How do I tell if a password breach alert is legit or phishing?
#1
I just got a notification that my password was found in a data breach, but the alert came from a service I don't remember signing up for. How do I even start verifying if this is a legitimate warning or some kind of phishing attempt itself?
Reply
#2
I got one like that a year ago. First thing I did was not click anything in the message. I checked who sent it, and I hovered over links to see the real domain. If I didn’t sign up for that service, I treated it as phishing and didn’t log in through it. Then I changed the password on any account that used the same one.
Reply
#3
I checked Have I Been Pwned using my email to see if there was a real breach, and then updated login details on any accounts that shared the same credential, and turned on 2FA where possible.
Reply
#4
I’ve gotten similar warnings that turned out to be nothing, so I always try to go to the official site by typing the address myself instead of following a link in the message.
Reply
#5
Do you think this is the real issue or could there be something else going on here?
Reply


[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Forum Jump: