How to Automate Alerts When Your Personal Data Shows Up in a New Breach

Starter · Level 1 of 3

Have I Been Pwned and Mozilla Monitor will both email you the moment your address turns up in a newly reported data breach, and wiring up both takes about fifteen minutes. Sign up for each service’s free notification option, confirm your email address, then route the alerts into a dedicated Gmail label so they don’t get buried in your regular inbox. That’s the whole system: two free monitors watching in the background, one filter making sure you actually see what they find. No paid identity-monitoring subscription is required for this baseline setup, though there’s a case for one near the end of this guide.

What counts as a breach, and why an alert actually matters

A breach, in the sense that matters here, is any incident where a company or service loses control of data it held about you: usernames, email addresses, passwords, sometimes payment details or physical addresses. Companies discover and disclose these on their own schedule, which is often weeks or months after the fact, and most people never see the disclosure at all unless they happen to be reading tech news that week.

The problem an alert solves is timing. If your password from an old, half-forgotten account leaks and you don’t hear about it, that password sits there — and if you reused it anywhere else, so does the risk. An alert turns a breach you’d never otherwise notice into a specific, actionable task: change this one password, on this one date, because of this one incident. That’s a fifteen-second job if you catch it early, and a much bigger cleanup if you don’t.

The pattern repeats constantly: a retailer’s customer database gets scraped, a small SaaS tool signed up for once and forgotten gets compromised, a forum account from years ago resurfaces in a compiled breach dump. None of those make the evening news, and none of them show up on your radar unless something is specifically watching for your address and telling you when it turns up.

Step 1: set up Have I Been Pwned notifications

Have I Been Pwned (HIBP) is the breach-notification service security researchers and journalists check first, and its free tier covers exactly the use case here: get emailed when your address shows up in a new breach.

  1. Go to the Notify Me page on haveibeenpwned.com.
  2. Enter the email address you want monitored and submit the form.
  3. Open the verification email HIBP sends and click the confirmation link. This step matters: monitoring doesn’t start until you verify.
  4. Once verified, you land on your HIBP dashboard, where you can add more than one address if you monitor a household or a small team.

From here, HIBP emails you automatically whenever the address you registered appears in a breach it has indexed. There’s nothing to check manually and nothing to renew; it’s a one-time setup that keeps running.

Step 2: add a second free monitor for coverage redundancy

No single breach database catches everything, so pairing HIBP with a second, independently sourced monitor closes some of the gap. Mozilla Monitor is a solid free pairing: it’s run by an organization with no interest in upselling you into a bundle, and its baseline breach alerts cost nothing.

  1. Go to monitor.mozilla.org and enter your email address for a free scan.
  2. Review the scan results, which show any breaches already tied to that address.
  3. Sign up for ongoing breach alerts using the same address, which requires a free Mozilla account if you don’t already have one.
  4. Confirm the account, and Mozilla Monitor will email you automatically going forward whenever a new breach affecting that address appears in its database.

Register the same email address with both services. Redundant coverage on one address you actually check is more useful than partial coverage spread across several inboxes you don’t.

Check what’s already out there before you turn on alerts

Both signup flows double as an immediate check, not just a future one. Entering an address on HIBP’s main search page shows every indexed breach already tied to it, and Mozilla Monitor’s free scan does the same thing before it asks for ongoing alerts. Run that check first, on every address worth monitoring, so the alert setup starts from a known baseline instead of leaving old exposures undiscovered. If either scan turns up a breach involving a password still in use anywhere, treat it the same as a fresh alert: change that password today, not after the next incident makes it urgent.

Route the alerts so they don’t get lost in your inbox

Both services email from a predictable sender address, which makes them easy to filter. Create a Gmail filter that matches mail from HIBP’s and Mozilla Monitor’s notification addresses, apply a dedicated label such as “Security Alerts,” and skip the inbox so the label is the only place these emails live. That way a breach notification never scrolls past unread among newsletters and receipts — it sits in one place you can check on a schedule. If you haven’t set up Gmail filters and labels before, Gmail filters and labels: automate your inbox in 30 minutes walks through the exact setup, and the same filter pattern works for these breach alerts.

What to do the moment an alert lands

When a breach notification actually arrives, work through a short, fixed checklist instead of improvising:

  • Confirm which account the breach involves, and change that account’s password immediately.
  • Check whether you reused that password anywhere else, and change it there too.
  • Turn on two-factor authentication for the breached account if it isn’t already on.
  • If the breach exposed more than a password (payment details, government ID numbers, security questions), check that provider’s own breach notice for its specific recommended next steps.
  • Note the date and source in a password manager or a simple log, so you have a record if the account gets disputed later.

A password manager that generates and stores a unique password per site removes the reuse question entirely going forward, which is the single biggest lever for reducing how much any one breach can hurt.

What these free services do not catch

Free breach monitors are useful and honest about their limits, which is worth being honest about here too. They only know about breaches that have already been publicly disclosed and indexed, so a fresh leak circulating privately on criminal forums won’t trigger an alert until someone surfaces it publicly. They also only monitor the email address, phone number, or account you explicitly registered, so if a breach exposes a different email you use, or a physical address, they won’t flag it unless you registered that too. Neither service actively removes your information from data broker sites either; they tell you when new data leaks, not what’s already circulating from data brokers who compiled it legally. If you want to address that side, how to automate data broker opt-outs so they actually stick covers removal, which is a genuinely different problem from breach alerting.

How often to revisit this setup

Once it’s running, this setup needs almost no maintenance. Check your “Security Alerts” label whenever you happen to be in Gmail, respond to what’s there, and otherwise leave it alone. The one thing worth doing periodically is registering any new email address you start using regularly with both services (a work email, a new personal address, an address tied to a side project), since neither service backfills coverage automatically for an address you never told it about.

When a paid identity-monitoring bundle is worth it

The free setup above covers the core job: know when your email shows up in a new breach, and know quickly enough to act. Paid identity-monitoring bundles go further, typically adding credit file monitoring, Social Security number and bank account tracking, dark-web forum scanning beyond indexed public breaches, and identity-theft insurance or white-glove recovery help if something does go wrong. That’s a meaningfully different product, not just a fancier version of a free breach alert.

A paid bundle earns its cost if you’ve already had your identity stolen once and want the recovery support in place before it happens again, if you handle financial accounts or sensitive client data professionally and can’t treat a breach as a personal inconvenience, or if you’d genuinely rather not think about any of this and are willing to pay someone else to watch it. Skip it if the honest answer is that a breach means changing a password and moving on. The free pairing above already covers that case, and a subscription on top of it buys peace of mind rather than additional protection. For most people running the free setup above and reacting promptly when an alert lands, that’s enough.

The whole setup costs nothing and takes less time than reading this article. It won’t catch every leak on the day it happens, but it turns a habit you’d otherwise forget into an alert you can’t miss.