Dark web monitoring: what "your email appeared in a breach" actually means

Tobava Security Team · · 4 min read
← All articles

A breach notification is alarming and rarely actionable — it tells you something happened without telling you what to do. Here's how to read one properly and what genuinely needs your attention.

What a breach alert actually means

Your email address appeared in a dataset from a compromised service. That's it. It does not mean your email account was hacked, or that anyone has your current passwords.

What matters is what else was in the dataset alongside your address:

The real threat is reuse, not the breach

Attackers don't usually target you specifically. They take millions of leaked email/password pairs and replay them automatically against banks, email providers and shopping sites. This is credential stuffing, and it works because people reuse passwords.

A breach at a forum you forgot about in 2015 is harmless — unless that password also opens your email today.

What to do, in order

1. Change the password on the breached service — or delete the account if you no longer use it. Dormant accounts are liabilities.

2. Change it everywhere else you used it. This is the step that matters. If you can't remember where, that's the strongest possible argument for a password manager.

3. Prioritise your email account above everything. Every password reset lands there. If one account gets a unique, strong password and MFA today, make it that one.

4. Turn on MFA on anything important — email, banking, password manager, domain registrar. Even a leaked password is largely useless without the second factor. See 2FA vs passkeys.

5. Check for forwarding rules and filters you didn't create. After a mailbox compromise, attackers frequently leave an auto-forward or auto-delete rule so they keep reading after you change the password. Almost nobody checks this. In Tobava Mail these live on two separate screens in Settings — check both.

6. Watch for targeted phishing. Breach data feeds convincing follow-ups — messages referencing a real service you used, sometimes quoting a real old password to establish credibility.

What you don't need to do

The sextortion email

A common follow-up: an email quoting one of your old passwords, claiming your webcam was recorded, demanding payment. The password is real — from a breach dump. Everything else is fabricated. Delete it, and change that password anywhere it's still in use.

Getting ahead of it permanently

The goal isn't to never appear in a breach — with hundreds of services breached yearly, that's not achievable. The goal is making each breach a non-event: unique password, MFA enabled, nothing to reuse.

Try Tobava Mail free

Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.

Create your free account