A breach notification lands in your inbox, or you type your address into a checker and watch it surface in eight leaks you had forgotten about. The address is out. The question nobody answers is where it travels next, and who pays for it at each stop along the way.
Your email address gets bought several times over. A breach dump or infostealer log sells in bulk to dark-web resellers and credential-stuffing crews. Separately, legal data brokers use it as a join key to build a profile, then license that to marketers and list sellers. The journey ends at your inbox.
Who buys your email address after a breach?
A short chain of buyers, each paying for a slightly different thing. The same address that is nearly worthless as one line in a breach dump becomes valuable once someone confirms a real person reads it and can be sold something. Between the leak and the spam, your address passes through several hands, and two separate economies bid on it: a criminal one built on stolen dumps, and a legal one built on data brokers. Here is the route it takes.
| Stop on the journey | Who buys it | What they want it for |
|---|---|---|
| Breach dump / stealer log | Bulk resellers, initial-access brokers | Cheap raw material to clean up and repackage |
| Dark-web market | Credential-stuffing crews, spammers | Test reused passwords; blast promos and phishing |
| Data-broker enrichment | Licensed data brokers | An identifier to attach to a full personal profile |
| List-rental market | Marketers, lead sellers | A “confirmed live” address that opens and buys |
What happens the moment a breach dump goes public?
It gets copied endlessly and merged with older leaks. A single dumped database rarely stays a single file. Resellers pull it apart, deduplicate it, match it against previous breaches, and stitch the pieces into bigger, cleaner collections that are easier to sell. The scale is hard to overstate. In November 2025, Have I Been Pwned indexed one corpus of roughly 2 billion unique email addresses, pulled from infostealer logs and credential-stuffing lists and compiled by the security firm Synthient (Troy Hunt, 2025).
Two kinds of data feed that pile. Infostealer logs come from malware sitting on an infected machine, quietly harvesting saved passwords and session cookies. Credential-stuffing lists are bundles of email-and-password pairs from earlier breaches, sold so an attacker can test whether you reused that password anywhere else. Your address rides in both, which is why one careless site can put you in a file with two billion strangers.
Who buys it on the dark web?
Bulk resellers and credential-stuffing operators, mostly, and they pay very little. A raw address in a dump is a commodity sold by the million, because the file next to it holds millions more just like it. Privacy Affairs, a privacy research group, priced 100 million US email addresses at about $200 in its 2023 Dark Web Price Index, which works out to roughly half a million addresses for a single dollar. We break down the full economics in what your email address is actually worth; the short version is that raw is cheap and confirmed is expensive.
The credential-stuffing buyer is not interested in mailing you at all. That buyer wants to log in as you, using a password you reused, and take over an account worth more than the address itself. A live mailbox with the password attached sells for far more than a bare address, because access to your inbox unlocks password resets everywhere else.
How does a data broker turn your address into a profile?
Your email address is the join key. On its own it is a string of characters, but it is also a stable, unique identifier that stays the same across every site you use it on, which makes it the perfect thread to tie scattered records together. A data broker links your loyalty-card purchases, your public records, your web-tracking history, and your survey answers into one dossier, and your address is often the label on the folder.
The compiled profiles are enormous. In its 2014 report Data Brokers: A Call for Transparency and Accountability, the US Federal Trade Commission found that one broker, Acxiom, held data on 700 million consumers with more than 3,000 data segments for nearly every US consumer. Another broker in the same study added more than 3 billion new records to its databases every month. Your leaked address does not sit in a spreadsheet by itself. It becomes one attribute in a file that already knows a great deal about you.
Are data brokers legal, and who are they?
Mostly legal, and separate from the criminal resale chain. A licensed data broker generally builds its profiles from public records, purchase histories, loyalty programs, and web tracking, not from stolen breach dumps, which carry real legal risk. The two economies run in parallel and end in the same result, more targeted mail, but they are not the same business.
The legal industry is large and, in some places, finally visible. California’s Delete Act requires data brokers to register with the state, and more than 500 have signed the public registry maintained by the California Privacy Protection Agency (2026). A 2025 expansion, SB 361, widened what those brokers must disclose, down to whether they trade in sensitive categories like citizenship status or union membership. The registry is one of the few windows anywhere into who is buying and selling addresses like yours.
Where does your address finally land?
At spammers and marketers, the buyers who actually mail you. By the time your address reaches a rented list, it has been cleaned, matched, and ideally confirmed as live, which is the trait every buyer pays extra for. That confirmation is why unsubscribing from real spam can bring more of it: a click proves a human reads the address, and a confirmed-live address gets promoted to higher-value lists and resold to other senders.
The fuller your address’s travel history, the more mail you get from both directions. Marketers reach you because they rented a list you are on. Scammers reach you because they bought a dump you are in. The real cost of that traffic is not just clutter; it is the minutes you spend triaging it and the raised odds that one convincing fake slips through.
How do you check where your email address has been exposed?
Run it through a breach checker, and it takes about a minute.
- Open Have I Been Pwned. Go to
haveibeenpwned.com, the free breach-notification service run by security researcher Troy Hunt. It indexes public breach data so you can search it safely. - Type your address and search. The site lists every known breach your address appeared in, with the date of each and what was exposed, from passwords to phone numbers.
- Read what leaked, not just that it leaked. A breach that exposed only your address is a different problem from one that exposed your password. The detail tells you what to change.
- Turn on notifications. Subscribe with your address and the service emails you when it turns up in a future leak, so you are not relying on the breached company to tell you.
The expected outcome is a clear map of where your address is already loose. You cannot un-leak it, but you can stop reusing any exposed password and start shrinking your future exposure.
How do you get your address off these lists?
You cannot recall copies already sold, but you can stop feeding new ones. Three moves do most of the work.
First, if you live in California, use DROP. Since January 1, 2026, the state’s Delete Request and Opt-out Platform lets a resident file one deletion request that reaches every registered data broker at once, and brokers must begin honoring those requests by August 1, 2026. Outside California, you opt out broker by broker, which is slower but still works.
Second, stop handing out your real address. Masked email aliases give each site a throwaway forwarding address, so the next breach burns the alias instead of you, and you learn exactly who leaked it.
Third, get off the marketing lists you are already on, for real. Every legitimate sender you remove is one less address-holder registering your opens and keeping your address priced as live inventory. Doing that by hand across years of senders is slow, and not every unsubscribe tool deserves the inbox access it asks for. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out where the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. You can run it on your own inbox and clear the backlog in one sitting.
The takeaway
Your email address is bought many times over, and the buyers are not who you would guess. Bulk resellers and credential-stuffing crews trade it on dark-web markets for a fraction of a cent. Data brokers, most of them legal, use it as the join key that turns scattered records into a 3,000-attribute profile. Marketers and spammers rent the result. You cannot undo a leak, but you can check where your address already sits, stop confirming that you read it, and give out fewer real copies from here on. The less your address travels, the quieter your inbox gets.
