Am I hacked? A 3-minute triage checklist

A code you didn't request, a reset email you didn't ask for, or a call that knew too much. Answer two questions and you'll know what's happening and what to do first. Nothing you select leaves your browser.

What happened?

Pick the closest match.

Why this keeps happening

Almost every scenario above traces back to the same two ingredients. A password that leaked in a breach at some company you'd forgotten about, and a set of current, accurate personal details that tell an attacker how to reach you and how to sound convincing.

The first one you fix by changing passwords. The second one is the part most people never address, because it isn't hacked data. Data brokers and people-search sites collect your name, current and past addresses, phone numbers, age, and relatives from public records and commercial sources, publish it, and sell it to anyone who pays. It's legal, it's cheap, and it refreshes as you move and change numbers.

That's what turns a years-old leaked password into a call that opens with your street name, or a text that uses your real name, or a carrier representative who approves a SIM transfer because the caller answered every verification question correctly.

What removing your data actually changes

It doesn't retract a breach, and nothing pulls data back off the dark web. What it changes is the open-web half: the broker profiles and people-search listings that keep your current contact details attached to your name and keep getting resold.

Delist finds those listings, files the removals, and keeps re-checking them, because brokers routinely repost a profile weeks after it comes down. Fewer live listings means less material for building the next targeted attempt against you.

See who's publishing your personal information

Run a free scan to find which data broker and people-search sites are exposing your name, phone number, address, and email right now.

Run my free exposure scan

Keep reading

Why you're getting 2FA codes you didn't request · The first 48 hours after a breach · How phishing works · All free tools