple, Facebook and Have I Been Pwned pages cited below.
Where you saw itWhat it meansWhat to do first
Chrome, after you sign in to a site: "Your password was found in a public data breach"The password you just typed for that site matches a published breach listChange it on that site now, then run Checkup in Google Password Manager for other sites using it
Google Password Checkup lists passwords as compromised, reused or weakSaved passwords were exposed, are used on more than one account, or are easy to guessChange the compromised ones first, then the reused ones, starting with email
iPhone Security Recommendations marks a password as leakedApple's password monitoring found it in a known data leakTap the item and follow the steps to change it on that website
Facebook asks you to change your password when you log inFacebook found your email and password in a list stolen from another websiteFollow Facebook's steps to set a new password you use nowhere else
Have I Been Pwned shows your email in one or more breachesYour address was in data leaked by those sites; the passwords are not shownChange the password you used on each listed site, and anywhere you reused it
An email from a company saying it had a breachThe company is telling you your data was affectedCheck the notice is real by visiting the company's website yourself, then change that password

#Is the Alert Real or a Scam?

The alerts in the table appear inside the app or browser you already use, not as an email asking you to click. Google's Password Checkup page says to go directly to Password Checkup to confirm a notification is authentic.

  • Real: a prompt inside Chrome, the Passwords screen on your iPhone, or a Facebook prompt after you log in normally.
  • Suspicious: an email, SMS or WhatsApp message saying your data was leaked, with a link to "secure" or "verify" your account.
  • Scam: any page that asks for your current password, a login code or your bank details so it can "check" or "protect" you.

Google's phishing guidance is blunt: if you click a link and are asked for the password to your Google Account or another service, do not enter it; go directly to the website instead. It also notes that Gmail will never ask for your password by email. If you already typed a password into a page like that, our guide on what to do after clicking a phishing link covers the next steps.

#How to Check Whether Your Own Details Were Exposed

You only need to check your own email addresses and your own saved passwords. You never need leaked files for this, and you should never download or buy a so-called breach database. It is other people's stolen data, and you gain nothing from it that the checks below do not already tell you.

Whether you searched "semak emel bocor" or "密码泄露 怎么查", the checks are the same. Start with the passwords you already save, because those checks never ask you to type a password.

  1. Google Password Checkup: in Chrome on a computer, open the menu, choose "Passwords and autofill", then "Google Password Manager" and "Checkup". Outside Chrome, go to passwords.google.com and choose "Go to Password Checkup". Google's page says it shows passwords that are exposed, weak or used in multiple accounts.
  2. iPhone or iPad: on iOS 17 or earlier, go to Settings, Passwords, Security Recommendations, and turn on "Detect Compromised Passwords". Apple's password security page says passwords are then marked as leaked, reused or weak. On iOS 18 and later, passwords live in the Passwords app.

Then check your email address. Have I Been Pwned is a free service that tells you which known breaches included an address you type in. Its FAQ says no passwords are loaded alongside the email addresses, and that it can only return results for one address at a time. Type the address into the site yourself rather than following a link someone sent you.

  • Check each email you have used for sign-ups, including old Yahoo, Hotmail or work addresses.
  • Sign up for its notifications to hear about future breaches. The FAQ says alerts come from [email protected] and go only to the address being monitored.
  • Some breaches are marked sensitive and only show after you prove you own the address.

The same site runs a Pwned Passwords check, which it says hashes your password on your device and sends only a fragment. That design is unusual. As a rule, never type a real password into a website that offers to check it; use the checkups built into your browser or phone.

#What to Change First: A Priority Order

Change passwords in order of what each account can reset. Your email inbox comes first because every "Forgot password" link lands there. Whoever controls it can take the rest.

  1. Your main email account (Gmail, Outlook, Yahoo). Set a new password you use nowhere else, then check its recovery phone, recovery email and forwarding rules for anything you did not add.
  2. Any account that used the exact leaked password, whether or not it was the breached site.
  3. Online banking, e-wallets and shopping accounts with saved cards, if they shared a password with anything else.
  4. Social media: Instagram, Facebook, TikTok and X, plus any email address linked to them.
  5. Work accounts. Tell your IT team if a work password was reused on a breached site.
  6. Everything else, as you log in. A password manager can generate a unique password for each.

Chrome's password help page describes a "Change it for me" option on compatible websites. If it fails, choose "Change it on the site" and do it by hand.

If Facebook stopped you at login, go along with it. Its page on why it asks you to change your password says it checks lists of passwords stolen from other websites and, on a match, guides you through a change at your next login.

#Add a Second Step So a Leaked Password Is Not Enough

A new password fixes today's leak. A second sign-in step protects you from the next one. Google's page on 2-Step Verification describes it as an extra layer of security in case your password is stolen.

Second-step options described on Google's 2-Step Verification help page at the time of writing.
MethodHow it worksWhat Google says about it
PasskeyYou sign in with your fingerprint, face or screen lock on your own deviceStronger protection against phishing, and it cannot be written down or given away
Google promptYou tap Yes or No on a notification on your signed-in phoneRecommended if you do not use a passkey; can help protect against SIM swap
Authenticator appAn app on your phone creates one-time codesWorks without internet or mobile service
SMS or voice codeA six-digit code is sent to your phone numberBetter than nothing, but vulnerable to phone number-based hacks

One detail people miss: Google's passkey page says adding a passkey does not change or remove any existing sign-in or recovery methods. An old recovery phone or email someone else controls still works, so check those separately. Only create passkeys on devices you own, because anyone who can unlock that device can open your account.

SMS codes follow your SIM. If your phone suddenly shows "No service" and codes stop arriving, call your Malaysian carrier from another phone and ask whether the SIM was replaced. For Instagram, Facebook and TikTok, our walkthrough of two-factor authentication on each platform shows where the options are.

#Signs the Leak Has Already Been Used

Most alerts arrive before anyone uses the password. These signs mean someone got there first:

  • Login alerts or "new sign-in" emails from places or devices you do not recognise.
  • Emails saying your recovery email, phone number or password was changed.
  • Posts, messages or purchases you did not make.
  • Password resets you did not request arriving in your inbox.

If you see any of these, you have moved from prevention to response. Our guide to spotting someone else logged into your account explains how to sign out unknown sessions, and if the inbox itself is gone, see recovering a hacked Gmail account.

#Mistakes That Leave You Exposed After a Breach

  • Changing the password only on the breached site, and leaving the same password on your email.
  • Adding a number or symbol to the old password. Have I Been Pwned warns that attackers can predict common patterns even when a password is slightly modified.
  • Dismissing the alert. Google lets you dismiss a compromised password warning, but the password is still published.
  • Clicking "secure your account" in an email instead of opening the app yourself.
  • Typing a password into a stranger's "leak checker" site, or downloading leaked files to see what was taken.

#Malaysia: Breach Notices, Scams and Where to Report

The Personal Data Protection Commissioner's guideline on data breach notification says an organisation must tell affected people when a breach is likely to cause significant harm, no later than seven days after notifying the Commissioner, and explain the steps they can take. If you get such a notice, verify it on the company's own website, then act on it.

If a leaked password led to money leaving your account, call your bank and the National Scam Response Centre on 997 straight away. The government's NSRC 997 page asks victims to call within 24 hours of discovering a scam so authorities can try to block the transactions, to contact their bank, and to lodge a police report at the nearest police station.

A phishing site posing as a breach alert, or a hacked account, can be reported to CyberSecurity Malaysia's Cyber999 centre, the national point of contact for computer security incidents.

#When a Security Review Makes Sense

Most people can handle a breach alert alone with the steps above. A second pair of eyes helps when the leaked password guarded a business account or Page, when a leak has already turned into a takeover, or when you are unsure which recovery details are still yours. SocialSafe by AwareXone, AwareXone's recovery and digital identity service, reviews your situation first and tells you plainly whether you need help at all. We cannot remove your data from a breach, and nobody can. You can read how our account security service works, and our Trust Center sets out what we will never ask for, starting with your passwords and codes.

#Frequently Asked Questions

Is Have I Been Pwned safe to use?
Its FAQ says searched addresses are not collected and no passwords are stored with email addresses. You only need to type an email address, and you should type the site address yourself rather than follow a link.
Why is my email in a breach for a site I never joined?
Have I Been Pwned says this can happen when a company was bought or rebranded, or when someone else signed you up. Change any password you might have reused.
Can I get my data removed from a data breach?
No. Once data has leaked it cannot be recalled, and Have I Been Pwned says a breach record stays against an address as a historic fact. Changing passwords and adding a second sign-in step is what protects you.
Should I turn off Chrome's leaked password warnings?
Keep them on. The setting sits under Privacy and security in Chrome, and turning it off does not make the password any safer, it only stops you hearing about the next leak.
Does a breach alert mean my Google or iCloud account was hacked?
Not by itself. The alert means a saved password appeared in a leak from some website. Check your account's recent security activity, and if you see sign-ins you do not recognise, secure the account at once.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.