Care
What to do when a company email shows up in a data breach
When a work address leaks, the real risk is a reused password and a hidden forwarding rule. Here's what to fix the same day and how to hear about the next one.
SummaryUnder a minute
The short version
When a work email address appears in a data breach, the danger is usually a reused password that lets a stranger into the mailbox. Owners can find leaked addresses with a domain search, then change passwords, check for reuse, turn on two-step verification and look for forwarding rules the same day. Domain notifications and admin alerts give early warning of the next leak.
Key takeaways
- Staff often sign up for outside sites with work addresses, so a breach on one of those sites can leak the address and the password typed there.
- A domain search on a breach lookup service shows every address on your business domain that appears in known leaks, along with the type of data exposed.
- For each address with a leaked password, change it, sign out every session, check where else it was reused and turn on two-step verification.
- Check each affected mailbox for forwarding rules and filters, because a new password does not remove a rule an intruder already set up.
- Turn on domain breach notifications and your email provider's admin alerts, and make sure those alerts reach an inbox someone actually reads.

Someone on your team used their work address to sign up for a supplier portal or a free webinar, and that site was later breached. For a pool service company in Boca Raton that might be a parts wholesaler's online ordering account, and for a joinery firm in Bolton it might be the builders' merchant's trade site, usually signed up with the same address that's printed on the invoices. The address is now sitting in a leaked list, often next to the password they typed there, and if they use the same password for their work mailbox, a stranger can log in as them. In our experience nothing looks wrong at first. Mail still arrives and goes out, while the person who got in sets up a quiet rule that copies invoices to an outside address and waits for a payment they can redirect. Below is what to check and change the same day, and how to hear about the next leak early.

How to find out which of your addresses have leaked
Free breach lookup services gather leaked lists and let you search them. The best known is Have I Been Pwned: you type in one address and it shows which breached sites it appeared in and what kind of data leaked alongside it, such as names, phone numbers or passwords.
Checking one address at a time misses most of the picture for a business, though, because staff sign up for things with addresses you've forgotten about, including old ones that belonged to people who left. The same service has a domain search, free for smaller domains, while domains with many affected addresses need a paid subscription. You prove you control your domain (the part of the address after the @), usually by adding a small record at the company that hosts your domain or by receiving an email at an admin address, and then you see every address on that domain that shows up in its records.
What good looks like is a short list with the name of each breached site, the date of the breach and the types of data that leaked. Read the data types first. An entry that includes passwords is the one to act on today, even if the breach is old, because an old password that was never changed still works. Entries that only list names and email addresses mean more phishing emails are likely to arrive, which is worth telling the person about, but nobody can log in with that alone.
There are other ways you find out. A site may email its users to say it was breached, and it's easy to dismiss that as spam. Sometimes the first sign is a staff member mentioning a sign-in code they didn't ask for, or a supplier asking why they got a strange invoice from you. Treat both as leads and check that mailbox.
Email data breach: what to do the same day
Work through these in order for each address that showed a leaked password. Once you know where the settings are, it usually takes less than an hour per person.
Change the work password and sign everyone out
Change the mailbox password to something long that hasn't been used anywhere else. A string of several unrelated words is easy to type and hard to guess. Then sign the account out of every session. Your email admin page has an option to sign a user out everywhere, and the user can do it from their own account security page. This matters because changing the password doesn't always end a session that's already open on someone else's laptop.
Check where else that password was used
Ask the person, privately and without blame, where else they used the same password or a close variation of it. Reuse is what turns an old breach on some forgotten site into a live problem for your business. The places that usually come up are online banking and payroll, then the website login and social media accounts. Change each one, and if a variation like the same word with a different number at the end was used anywhere, change those too, because people trying leaked passwords test the obvious variations.
This is a good moment to set up a password manager for the business. Each site gets its own random password, staff don't have to remember any of them, and when someone leaves you can see which shared logins they had.
Turn on two-step verification
With two-step verification switched on, a password alone isn't enough to log in. The person also has to approve the sign-in on their phone or type a code from an app. Turn it on for the leaked account today, then for every mailbox in the business. As the admin you can require it for everyone, which works better than asking each person to do it. Where you have the choice, use an authenticator app over text message codes, since a phone number can be moved to another phone by someone who talks their way past a mobile carrier.
Look for forwarding rules and filters
This is the step most people skip, and in our experience it's where the damage hides. Someone who gets into a mailbox often sets up a rule so they keep receiving copies of mail after they've been locked out, or so replies from a customer never reach the real person. The invoices they wait for are usually the larger ones, like a roof replacement deposit in Broward County, a dock and seawall repair behind a canal-side home in Fort Lauderdale or a kitchen refit in Trafford.
In Outlook on the web, open Settings, then Mail, and look at both Forwarding and Rules. In Gmail, open Settings, choose See all settings, and look at the Forwarding and POP/IMAP tab and then the Filters and Blocked Addresses tab. These should worry you:
- forwarding to an outside address nobody recognizes
- a rule that moves messages containing words like invoice, payment or bank into a folder nobody opens
- a rule that deletes messages from a particular customer or supplier
- a recently added recovery phone number or backup email that doesn't belong to the staff member
Look in Sent and Deleted Items as well, for messages the person didn't write. If you find something, take a screenshot before you delete it, so you keep a record of the outside address and the dates. Then send customers and suppliers a short, calm note saying that if they ever get a message from you asking to change bank details, they should call you on a number they already have before paying anything.

Set up alerts so you hear about the next one early
Once your domain is verified with the breach lookup service, turn on notifications for the domain. You'll get an email when any address on it appears in a newly loaded breach, which gives you a head start on changing the password and checking the mailbox.
Your email provider has its own alerts. The business versions of both Microsoft and Google mail can send admin warnings for things like a suspicious sign-in or a new rule that forwards mail outside the company, and some of these are on by default. Open the admin alerts page once and check two things: that the alerts are turned on, and that they go to an inbox someone reads. A common gap we find is alerts going to the address of whoever set up the account years ago, who may not even work there anymore. For a Florida business, it's worth checking this before hurricane season, because after a storm knocks the power out, staff end up reading mail on phones and borrowed laptops for days, and a strange sign-in warning is easy to miss in that mess.
Alerts are easier to act on when there are fewer outside sign-ups to worry about, so a couple of habits are worth agreeing with the team:
- use the work address for work tools only, and a personal address for newsletters, contests and online shopping
- when someone leaves, change the passwords they knew and either close their mailbox or turn it into a shared one that an admin controls
Keep a simple list of which business accounts exist and who can log into each one. When the next alert arrives, that list tells you in a few minutes what else might be affected.

How Pixedi handles this in the Care plan
In the Care plan, $250 a month, email health and watching the business's online accounts are part of the routine work. We keep watch for your domain's addresses turning up in new breaches and check sign-in security and forwarding settings on the mailboxes. When something needs a change on your side, such as a staff member resetting a password, we tell you and walk them through it. What we found and what we did goes into the one-page monthly report, so you don't have to log in anywhere to see it.
What to do this afternoon
Do the domain search for your business address on the breach lookup service and read the data types for each entry. Pick the address with the most recent leaked password, open that mailbox's forwarding and rules settings first, then change its password and turn on two-step verification before you move on to the next name on the list.
Sources
Ask AI about this article
Opens the assistant in a new tab with this page as the source.
Keep reading
Want this handled for your business?
Start with the free site audit: speed, search, mobile, security, local presence and email, in plain English.


