From the Journal · March 19, 2026
Was Your Data in a Breach? How to Check — and What to Do Next
Data breaches are now a fact of online life. Here is how to find out if your information leaked, and the exact steps to take if it did.

To find out if your data was exposed, check your email and passwords against a reputable breach database, then change any reused passwords and turn on two-factor authentication. Breaches are no longer rare events — billions of records are exposed every year, and the average person's email appears in several.
How to check
Free services let you search whether your email or phone number has appeared in a known breach. The security community's long-running Have I Been Pwned is the best-known reference. The problem with a raw list of breaches is that it tells you that something happened without telling you what to do — which is where most people freeze.
What to do if you're exposed
Prioritize by risk. Change the password on the breached account first, then anywhere you reused that password. Enable two-factor authentication — the Cybersecurity and Infrastructure Security Agency calls it one of the most effective defenses available. Watch for phishing that references the leaked details, and consider a password manager so every account has a unique login.
Stronger habits that end the cycle
Two upgrades make future breaches far less damaging. First, stop reusing passwords entirely — a password manager generates and stores a unique one for every site, so a single leak can't cascade across your accounts. Increasingly, sites also support passkeys, which replace passwords with a device-based login that can't be phished or leaked in the usual way. Second, if you're worried about identity theft, you can place a free credit freeze with the major bureaus; it blocks new accounts from being opened in your name and can be lifted in minutes when you need it. Neither step costs anything, and together they turn a breach from a crisis into a shrug.
Monitoring, in plain English
TrueID.Help tells you the moment your details turn up in a breach and, crucially, explains what to do about it in plain language rather than leaving you with a scary list. It is part of the nine apps now in public beta at Smith App Studio — testers get 50% off with BETA50 through September 24.
It also helps to think about what a breach actually exposes. An email address alone is low-risk; a password, especially a reused one, is high-risk; a Social Security or financial account number is the kind of thing that warrants a credit freeze and close monitoring. Not every breach demands the same response, and matching your reaction to the real risk keeps you from either panicking over a newsletter leak or shrugging off something serious. The goal isn't fear — it's a calm, proportionate checklist you run each time.
You cannot prevent companies from being breached. But you can make a leaked password worthless by never reusing one, and you can find out early enough to act. In 2026, that habit is basic digital hygiene — like locking your front door.
