How your email address ends up in a data breach

« Blog · By

Sooner or later almost everyone receives a message with one of their old passwords in the subject line. That is not a sign of a hacked computer. It is almost always the delayed consequence of a breach at a provider you once registered with.

The routes out

  • A break-in at the provider. The classic case: a database gets copied. Everyone registered is affected, regardless of how good their own password was.
  • An unsecured database. No break-in needed — a store sits open on the internet and automated scanners find it.
  • A service provider in the chain. Not the shop itself but its newsletter provider, its shipping partner or an analytics service.
  • Malware on a device. Programs that read stored credentials out of the browser.
  • Scraping. Addresses that sat publicly on websites, in forums or in legal notices get collected automatically.
  • Legal address trading. Consent to "sharing with selected partners" in the small print is enough.

What happens next

The data gets merged. Five separate breaches become one profile: address, name, phone number, city, old passwords, interests. These combined collections are worth more than any single breach.

They are used for:

  • Credential stuffing. Known address and password combinations are tried automatically against hundreds of other services. Anyone reusing passwords loses accounts that were never breached themselves.
  • Targeted phishing. A message that knows your name, your city and your last order reads entirely differently from bulk spam.
  • Extortion attempts. The old password in the subject line is there to create credibility. There is generally nothing behind it.
  • Plain spam, often years later. Our own analysis shows exactly that: the address list that hit us was over ten years old.

Checking whether you are affected

There are reputable services that check an address against known breaches; the best known is Have I Been Pwned. Never enter a password there — only the address. And avoid sites offering paid "removal" from breaches. Once data has leaked, it cannot be recalled.

What to do

  1. Change the password of the affected service — and everywhere you used the same one. The second part matters more.
  2. A separate password for every service. Without a password manager that is unmanageable; with one it is easier than before.
  3. Turn on two-factor authentication, at minimum for your mailbox, your bank and your most important accounts. A leaked password alone is then not enough.
  4. Do not respond to extortion mail. Neither pay nor reply.
  5. Use a separate address per provider from now on. At the next breach you will know immediately who it was, and can shut down that one channel.

The mailbox comes first

One point often gets overlooked: your email address is the recovery route for nearly every other account. Anyone with access to your mailbox can have new passwords sent to themselves everywhere else. The mailbox is therefore the account that deserves the strongest protection — a unique password and a second factor that does not itself run over email.