The attack has a name: credential stuffing
Data breaches happen to companies, not to you directly — but the passwords inside them are yours. When a site you used gets breached, your email address and password from that site can end up in a dump that circulates publicly or gets sold. New York’s Attorney General defines the resulting attack plainly: “credential stuffing is a type of cyberattack that typically involves repeated attempts to log in to online accounts using usernames and passwords stolen from other online services,” and it works because people tend to reuse the same password across the accounts they have to manage. Attackers don’t have to guess anything — they take a password that leaked from Site A and simply try it at Site B, Site C, and Site D, because attackers know that the username and password used at one website may also be used at a half-dozen others.
This matters differently for you than it does for a random hacker’s target list. An intimate partner or ex doesn’t need underground tools for this. If they know (or can guess) an email address you use, and you’ve ever reused a password, a single leaked password from an old, unrelated account can open your email, cloud storage, or social media today. CISA’s guidance following a major credential exposure tells individual users to “immediately update any potentially affected passwords that may have been reused across other platforms or services” — advice that applies whether the attacker is a criminal group or someone who used to have your Wi-Fi password. CISA’s own password guidance is built around this same weakness: it recommends passwords be long, random, and — critically — unique to each account, because reuse is what turns one breach into many compromised accounts.
Checking whether you’re already exposed
You don’t have to guess whether your information is out there. A few tools exist to check.
Have I Been Pwned. This is a long-running, free lookup service. By its own description, “the site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach,” and it “aggregates breaches and enables people to assess where their personal data has been exposed.” You search by email address, and it shows you which known breaches that address appeared in — with real limits. “Sensitive” breaches (85 at present, including adult-site and dating-site incidents) don’t appear in a public search unless you verify you own the address; a couple have been permanently “retired”; some are flagged “unverified.” HIBP itself says it holds only “a small subset of all the records that have been breached over the years” — not finding an address there doesn’t mean it’s clean. It’s careful about what it stores: “when email addresses from a data breach are loaded into the site, no corresponding passwords are loaded with them,” and every password checked through its companion Pwned Passwords tool is only compared as a SHA-1 hash, never stored in readable form, and searches are not logged. If a password shows up as pwned: it “should no longer be used as its exposure puts it at higher risk of being used to login to accounts using the now-exposed secret.” One more distinction: an HIBP match can be a breach without a password at all — an email showing up isn’t automatically a password to change.
Google Password Manager’s Checkup. If you save passwords to a Google account, Password Checkup will tell you whether any are exposed, weak, or used in multiple accounts. Google’s description is specific: “compromised passwords and username combinations are unsafe because they’ve been published online,” and Google recommends changing them as soon as you can. On a phone or in Chrome: Settings → Google Password Manager → Checkup (wording varies by device/version). Google can also proactively notify you of an exposed saved password.
Apple’s Security Recommendations. On iPhone and iPad, Apple’s Passwords app does something similar for iCloud Keychain entries. Apple explains that the device “automatically identifies common weaknesses” in saved passwords — easily guessed patterns or passwords reused across sites — and separately, “iPhone can also securely monitor your passwords and alert you if they appear in known data leaks.” To check: Passwords app → Security, where any flagged account explains the problem. Toggle detection at Settings → Apps → Passwords → Detect Compromised Passwords. Apple’s technical documentation adds detail on how flags are set: passwords are marked “reused” if the same password is seen used for more than one saved password across different domains, and marked “leaked” if the Password Monitoring feature can claim they have been present in a data leak.
None of these tools can tell you who used a leaked password. An HIBP email search tells you an address appeared in a given breach, whether or not that breach included a password; Google’s and Apple’s checkups flag a credential as compromised without naming the breach. Either way, retire the password.
The fix hierarchy, in order
Finding an exposed password is the easy part. What you do next — and the order — matters more.
- Change the exposed password first, everywhere it’s reused. Have I Been Pwned’s own guidance is that an exposed password “should no longer be used” anywhere — not just on the breached site. If you don’t know everywhere you’ve used it, that’s the argument for the next step.
- Move to a password manager with unique, generated passwords per account. This removes the reuse pattern that makes credential stuffing work at all. This is the deeper subject of account security when someone knows you — manager choice, master-password strategy, and the case where an intimate partner already knows an old password.
- Turn on two-factor authentication, or move to a passkey where it’s offered. Even a correctly guessed or stolen password doesn’t get an attacker in if a second factor is required. Passkeys remove the reusable password entirely for that account.
- Check your email account specifically, and first. Email is usually the recovery path for everything else. Email security goes deeper on mailbox-specific risks like forwarding rules and connected apps.
Credit freezes: for breach fallout beyond your accounts
Not every breach exposes a password — some expose a Social Security number, driver’s license number, or other identity data with no password to change. For that kind of exposure, the relevant tool is a credit freeze, not a password manager. The FTC is explicit that this protection is free: “there’s no cost to place or lift a credit freeze,” and “anyone can do it, any time” — you don’t need to wait until you know you’ve been breached. A freeze means, in the FTC’s words, “nobody can open a new credit account in your name” while it’s active, including you, until you temporarily lift it, and it doesn’t affect your credit score. To set one up, contact all three bureaus separately — Equifax, Experian, and TransUnion — since a freeze at one doesn’t cover the others. An initial fraud alert is a lighter, also-free option: it lasts one year, only requires businesses to verify your identity before opening new credit, and needs just one bureau contacted, which must notify the other two.
If you’ve gotten breach notices or one of the “your information is for sale on the dark web” emails, the FTC’s advice is to be skeptical of the email itself first: don’t click links or call numbers in the message; verify through a company site or number you already know, then change passwords starting with email, check credit reports, and consider a freeze.
“Dark web monitoring” — what it actually does
Paid monitoring services advertise that they watch the dark web for your data and alert you if something turns up. The FTC’s own consumer guidance doesn’t spell out how these services work internally — it simply acknowledges that some people have “a credit monitoring service or a credit card with a company that monitors the dark web.” What the FTC is clear on is what to do next, regardless of whether a monitoring service flagged the exposure or you found it yourself: change your passwords, check your credit reports, and consider a freeze. A monitoring subscription is a convenient alert system; it isn’t prevention — it can’t stop a breach or remove data already circulating — and it isn’t a substitute for those follow-up actions.
What this doesn’t tell you
None of these checks — HIBP, Google’s Checkup, Apple’s Security Recommendations, or a paid monitoring service — can confirm whether a specific person used a leaked password to get into your account. At best, they tell you an email turned up in a breach or a saved password looks compromised, not that someone used it against you. The exposure check is step one, not proof either way; changing the password and enabling a stronger second factor closes the door regardless of who walked through it.