Has my email been breached?
Type your address and the tool tells you which public data breaches it appears in, what was exposed each time, and when. Free, no account, and it never asks for a password.
- Every breach, named The service involved, the year, and what happened.
- The data exposed Passwords, phone numbers, postal addresses, government IDs, bank details.
- The scale How many accounts were caught, and the organisation's sector.
- Nothing is kept No password asked for, no cookie set, no address stored.
Data breaches, every single day.
Since the start of 2026 there have been data breaches every day, several times a day. The public FrenchBreaches tracker adds several of them every day, and the list mixes small businesses, federations, charities and town halls without distinction. Private and public alike, up to state bodies: France Travail, in the table below, is one.
The CNIL says the same thing in numbers: 6,167 data breach notifications in 2025, close to 16 a day, and nobody is spared. It is devoting half of its inspections and enforcement action to data security in 2026, and it still only counts French organisations that report. Many do not, even though failing to report is itself an offence, punishable by up to 10 million euros or 2% of turnover.
It is rarely a spectacular intrusion, more often a misconfigured server, a compromised supplier, an old service nobody switched off. And one breach produces the next, because the passwords it exposes are what gets someone into a supplier or a subcontractor, which leaks in turn. The data itself circulates for years, and the person concerned almost always finds out after the fact, if at all.
Five of the biggest French breaches of recent years
A breach does not close with the year it happened in: in January 2026 the CNIL fined Free Mobile and Free 42 million euros in total, and France Travail 5 million, over these 2024 intrusions.
The email address is the pivot for everything else. It identifies your accounts, it receives your password resets, and it is what lets two separate breaches be cross-referenced into one profile. An address paired with a leaked password gets replayed automatically against dozens of other services until one accepts it. That is credential stuffing, and it takes no particular skill.
Knowing where your address leaked repairs nothing, but it changes the question. You stop wondering whether you are affected and start knowing which of your accounts are, and in what order to take them back.
Your address is in a breach. Here is what to do.
In order, from most useful to most time-consuming. The first two points cover most of the real risk.
- Change the password on the service involved, then on every account where you had reused the same one. Reuse is what turns an old breach into a current problem.
- Turn on two-factor authentication everywhere it exists, starting with your mailbox. A dedicated app, Ente Auth, Aegis, 2FAS or Google Authenticator, beats a code sent by SMS, which an attacker can hijack by having your SIM card reissued. A hardware key, YubiKey or Nitrokey, beats everything else.
- Move to a password manager, with one unique password per service. Bitwarden and Proton Pass are free and open source, KeePassXC keeps everything local if you would rather sync nothing, 1Password is paid. Remembering forty different passwords is not a skill, it is a tool.
- Open your mail settings and check the auto-forwarding rules, the aliases and the connected devices. Someone who has had access to a mailbox usually leaves a quiet rule behind rather than coming back.
- Treat messages that quote accurate details about you with suspicion. A breach feeds targeted phishing directly, and a convincing message is not a legitimate one.
- If bank details are part of the breach, watch your statements and tell your bank. Blocking a card costs less than disputing a charge.
- Delete the accounts you no longer use. A service you forgot about is still a database holding your data, and it will leak without telling you.
- Run the check again from time to time. New databases are published and indexed constantly, and an address that is clean today can show up next month.
One work address is enough.
An address in the form first.last@your-company.com sitting in a breach is not a compromised hobby account. It is a named entry point into your information system. The password that came with it will be replayed against your VPN, your extranet, your webmail and your SSO, and it only takes one employee who reused theirs for the attempt to succeed.
This page queries a public index. A public index tells you that a breach exists. It does not tell you what is actually circulating about you today, or whether any of it still works.
On a company perimeter, under contract and with the authorization of whoever owns the accounts, I go further: which addresses on your domain are genuinely exposed, which credentials appear in the data sets in circulation, which of them still work, and what other data (documents, bank details, attachments) travels with the breach. The deliverable is a dated picture of the exposure, with what to cut off first.
This work connects to the rest: an exposed address matters mostly for what it opens, and it is the permissions and the authentication in your applications that decide whether it opens anything at all.
Where these results come from.
The check queries the public index maintained by XposedOrNot, a free service that catalogues publicly disclosed data breaches and the categories of information exposed in each one. The breach descriptions shown in the result come from that index.
The request leaves your browser and goes to that service directly. It does not pass through bughunter.pro, which means I never see the address you type.
An index only knows what has been published and then catalogued. A database resold privately, a breach never disclosed, or an incident too recent will not be in it yet. An empty result therefore means "nothing publicly known", not "nothing leaked".
Following breach news
Common questions.
Is the tool really free?
Yes, with no account, no signup and no practical limit. The check queries the public XposedOrNot index, which is a free service. There is nothing to pay and nothing to create. The only ceiling is the one that service applies, 25 searches per hour from the same connection.
Is my email address stored anywhere?
Not by me. The request goes straight from your browser to XposedOrNot without passing through bughunter.pro. I never see the address you type, so there is nothing to store, nothing to log and nothing to delete. This tool sets no cookie, and the result is gone the moment you close the tab.
My address is in no breach. Am I safe?
That is good news, and it is not a guarantee. An index only knows the breaches that were made public and then catalogued. A database resold privately, a breach never disclosed, or an incident too recent to be indexed will not show up. No result means nothing is publicly known, not that nothing leaked.
Can you tell me which password leaked?
Not on this page, and no serious service does it for an arbitrary address typed into a form, because that amounts to handing credentials to whoever asks. On a company perimeter, under contract and with the authorization of whoever owns the accounts, the question becomes legitimate and I can answer it.
The tool shows an error or does not respond. Why?
Three possible causes. The service being queried caps searches per connection, 25 per hour and 100 per day, and you may have reached that ceiling. The service can also be temporarily unavailable, in which case trying again a little later is enough. Finally, an ad blocker or an aggressive privacy extension can stop the call from leaving your browser.
I manage a company's addresses. Can I check a whole domain?
Not from this page, which handles one address at a time. Across a full domain the work changes nature: the exposed addresses have to be enumerated, several sources cross-checked, false positives discarded, and what is still usable today established. That is an engagement, not a form, and it starts with a scoping conversation.
Go further than a public index.
If it is your company domain showing up in the breaches, tell me which one and what you expose on the internet. I come back with a scope and a price. First conversation with no commitment, full confidentiality.