I typed my email address into the Duelling Hares digital exposure check. The report took about two seconds to generate. It listed twelve breaches I had been part of across eighteen years of using the internet. Four of those breaches exposed plaintext passwords. Two exposed security questions and answers. One exposed payment card data.

I knew about the Adobe breach. I did not know about the Shopify vendor leak from a tea company I bought from once in 2020. I did not know that my email had been collected by at least three data brokers who resell it to anyone with a credit card.

Let me walk through what the report showed and what it means.

My email has been part of twelve data breaches. The oldest was Adobe in 2013. 153 million accounts. Email, encrypted password, and password hint exposed. The hint for my Adobe account was the name of a pet I had not owned since 2009. That pet’s name is now in a breach corpus that circulates on the dark web.

The most recent breach was from 2023. A marketing analytics platform that a newsletter service used. The breach exposed email addresses and engagement data: which emails I opened, which links I clicked, what time of day I read them. That is not a password risk. It is a profiling risk. That data gets fed into advertising profiles that follow me across the web.

Four breaches exposed plaintext passwords. Plaintext means the site stored my password without hashing it. When the breach happened, my password was readable by anyone who obtained the database. If I had reused that password anywhere else, all of those accounts would be compromised.

The tool identified 47 services likely associated with my email. That number is an undercount. Most people have well over 100 accounts spread across their lifetime of internet use. The tool finds the ones linked to breaches, public profiles, and data broker records. Forty-seven is a lower bound.

The data broker piece is the one most people miss. When a breach happens, the email and associated data get collected by data brokers who aggregate it with other sources. Voter registration records. Property tax records. Social media profiles. Forum posts. The broker builds a composite profile and sells access to it. That profile does not get deleted when you change your password.

I checked what data was available for my email. Public records showed my approximate location based on past address associations. LinkedIn confirmed my professional history. A forum account from 2015 showed my interests and writing style. The composite profile was detailed enough to impersonate me convincingly.

The digital exposure check does not store the email you enter. It runs locally in your browser. That is important because an email check tool that logs the emails you search is itself a privacy risk. This one does not.

Here is what I did after the report. I went through each of the twelve breaches and checked whether I still used the compromised passwords anywhere. Most of them I had changed years ago. Two were still active on low-priority accounts. I changed those. I enabled two-factor authentication on every service that supported it. I deleted accounts I no longer used.

The cleanup took about three hours. That is three hours of work to fix eighteen years of digital accumulation. Most people will not spend that time. They should.

You can check your own email at the Duelling Hares digital exposure check. It takes ten seconds. The results might make you uncomfortable. That is the point. You cannot fix a problem you do not know exists.

The internet remembers everything. You should know what it remembers about you.