Breach research

Your Email Is in Every Breach We Index. It’s the Master Key.

August 26, 2026
Six leaked data fragments (password, phone number, home address, date of birth, IP address, browser cookies) all connected to one central email symbol: 779 of 779 breaches indexed by XposedOrNot contain email addresses

Every one of the 779 breaches in the XposedOrNot catalog contains email addresses. Not most of them. All 779, as of August 26, 2026. Scroll down for the receipt if you want to run the count yourself.

We run XposedOrNot, a free breach-search service with an open API. Its catalog stretches from 2007 to 2026: 779 breaches, 11.61 billion exposed records. (Records, not people: one record is one row of leaked data, and the same address appears across many breaches.) When we counted which data types those breaches expose, the ranking looked like this:

RankData typeBreachesShare of catalog
1Email addresses779100%
2Passwords51666%
3Names40552%
4Usernames39350%
5IP addresses27535%
6Phone numbers27435%
7Physical addresses21728%
8Dates of birth19625%
9Genders11214%
10Geographic locations10413%

Passwords, the thing everyone worries about, show up in two thirds of breaches. Names in half. Email addresses in every single one.

The short version:

  • All 779 breaches in our catalog expose email addresses; no other data type comes close (passwords are second at 66%). As of August 2026.
  • Your email almost never leaks alone: 583 breaches (75%) pair it with three or more other data types.
  • You cannot rotate your email the way you rotate a password, so the defense is making it open fewer doors: unique passwords, 2FA on the email account itself, and knowing what is already out there.

The rest of this post is why that gap at the top of the table exists, what it lets an attacker do, and the reasoning behind those three moves.

Why email is the join key

Your email address works harder than anything else you own online. It logs you in almost everywhere, it recovers every other account when you get locked out, and it stays put through every password reset, phone upgrade, and job change.

Now flip it around. Someone sitting on a pile of breach data owns billions of fragments: a password from one leak, a phone number from another, a home address from a third. Fragments are cheap. The money is in joining them, and the join key is the email address, the one field present across the whole pile.

In database terms, your email is the primary key of your digital identity. Nobody designed it that way. It just happens to be the only identifier that every service demands and almost no one ever changes.

It is almost never just your email

The 100% figure understates the problem, because email addresses rarely leak alone. Of the 779 breaches in the catalog, exactly 8 expose email addresses and nothing else. The other 771 pair your address with at least one more data type, and 583 of them, three quarters of the catalog, pair it with three or more. The median breach exposes 4 different data types. The widest single entry exposes 13, including religion, sexual preferences, and drink and drug habits, from a 2020 dating-site breach.

The long tail is its own lesson. Across the catalog we count 65 distinct data-type labels, and 30 of them appear in exactly one breach: auth tokens, AI prompts, mothers’ maiden names, vehicle identification numbers. Security questions and answers appear in 6 breaches, social security numbers and passport numbers in 4 each. Whatever the strangest thing you ever handed a website was, somewhere there is a breach where that exact category sits in a row keyed to someone’s email address.

Two numbers from that co-occurrence table deserve a closer look:

  • Passwords ride along in 516 breaches, and those 516 account for 6.75 billion of the catalog’s 11.61 billion records. When your address leaks, a password comes with it more often than not.
  • You do not need a password to be exposed. The Verifications.io breach alone holds 762 million records pairing email addresses with names, phone numbers, dates of birth, genders, and locations, and not a single password. Armed with that, someone sails past the average “security question” and writes you a phishing email that reads like it came from an old acquaintance. Which, in a grim way, it did.

What the join looks like in practice

No genius required; there are tools for this. Someone searches your address across every breach, combolist, and stealer log they hold (three different leak types with three different risk profiles, as we covered earlier) and gets back your slice of entries like these, all real, all in our catalog:

  • Collection-1, surfaced 2019: 790 million records pairing email addresses with passwords, stitched together from thousands of older leaks. A combolist is the join already done for you, at industrial scale.
  • Verifications.io, 2019: the 762 million profile records above. No passwords, maximum personal detail.
  • AlienStealer logs, 2025: 299,646,818 unique email addresses we extracted from infostealer logs, where credentials arrive fresh from infected devices rather than from a hacked server.

Fragment by fragment, the join produces passwords to try everywhere, personal details that season phishing with credibility, and a timeline of your habits going back years. The catalog’s giants do the heavy lifting: as we found when we ranked industries by breach volume, the median breach holds 1.13 million records while the mean is 14.9 million, because a small number of mega-compilations carry most of the total. Your forgotten forum account and your current bank login sit in the same pile, joined on one address.

And the join has time on its side. When we measured the gap between a breach happening and its data surfacing publicly, the median came out at 1,591 days. More than four years. A leak from a site you last used in 2014 becomes a problem for your bank today precisely through this machinery: the data circulates privately, gets joined, and surfaces long after you stopped thinking about it. Our oldest entry, gPotato from 2007, took over a decade to surface in usable form.

What you cannot do, and what you can

You cannot realistically change your email. It is load-bearing across hundreds of accounts, and rotating it is a months-long project that mostly is not worth it. Unlike a password, exposure of your email is permanent.

So the strategy is not to hide the key. It is to make the key open fewer doors:

1. Break the password chain. The join is only profitable if a found password works somewhere else. Unique passwords everywhere (via a password manager, not discipline) turn the attacker’s best asset into trivia. The stakes are not theoretical: 83 of the 516 password-bearing breaches in our catalog stored those passwords in plaintext. You can check whether a password has already surfaced without sending it anywhere; the check uses a k-anonymity design.

2. Turn on 2FA where it counts. Email account first, then banking. The email account deserves special paranoia because it resets everything else; it is the master key’s master key.

3. Consider aliases for new signups. Many providers support address aliases or subaddressing, and dedicated alias services exist. Every alias is a join the attacker does not get for free. (This is optimization, not obligation; steps 1 and 2 carry most of the value.)

4. Know what is already joined to you. Ten seconds: xposedornot.com, your address, no signup. The results are exactly the fragments an attacker would see, minus the raw passwords, which we never display or serve to anyone. Our walkthrough of a breach check covers how to read what comes back.

5. Get told when new fragments appear. A free alert, set up once, and the next breach containing your address notifies you instead of only the people who bought the dump. Given the four-year median lag above, an alert is how you find out in the first usable hour rather than in 2030. If you would rather not be publicly searchable at all, Privacy Shield hides your address from public queries while you keep your own view.

The receipt

As always in this series, do not take our word for the headline number:

curl -s "https://api.xposedornot.com/v1/breaches" > breaches.json
python3 -c "
import json
d = json.load(open('breaches.json'))['exposedBreaches']
def kinds(x): return set(t.strip() for t in x['exposedData'] if t.strip())
print('Total breaches:', len(d))
print('With email addresses:', sum(1 for x in d if 'Email addresses' in kinds(x)))
print('Email and nothing else:', sum(1 for x in d if kinds(x) == {'Email addresses'}))
print('Email plus 3 or more other types:', sum(1 for x in d if len(kinds(x) - {'Email addresses'}) >= 3))
"

Our run on August 26, 2026:

Total breaches: 779
With email addresses: 779
Email and nothing else: 8
Email plus 3 or more other types: 583

One honest caveat with it: a breach-search service indexes what it can search, so email-bearing breaches are naturally what a catalog like ours collects. The 100% describes our catalog, not a census of all breaches ever, and an email-indexed catalog reaching exactly 100% is partly a statement about how we index. The practical conclusion survives the caveat: your email is the most-leaked, most-joinable identifier you own, and it almost never leaks alone.

Check what is already tied to yours: xposedornot.com. Worst case? You learn something useful.

And if numbers-with-receipts is how you like your security content, drop us a star on GitHub. It helps others find the project, and honestly, it makes our day.

Frequently asked questions

Why is my email address in so many data breaches? Because it is the one identifier nearly every service requires and stores. In the XposedOrNot catalog, all 779 indexed breaches contain email addresses (as of August 2026), ahead of passwords (66% of breaches) and names (52%). Your email is your username, your recovery channel, and the field that stays constant for years, so it appears wherever anything leaks.

Can I remove my email address from data breaches? No. Copies of breach data spread beyond anyone’s reach the day they leak, and swapping your email address is a months-long project few people finish. Focus on damage control instead: unique passwords everywhere, 2FA on the mailbox that resets everything else, and a breach alert for whatever surfaces next. On XposedOrNot, Privacy Shield also takes your address out of public search results.

Do data breaches expose more than email addresses? Almost always. Only 8 of the 779 breaches we index expose email addresses alone; 75% pair the address with three or more other data types, most commonly passwords, names, usernames, IP addresses, and phone numbers. Some breaches carry no passwords at all but plenty of personal detail; one exposed 762 million records with names, phone numbers, and dates of birth attached to email addresses.

Appendix: Sources and references

—


Check out some of our posts for you.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading