How to check whether your data has leaked: a safe approach without panic
You can check whether an e-mail address and password have leaked in a minute through the international service Have I Been Pwned. Phone numbers and Russian databases are harder: there is no single reliable public tool, and dubious “checking” Telegram bots often collect user data themselves.
This guide is practical. First we cover safe ways to check, then separately what to do with leaks you find and what protection steps to take.
The main rule: checking is not the goal, it is a reason to work on digital hygiene. The leaks themselves have already happened; you cannot affect them, but you can affect the damage.
Short answer
- E-mail addresses and passwords — check through Have I Been Pwned, an international open-source service.
- Phone number — there is no single reliable public service for Russia. Do not use “checking” Telegram bots.
- Passport data and SNILS — you cannot “check” them publicly. Protect yourself through procedures, such as a self-ban on loans.
- After finding a leak: change the password + enable 2FA + check credit bureaus (free twice a year through Gosuslugi (Госуслуги)).
- Do not enter passport data into random “checking services” — that is the worst option.
How to check safely: step by step
Step 1. Check your e-mail
Open haveibeenpwned.com and enter your e-mail address. The service will show which known leaks included this e-mail address and which fields were exposed there, such as password, phone number, or name. The service does not store the search query and does not send spam.
Check all your e-mail addresses: your main one, work one, and old university one. It is especially important to check the address used for your bank, Gosuslugi, and important messengers.
Step 2. Check your password
On the same site, use the Passwords section: enter the password. It is transmitted as a hash; the plaintext password is not sent to the server. If the password appears in leaks, change it urgently everywhere it was used.
Step 3. Subscribe to notifications
Have I Been Pwned lets you set up notifications: you will receive an e-mail as soon as your e-mail address appears in a new leak. Subscribe your main addresses.
Step 4. Check your credit history
Through Gosuslugi, you can get a credit bureau report free of charge twice a year. This is not a check for the “leak” itself, but for its consequences: if a loan was issued using your passport, it will be visible in your credit history. If you find an unfamiliar loan, file a report with the bank and the police.
Step 5. Set up a self-ban on loans
Starting in 2025, Gosuslugi lets you set a self-ban on taking out loans. This closes the main risk from a passport data leak: the bank simply will not be able to issue a loan remotely.
What to check and where it is safe
| What we are checking | Where it is safe | What to avoid |
|---|---|---|
| Have I Been Pwned | “Telegram bots for checking” | |
| Password | Have I Been Pwned (Passwords) | Entering a password into random forms |
| Phone number (Russia) | No reliable public service — skip this step | “Find out who called” bots — they collect your database |
| Passport / SNILS | Protection through procedures: self-ban, credit bureaus | “We will check your passport for free” — almost always phishing |
| Credit history | Gosuslugi (free twice a year) | “Find out debts by surname” — scammers |
| Access to Gosuslugi | Personal account → login history | Third-party “account analytics” tools |
How to check right now
Wanted Radar does not check data leaks — Have I Been Pwned is available for that, linked above. We search the MVD wanted persons registry; source: Mediazona. If you found a leak and want to make sure you were not framed in a criminal case under someone else’s name, you can do that with us.
What to do after finding a leak
Do not panic. Most leaks are already “historical data”: old passwords and inactive e-mail addresses, which by themselves do not give a scammer access. Combinations are dangerous: phone number + bank, e-mail + password if the password is still active, passport + SNILS.
The minimum set of actions after finding a leak: change the password on the affected service and everywhere the same password was used; enable 2FA through an authenticator app, not SMS; if the leak included a phone number, keep in mind that over the next few months you can expect “bank” calls using social-engineering schemes.
What to do next
- Change the password on the affected service and everywhere the same password was used.
- Enable two-factor authentication through an app: Aegis, 2FAS, Google Authenticator.
- Install a password manager such as Bitwarden or KeePassXC — all passwords should be unique.
- Request your credit history through Gosuslugi once a year.
- Set up a self-ban on loans — it closes the main risk from a passport leak.
- Subscribe to Have I Been Pwned notifications — you will learn about a new leak in real time.
- If the leak included a phone number, discuss scammer schemes with elderly relatives in advance.
Disclaimer: this material is informational and is not legal advice. For questions about unlawful loans issued in your name, contact the bank, the credit bureau, and the police (Article 159 of the Criminal Code of the Russian Federation).
Conclusion
Checking for leaks is a simple step and takes a few minutes. The main thing is not to use dubious “checking” services that collect data themselves. Have I Been Pwned + credit bureaus through Gosuslugi + a self-ban on loans — this minimum set closes most everyday risks. Read about how scammers use leaks in phone calls in a separate article.