You usually cannot tell that a password has been stolen by looking at it. The useful evidence comes from account activity, security settings and known data exposures. Even then, a leaked address, an exposed password and an account being actively misused are different findings. Distinguishing them helps you act promptly without drawing conclusions the available evidence cannot support.
This guide explains what to inspect, how to use Have I Been Pwned and when to move from checking to account recovery. Do not enter a working password into an unfamiliar website that promises to identify the person who stole it.
What should you check first?
Open the affected service independently and examine security events, connected devices, recovery details and activity you did not perform. Look up known exposure through reputable official tools, but remember that a negative result is not proof of safety. If your current password was exposed or an unauthorised action is confirmed, change the secret and review the account's other access routes.
Recognise signs that deserve attention
Warnings include a successful login you cannot explain, a recovery address changed without your permission, an unfamiliar authentication method and messages or purchases you did not make. Being suddenly unable to sign in can also warrant investigation. It does not, on its own, prove hacking: a service outage, an incorrect username or a forgotten update can produce similar symptoms.
Compare the timing and the details with your own activity. A notification after setting up a new phone is different from an unknown device followed by changed recovery settings. An unsuccessful attempt means somebody tried to enter; it does not demonstrate that they had the right password or gained access.
Do not dismiss an event simply because you can still log in. An unauthorised user may not change the password immediately. Conversely, do not identify a particular person from an approximate location or IP address. Those details are clues, not reliable proof of personal identity.
Inspect the provider's settings independently
Use your normal application, a bookmark or a known address instead of the button in the warning email. Look for security history, active sessions, authorised applications and recovery methods. The exact menu names vary. Consult the provider's help if you cannot find them rather than relying on instructions from an unsolicited support message.
Make a short note of events that need explanation. Record the time, displayed device and action observed, not your password. This makes it easier to compare an alert with a trip, a VPN session or a device change. For a workplace account, ask the administrator to help interpret events if the available information is incomplete.
Check the account's actual activity too. A security history may be limited while a new forwarding rule, unknown purchase or changed profile remains visible. No single screen necessarily gives a complete picture of everything that happened.
Use Have I Been Pwned for known exposure
Have I Been Pwned lets you investigate whether an email address appears in the breaches its service has recorded. Visit the official domain. An email-address lookup does not require you to disclose that email account's password. Avoid imitation pages promising a more complete answer in exchange for credentials or payment to an unknown operator.
A positive result means the address appears in the relevant recorded data. It does not establish that your current password is known or that someone is currently inside the account. Review the listed incident and the categories of exposed information. An address, contact details and password-related data are not equivalent findings.
Distinguish the incident date from the date the record was added. Older data can become visible much later. If you replaced the password after the affected period, investigate remaining reuse of the old value rather than assuming its replacement is necessarily exposed.
Read the official FAQ when a result is unclear. The service documents limitations; it is not a live detector of every login or a way to identify an intruder.
Understand what a password-value lookup means
Pwned Passwords answers a different question: whether a password value appears in its corpus of exposed secrets. Finding a value there does not identify your account as its source. Another person may have used the same value. Nevertheless, it is not a good value to keep as your own account password.
The documented range-search mechanism uses a partial hash query rather than sending the complete password to that endpoint. This does not make every website offering a password check trustworthy. The implementation and the destination still matter. Consult the official API documentation if you need to understand the mechanism.
For an ordinary user, the practical result matters more than a technical score. Replace a known exposed value with an independent generated one, check where it was reused and save the confirmed replacement. Do not try minor variations of the exposed value until a checker gives a different answer.
Check whether the warning itself is genuine
A warning message can be legitimate, fraudulent or simply older than you first realised. Compare it with an event obtained from inside the official account. A familiar logo and display name are not enough. An attacker can use personal details from a leak to make a message seem convincing.
A browser padlock indicates an encrypted connection to the site you are visiting, not that the site is the real provider. Inspect the domain before entering credentials. If someone calls claiming to cancel the intrusion, do not tell them a login code or approve a request they generated. Contact the service yourself through a known support channel.
Unexpected approval requests should be refused. Receiving one does not require you to continue a conversation with the person who claims to be resolving it. Secure the account from your own verified route.
Interpret location and device details carefully
A login shown in another city may reflect an operator's infrastructure or a VPN. Compare the time, browser, device type and your real activity. Location alone is weaker evidence than a combination of an unfamiliar session and an unauthorised account change.
Device names can also be generic. Consider tablets, secondary browsers and legitimate applications before deciding that every unfamiliar label is hostile. If you cannot identify a session, use the provider's sign-out controls and reconnect your known devices. Check what those controls actually invalidate.
Some services expose little history. Lack of detail is not proof that nothing happened. If a suspicious action is visible elsewhere in the account, act on that evidence rather than waiting for a perfect security log.
Choose an action proportionate to the evidence
An old breach containing your email address calls for review of the affected data, current recovery settings and old password reuse. A current password known to be exposed should be replaced even without visible misuse. A confirmed unauthorised login or account modification calls for the account recovery procedure, including sessions and connected applications.
There is also a common intermediate case: you typed credentials into a doubtful page but see no suspicious history yet. Do not wait for a breach database to record the event. Open the legitimate service from a trusted device, replace the password and inspect recovery methods and sessions. A public breach lookup is not designed to confirm each phishing form submission.
If an extortion message quotes an old password, that fact alone does not prove current control of your computer. Previously exposed values can be used to make threats persuasive. Verify accounts independently, preserve useful evidence where appropriate and do not reply with more personal information.
Build a reasonable verification routine
Enable useful security notifications and protect the mailbox receiving them. Learn where your important accounts list sessions and how to reach support before an incident. You do not need to monitor every service constantly, but knowing the recovery path reduces confusion when a real warning arrives.
After an alert, record what you checked and what changed, without storing secrets in the incident notes. Revisit unexplained events and remaining reused passwords. No known-breach tool covers every theft by phishing or malware, so independent passwords, device protection and careful recovery settings remain necessary.
Investigate several affected accounts as one possible device problem
If unrelated accounts show suspicious activity even though their passwords were independently generated, widen the investigation. Check whether they were accessed from the same computer, browser or recently installed software. A common device can provide another relationship between accounts that do not share a secret.
This pattern is a reason to seek appropriate help, not a diagnosis by itself. Do not name a particular malicious program solely from two alerts. Use a trusted device for urgent account checks, examine the suspicious machine through the relevant support process and avoid immediately entering every replacement secret on it.
For a work device, tell the responsible team which accounts were affected and when the events occurred. They can compare the timeline with configuration changes and other information unavailable to you. Preserve useful messages without publishing account details in a public support forum.
A negative breach lookup does not resolve this scenario because it does not inspect your computer. Likewise, replacing one password does not demonstrate that the underlying cause has disappeared. Keep account containment and device assessment as related but separate work, and return to the official account history afterwards to confirm there is no unexplained continuing activity.
Look for evidence, then act on it
Use account activity and official exposure tools together, while keeping their limits clear. A negative search is not a clean bill of health, and a positive email result is not proof of an active intruder. Follow the evidence, secure exposed access and use the complete security guide to reduce the chance that another account suffers the same problem.
