← All guides

How to Find Out If Your Data Has Been Sold or Leaked

No single checker can prove everywhere your data went. Start with known breaches, public listings, and company records. Each answers a different question: a leak, a visible listing, and a data sale are not the same thing.

Published July 2, 2026 · Updated September 29, 2026 · 5 min read

Start here

  1. Check your email in known breaches

    Use Have I Been Pwned to check an email address. A match identifies a known breach; it does not show a complete history of data sales. Enter your email on that service, not on this page.

    Check Have I Been Pwned →
  2. Find personal details in Google results

    Results about you can help find contact details such as your address or phone number in search results and request eligible removals. A search result is evidence of publication, not necessarily a sale.

    Open Google's Results about you →
  3. Act on a listing you find

    Save the page address and date, then use the company's official privacy or removal process. Our removal guide covers individual requests and California's free DROP service.

    Follow the data removal steps →

Check what your browser reveals now

The free test shows signals a website can read from this browser and practical ways to limit exposure. It cannot search broker records or tell you who sold your data.

Run the free browser privacy test →

Sold, leaked, or publicly listed?

A breach involves unauthorized access or disclosure. A sale or sharing arrangement involves data being passed between organizations, with rules that depend on the context and jurisdiction. A public listing may come from public records, a broker, or information you posted yourself.

A breach match does not prove a sale. A broker listing shows that the broker holds or publishes those details, but it may not identify the source or every recipient. A clean result cannot prove your data has never been collected or shared.

Check known breaches first

Look up your email with Have I Been Pwned and read the named breach and affected data types. Review each affected account directly. If a password was exposed or reused, replace it with a unique password and enable the account's stronger sign-in options.

Mozilla Monitor still offers free breach monitoring. Its paid data-broker removal product, Monitor Plus, has closed. Neither service can search every stolen dataset or provide a full sales history.

Search for public listings and record what you find

Search your name with a current or previous city, and review results carefully: people with similar names can be mixed together. If a people-search site shows your details, keep the listing URL, the date, and which details are exposed before requesting removal.

Avoid giving an unfamiliar scan site extra sensitive details just to see a result. Start with information already visible, verify the service's address and privacy policy, and do not enter account passwords into a breach lookup.

Google's dark web report is no longer available: it ended on February 16, 2026. Results about you remains a separate way to find contact details in Google Search; it does not search the dark web or delete the source page.

Ask companies for their records

Use the official privacy request process of a company that may hold your information. Ask what it holds, where it came from, and what sale or sharing information it can provide. Keep the request and response together with your listing records.

Applicable rights depend on where you live, the organization, and the data involved. California's CCPA provides access and sale or sharing opt-out rights for covered businesses; EU data protection rules also provide access rights. Identity verification and exceptions may apply. Use the official sources below to check the rights relevant to you.

Choose the next step from the evidence

  • A known breach: secure the affected accounts and watch for messages that use the exposed details.
  • A public listing: request removal from the source, then address remaining search results separately.
  • Company records showing unwanted sale or sharing: use the applicable opt-out or deletion process and save the response.
  • No matches: keep sensible account and browser protections. An incomplete search is not a clean bill of privacy.

Frequently asked questions

Is there one website that tells me everywhere my data has been sold?
No. Breach tools cover known leaks, search and broker listings show some published information, and company access requests can provide further records. None gives a complete sales history.
Does Have I Been Pwned show whether my data was sold?
It shows whether an email appears in the breach data it covers. A breach match is not proof of a sale, and no match does not rule out collection, sharing, or an unlisted breach.
Can I still use Google's dark web report or Mozilla Monitor Plus?
Google's dark web report ended on February 16, 2026, and Mozilla Monitor Plus has closed. Google's Results about you and Mozilla's free breach monitoring are separate services that remain available.

Sources & further reading

Test your browser

See which browser, device, network, and fingerprinting signals your current setup exposes, then review practical next steps.

Run the free browser privacy test →