Skip to content
Privacy & Safety

Where your email address goes after a data breach

A leaked email address gets bought many times over, by breach resellers, data brokers, list sellers, and spammers. Here's the journey, and how to check yours.

Email Unsubscriber Team 8 min read
Flat vector illustration of a cream envelope riding a conveyor belt past grabbing market stalls, with a broken padlock spilling address cards, a growing dossier folder, a SOLD tag, and a magnifying glass.

A breach notification lands in your inbox, or you type your address into a checker and watch it surface in eight leaks you had forgotten about. The address is out. The question nobody answers is where it travels next, and who pays for it at each stop along the way.

Your email address gets bought several times over. A breach dump or infostealer log sells in bulk to dark-web resellers and credential-stuffing crews. Separately, legal data brokers use it as a join key to build a profile, then license that to marketers and list sellers. The journey ends at your inbox.

Who buys your email address after a breach?

A short chain of buyers, each paying for a slightly different thing. The same address that is nearly worthless as one line in a breach dump becomes valuable once someone confirms a real person reads it and can be sold something. Between the leak and the spam, your address passes through several hands, and two separate economies bid on it: a criminal one built on stolen dumps, and a legal one built on data brokers. Here is the route it takes.

Stop on the journeyWho buys itWhat they want it for
Breach dump / stealer logBulk resellers, initial-access brokersCheap raw material to clean up and repackage
Dark-web marketCredential-stuffing crews, spammersTest reused passwords; blast promos and phishing
Data-broker enrichmentLicensed data brokersAn identifier to attach to a full personal profile
List-rental marketMarketers, lead sellersA “confirmed live” address that opens and buys

What happens the moment a breach dump goes public?

It gets copied endlessly and merged with older leaks. A single dumped database rarely stays a single file. Resellers pull it apart, deduplicate it, match it against previous breaches, and stitch the pieces into bigger, cleaner collections that are easier to sell. The scale is hard to overstate. In November 2025, Have I Been Pwned indexed one corpus of roughly 2 billion unique email addresses, pulled from infostealer logs and credential-stuffing lists and compiled by the security firm Synthient (Troy Hunt, 2025).

Two kinds of data feed that pile. Infostealer logs come from malware sitting on an infected machine, quietly harvesting saved passwords and session cookies. Credential-stuffing lists are bundles of email-and-password pairs from earlier breaches, sold so an attacker can test whether you reused that password anywhere else. Your address rides in both, which is why one careless site can put you in a file with two billion strangers.

Who buys it on the dark web?

Bulk resellers and credential-stuffing operators, mostly, and they pay very little. A raw address in a dump is a commodity sold by the million, because the file next to it holds millions more just like it. Privacy Affairs, a privacy research group, priced 100 million US email addresses at about $200 in its 2023 Dark Web Price Index, which works out to roughly half a million addresses for a single dollar. We break down the full economics in what your email address is actually worth; the short version is that raw is cheap and confirmed is expensive.

The credential-stuffing buyer is not interested in mailing you at all. That buyer wants to log in as you, using a password you reused, and take over an account worth more than the address itself. A live mailbox with the password attached sells for far more than a bare address, because access to your inbox unlocks password resets everywhere else.

How does a data broker turn your address into a profile?

Your email address is the join key. On its own it is a string of characters, but it is also a stable, unique identifier that stays the same across every site you use it on, which makes it the perfect thread to tie scattered records together. A data broker links your loyalty-card purchases, your public records, your web-tracking history, and your survey answers into one dossier, and your address is often the label on the folder.

The compiled profiles are enormous. In its 2014 report Data Brokers: A Call for Transparency and Accountability, the US Federal Trade Commission found that one broker, Acxiom, held data on 700 million consumers with more than 3,000 data segments for nearly every US consumer. Another broker in the same study added more than 3 billion new records to its databases every month. Your leaked address does not sit in a spreadsheet by itself. It becomes one attribute in a file that already knows a great deal about you.

Mostly legal, and separate from the criminal resale chain. A licensed data broker generally builds its profiles from public records, purchase histories, loyalty programs, and web tracking, not from stolen breach dumps, which carry real legal risk. The two economies run in parallel and end in the same result, more targeted mail, but they are not the same business.

The legal industry is large and, in some places, finally visible. California’s Delete Act requires data brokers to register with the state, and more than 500 have signed the public registry maintained by the California Privacy Protection Agency (2026). A 2025 expansion, SB 361, widened what those brokers must disclose, down to whether they trade in sensitive categories like citizenship status or union membership. The registry is one of the few windows anywhere into who is buying and selling addresses like yours.

Where does your address finally land?

At spammers and marketers, the buyers who actually mail you. By the time your address reaches a rented list, it has been cleaned, matched, and ideally confirmed as live, which is the trait every buyer pays extra for. That confirmation is why unsubscribing from real spam can bring more of it: a click proves a human reads the address, and a confirmed-live address gets promoted to higher-value lists and resold to other senders.

The fuller your address’s travel history, the more mail you get from both directions. Marketers reach you because they rented a list you are on. Scammers reach you because they bought a dump you are in. The real cost of that traffic is not just clutter; it is the minutes you spend triaging it and the raised odds that one convincing fake slips through.

How do you check where your email address has been exposed?

Run it through a breach checker, and it takes about a minute.

  1. Open Have I Been Pwned. Go to haveibeenpwned.com, the free breach-notification service run by security researcher Troy Hunt. It indexes public breach data so you can search it safely.
  2. Type your address and search. The site lists every known breach your address appeared in, with the date of each and what was exposed, from passwords to phone numbers.
  3. Read what leaked, not just that it leaked. A breach that exposed only your address is a different problem from one that exposed your password. The detail tells you what to change.
  4. Turn on notifications. Subscribe with your address and the service emails you when it turns up in a future leak, so you are not relying on the breached company to tell you.

The expected outcome is a clear map of where your address is already loose. You cannot un-leak it, but you can stop reusing any exposed password and start shrinking your future exposure.

How do you get your address off these lists?

You cannot recall copies already sold, but you can stop feeding new ones. Three moves do most of the work.

First, if you live in California, use DROP. Since January 1, 2026, the state’s Delete Request and Opt-out Platform lets a resident file one deletion request that reaches every registered data broker at once, and brokers must begin honoring those requests by August 1, 2026. Outside California, you opt out broker by broker, which is slower but still works.

Second, stop handing out your real address. Masked email aliases give each site a throwaway forwarding address, so the next breach burns the alias instead of you, and you learn exactly who leaked it.

Third, get off the marketing lists you are already on, for real. Every legitimate sender you remove is one less address-holder registering your opens and keeping your address priced as live inventory. Doing that by hand across years of senders is slow, and not every unsubscribe tool deserves the inbox access it asks for. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out where the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. You can run it on your own inbox and clear the backlog in one sitting.

The takeaway

Your email address is bought many times over, and the buyers are not who you would guess. Bulk resellers and credential-stuffing crews trade it on dark-web markets for a fraction of a cent. Data brokers, most of them legal, use it as the join key that turns scattered records into a 3,000-attribute profile. Marketers and spammers rent the result. You cannot undo a leak, but you can check where your address already sits, stop confirming that you read it, and give out fewer real copies from here on. The less your address travels, the quieter your inbox gets.

Frequently asked questions

Who buys your email address?

Several buyers, in sequence. Bulk resellers and initial-access brokers buy raw breach dumps cheaply to repackage. Credential-stuffing crews buy them to test reused passwords. Separately, licensed data brokers use your address as an identifier to build a profile, then license that to marketers and list sellers. The chain ends with spammers and advertisers who reach your inbox.

Where does your email address go after a data breach?

It gets copied, merged with older leaks, and resold. A breached address first circulates on dark-web markets among bulk resellers and credential-stuffing operators. In parallel, it feeds the legal data-broker economy, where it becomes the join key that ties scattered records into one profile. Both tracks end at the same place: more mail arriving in your inbox.

Do data brokers buy stolen email addresses?

Licensed data brokers mostly build profiles from public records, purchases, loyalty programs, and web tracking rather than criminal breach dumps, which carry legal risk. But your address is the identifier that links those records together, so the legal and criminal economies feed the same result. More than 500 data brokers are on California's public registry under its Delete Act.

How do I check if my email has been in a data breach?

Use Have I Been Pwned. Go to haveibeenpwned.com, type your address, and it lists every known breach your address appeared in, with dates and what was exposed. The service is free and does not store your address to spam it. You can also subscribe to be notified when your address turns up in a future leak.

Can you get your email address removed from data broker lists?

Partly. California residents can use DROP, the state's Delete Request and Opt-out Platform, to send one deletion request that reaches every registered data broker at once; brokers must begin honoring requests by August 1, 2026. Outside California, you opt out broker by broker. You cannot recall copies already sold, but you can stop feeding new signals.

How do spammers get my email address?

Usually by buying it, not guessing it. Your address enters circulation through a breach, a resold marketing list, or a form you filled in years ago, then changes hands across dark-web markets and list-rental brokers. A spammer buys a batch, blasts it, and any click or open you register marks your address as live, which makes it worth reselling again.

What is a data broker?

A data broker is a business that collects personal information about people from many sources and sells it to other companies, even when the person never dealt with the broker directly. They compile records into detailed profiles keyed to identifiers like your email address. The US Federal Trade Commission found one broker holding over 3,000 data segments for nearly every US consumer.

Why do I get emails from companies I never signed up for?

Because your address was sold or leaked and now travels independently of you. Once it lands on a rented marketing list or a breach dump, senders you never contacted can buy a batch that includes you. If your address has ever been flagged as live and responsive, it also gets promoted to higher-value lists and resold, which brings mail from strangers.