# Password Found in a Data Breach? Check and Fix It

> Got a "password found in a data breach" alert in Malaysia? How to check your email and passwords safely, what to change first, and fake alerts to ignore.

- URL: https://www.awarexone.com/research/data-breach-leaked-password-check
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-29
- Topics: Account security, Data breach, Malaysia
- Related service: Account security: https://www.awarexone.com/services/account-security

## Short answer

It usually means a password you saved was published after another website was breached, not that Google, Apple or Meta was hacked. Change that password everywhere you used it, starting with your email account, and give every account its own password. Then turn on two-step verification, and ignore messages asking you to click or type your password to check.

## Summary

- A leaked password alert usually means a password you saved was published after some other website was breached, not that Google, Apple or Meta was hacked.
- Open Password Checkup or your phone's password settings yourself, never through a link in a message, to see which accounts use the exposed password.
- Change that password everywhere you used it, starting with your email account, and give every account its own password from now on.
- Then turn on two-step verification with an authenticator app, a prompt or a passkey, so a leaked password alone cannot open the account.
- Ignore emails and pop-ups that say your data leaked and ask you to click, log in or type your password to check it, and never share a login code.
- No tool can delete your details from a breach, and a clean result does not prove you were never exposed, so unique passwords matter more than any check.

Chrome, your iPhone or Facebook has just told you a password you use was found in a data breach. Or a breach checker listed your email against websites you barely remember joining.

The short answer: this is a warning, not a break-in. Somewhere, a website you signed up to lost its user data, and your email or password ended up in a published list. Change that password everywhere you used it, starting with your email account, then add a second sign-in step so the old password is useless on its own.

This guide explains each alert, how to check your own details safely, what to change first, and the fake "your data was leaked" messages to ignore.

Last checked: 29 September 2026.

## What Does "Your Password Was Found in a Data Breach" Mean?

It means a password saved in your browser or phone matches one that has been published online after a breach, usually of some other website or app. Google's [Password Checkup page](https://support.google.com/accounts/answer/9457609) says compromised password and username combinations are unsafe because they have been published online, and recommends changing them as soon as you can. The alert does not mean Google, Apple or Meta was hacked, and it does not prove anyone has logged in. The risk is reuse: if one password opens your email, Instagram and banking, one leak opens all three.

## Which Alert Did You Get?

Several tools raise breach alerts, and they check slightly different things. Match yours below. The wording on your screen can vary by app version, language and region, so go by the key words.

*Breach alerts and first steps, from the Google, Apple, Facebook and Have I Been Pwned pages cited below.*

| Where you saw it | What it means | What to do first |
| --- | --- | --- |
| Chrome, after you sign in to a site: "Your password was found in a public data breach" | The password you just typed for that site matches a published breach list | Change it on that site now, then run Checkup in Google Password Manager for other sites using it |
| Google Password Checkup lists passwords as compromised, reused or weak | Saved passwords were exposed, are used on more than one account, or are easy to guess | Change the compromised ones first, then the reused ones, starting with email |
| iPhone Security Recommendations marks a password as leaked | Apple's password monitoring found it in a known data leak | Tap the item and follow the steps to change it on that website |
| Facebook asks you to change your password when you log in | Facebook found your email and password in a list stolen from another website | Follow Facebook's steps to set a new password you use nowhere else |
| Have I Been Pwned shows your email in one or more breaches | Your address was in data leaked by those sites; the passwords are not shown | Change the password you used on each listed site, and anywhere you reused it |
| An email from a company saying it had a breach | The company is telling you your data was affected | Check the notice is real by visiting the company's website yourself, then change that password |

## Is the Alert Real or a Scam?

The alerts in the table appear inside the app or browser you already use, not as an email asking you to click. Google's Password Checkup page says to go directly to Password Checkup to confirm a notification is authentic.

- Real: a prompt inside Chrome, the Passwords screen on your iPhone, or a Facebook prompt after you log in normally.
- Suspicious: an email, SMS or WhatsApp message saying your data was leaked, with a link to "secure" or "verify" your account.
- Scam: any page that asks for your current password, a login code or your bank details so it can "check" or "protect" you.

Google's [phishing guidance](https://support.google.com/mail/answer/8253) is blunt: if you click a link and are asked for the password to your Google Account or another service, do not enter it; go directly to the website instead. It also notes that Gmail will never ask for your password by email. If you already typed a password into a page like that, our guide on [what to do after clicking a phishing link](https://www.awarexone.com/research/clicked-phishing-link-what-to-do) covers the next steps.

## How to Check Whether Your Own Details Were Exposed

You only need to check your own email addresses and your own saved passwords. You never need leaked files for this, and you should never download or buy a so-called breach database. It is other people's stolen data, and you gain nothing from it that the checks below do not already tell you.

Whether you searched "semak emel bocor" or "密码泄露 怎么查", the checks are the same. Start with the passwords you already save, because those checks never ask you to type a password.

1. Google Password Checkup: in Chrome on a computer, open the menu, choose "Passwords and autofill", then "Google Password Manager" and "Checkup". Outside Chrome, go to passwords.google.com and choose "Go to Password Checkup". Google's page says it shows passwords that are exposed, weak or used in multiple accounts.
2. iPhone or iPad: on iOS 17 or earlier, go to Settings, Passwords, Security Recommendations, and turn on "Detect Compromised Passwords". Apple's [password security page](https://support.apple.com/en-gb/guide/personal-safety/ipsec74bc4cf/web) says passwords are then marked as leaked, reused or weak. On iOS 18 and later, passwords live in the Passwords app.

Then check your email address. [Have I Been Pwned](https://haveibeenpwned.com/) is a free service that tells you which known breaches included an address you type in. Its [FAQ](https://haveibeenpwned.com/FAQs) says no passwords are loaded alongside the email addresses, and that it can only return results for one address at a time. Type the address into the site yourself rather than following a link someone sent you.

- Check each email you have used for sign-ups, including old Yahoo, Hotmail or work addresses.
- Sign up for its notifications to hear about future breaches. The FAQ says alerts come from noreply@haveibeenpwned.com and go only to the address being monitored.
- Some breaches are marked sensitive and only show after you prove you own the address.

> Note: **A clean result is not an all-clear.** Have I Been Pwned's FAQ says it holds only a small subset of all the records ever breached, and that many breaches are never made public. If your email does not appear, still change any password you have reused. It also says a breach record cannot be removed from an address once loaded, because it is a historic fact; changing the password is what protects you.

The same site runs a [Pwned Passwords](https://haveibeenpwned.com/Passwords) check, which it says hashes your password on your device and sends only a fragment. That design is unusual. As a rule, never type a real password into a website that offers to check it; use the checkups built into your browser or phone.

## What to Change First: A Priority Order

Change passwords in order of what each account can reset. Your email inbox comes first because every "Forgot password" link lands there. Whoever controls it can take the rest.

1. Your main email account (Gmail, Outlook, Yahoo). Set a new password you use nowhere else, then check its recovery phone, recovery email and forwarding rules for anything you did not add.
2. Any account that used the exact leaked password, whether or not it was the breached site.
3. Online banking, e-wallets and shopping accounts with saved cards, if they shared a password with anything else.
4. Social media: Instagram, Facebook, TikTok and X, plus any email address linked to them.
5. Work accounts. Tell your IT team if a work password was reused on a breached site.
6. Everything else, as you log in. A password manager can generate a unique password for each.

Chrome's [password help page](https://support.google.com/chrome/answer/95606) describes a "Change it for me" option on compatible websites. If it fails, choose "Change it on the site" and do it by hand.

If Facebook stopped you at login, go along with it. Its page on [why it asks you to change your password](https://www.facebook.com/help/290656277791437/) says it checks lists of passwords stolen from other websites and, on a match, guides you through a change at your next login.

## Add a Second Step So a Leaked Password Is Not Enough

A new password fixes today's leak. A second sign-in step protects you from the next one. Google's page on [2-Step Verification](https://support.google.com/accounts/answer/185839) describes it as an extra layer of security in case your password is stolen.

*Second-step options described on Google's 2-Step Verification help page at the time of writing.*

| Method | How it works | What Google says about it |
| --- | --- | --- |
| Passkey | You sign in with your fingerprint, face or screen lock on your own device | Stronger protection against phishing, and it cannot be written down or given away |
| Google prompt | You tap Yes or No on a notification on your signed-in phone | Recommended if you do not use a passkey; can help protect against SIM swap |
| Authenticator app | An app on your phone creates one-time codes | Works without internet or mobile service |
| SMS or voice code | A six-digit code is sent to your phone number | Better than nothing, but vulnerable to phone number-based hacks |

One detail people miss: Google's [passkey page](https://support.google.com/accounts/answer/13548313) says adding a passkey does not change or remove any existing sign-in or recovery methods. An old recovery phone or email someone else controls still works, so check those separately. Only create passkeys on devices you own, because anyone who can unlock that device can open your account.

SMS codes follow your SIM. If your phone suddenly shows "No service" and codes stop arriving, call your Malaysian carrier from another phone and ask whether the SIM was replaced. For Instagram, Facebook and TikTok, our walkthrough of [two-factor authentication on each platform](https://www.awarexone.com/research/two-factor-authentication-instagram-facebook-tiktok) shows where the options are.

## Signs the Leak Has Already Been Used

Most alerts arrive before anyone uses the password. These signs mean someone got there first:

- Login alerts or "new sign-in" emails from places or devices you do not recognise.
- Emails saying your recovery email, phone number or password was changed.
- Posts, messages or purchases you did not make.
- Password resets you did not request arriving in your inbox.

If you see any of these, you have moved from prevention to response. Our guide to [spotting someone else logged into your account](https://www.awarexone.com/research/someone-logged-into-my-account) explains how to sign out unknown sessions, and if the inbox itself is gone, see [recovering a hacked Gmail account](https://www.awarexone.com/research/gmail-hacked-recovery).

## Mistakes That Leave You Exposed After a Breach

- Changing the password only on the breached site, and leaving the same password on your email.
- Adding a number or symbol to the old password. Have I Been Pwned warns that attackers can predict common patterns even when a password is slightly modified.
- Dismissing the alert. Google lets you dismiss a compromised password warning, but the password is still published.
- Clicking "secure your account" in an email instead of opening the app yourself.
- Typing a password into a stranger's "leak checker" site, or downloading leaked files to see what was taken.

> Warning: **"Your data has been leaked" messages.** Scam messages in English, Bahasa Malaysia and Chinese claim your data was leaked and offer to secure, remove or check it for a payment. Nobody can delete your details from a breach that has already spread. No bank, platform, government agency or genuine security service needs your password, OTP, two-factor code or backup code, and Google says it will not call you to verify a code. Keep them to yourself, including from us.

## Malaysia: Breach Notices, Scams and Where to Report

The Personal Data Protection Commissioner's [guideline on data breach notification](https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DBN_ENG.pdf) says an organisation must tell affected people when a breach is likely to cause significant harm, no later than seven days after notifying the Commissioner, and explain the steps they can take. If you get such a notice, verify it on the company's own website, then act on it.

If a leaked password led to money leaving your account, call your bank and the National Scam Response Centre on 997 straight away. The government's [NSRC 997 page](https://www.malaysia.gov.my/en/categories/safety-and-community/cybersecurity/nsrc-997-hotline) asks victims to call within 24 hours of discovering a scam so authorities can try to block the transactions, to contact their bank, and to lodge a police report at the nearest police station.

A phishing site posing as a breach alert, or a hacked account, can be reported to CyberSecurity Malaysia's [Cyber999 centre](https://www.cybersecurity.my/portal-main/services/cyber999-overview), the national point of contact for computer security incidents.

## When a Security Review Makes Sense

Most people can handle a breach alert alone with the steps above. A second pair of eyes helps when the leaked password guarded a business account or Page, when a leak has already turned into a takeover, or when you are unsure which recovery details are still yours. SocialSafe by AwareXone, AwareXone's recovery and digital identity service, reviews your situation first and tells you plainly whether you need help at all. We cannot remove your data from a breach, and nobody can. You can read how our [account security service](https://www.awarexone.com/services/account-security) works, and our [Trust Center](https://www.awarexone.com/trust) sets out what we will never ask for, starting with your passwords and codes.

## Frequently Asked Questions

### Is Have I Been Pwned safe to use?

Its FAQ says searched addresses are not collected and no passwords are stored with email addresses. You only need to type an email address, and you should type the site address yourself rather than follow a link.

### Why is my email in a breach for a site I never joined?

Have I Been Pwned says this can happen when a company was bought or rebranded, or when someone else signed you up. Change any password you might have reused.

### Can I get my data removed from a data breach?

No. Once data has leaked it cannot be recalled, and Have I Been Pwned says a breach record stays against an address as a historic fact. Changing passwords and adding a second sign-in step is what protects you.

### Should I turn off Chrome's leaked password warnings?

Keep them on. The setting sits under Privacy and security in Chrome, and turning it off does not make the password any safer, it only stops you hearing about the next leak.

### Does a breach alert mean my Google or iCloud account was hacked?

Not by itself. The alert means a saved password appeared in a leak from some website. Check your account's recent security activity, and if you see sign-ins you do not recognise, secure the account at once.

## Official sources

- [Have I Been Pwned: Check if your email address is in a data breach (read 29 September 2026)](https://haveibeenpwned.com/)
- [Have I Been Pwned: Frequently Asked Questions (read 29 September 2026)](https://haveibeenpwned.com/FAQs)
- [Have I Been Pwned: Pwned Passwords (read 29 September 2026)](https://haveibeenpwned.com/Passwords)
- [Google Account Help: Change compromised passwords in your Google Account (read 29 September 2026)](https://support.google.com/accounts/answer/9457609)
- [Google Chrome Help: Manage passwords in Chrome (read 29 September 2026)](https://support.google.com/chrome/answer/95606)
- [Google Account Help: Turn on 2-Step Verification (read 29 September 2026)](https://support.google.com/accounts/answer/185839)
- [Google Account Help: Sign in with a passkey instead of a password (read 29 September 2026)](https://support.google.com/accounts/answer/13548313)
- [Gmail Help: Avoid and report phishing emails (read 29 September 2026)](https://support.google.com/mail/answer/8253)
- [Apple Support: Secure your device, app and website passwords (read 29 September 2026)](https://support.apple.com/en-gb/guide/personal-safety/ipsec74bc4cf/web)
- [Facebook Help Center: Why Facebook asks you to change your password (read 29 September 2026)](https://www.facebook.com/help/290656277791437/)
- [Personal Data Protection Commissioner: Guideline on Data Breach Notification (read 29 September 2026)](https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DBN_ENG.pdf)
- [MyGOV Malaysia: NSRC 997 Hotline (read 29 September 2026)](https://www.malaysia.gov.my/en/categories/safety-and-community/cybersecurity/nsrc-997-hotline)
- [CyberSecurity Malaysia: Cyber999 Cyber Incident Response Center (read 29 September 2026)](https://www.cybersecurity.my/portal-main/services/cyber999-overview)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
