A shop you bought something from four years ago gets breached. You find out from a news article, or from a notification, or from nothing at all. What actually happens to your email address after that?

Not what people usually imagine. It does not leak once and settle.

The first week

The data appears somewhere private first: a small forum, a private channel, sold to a handful of buyers. At this stage it is worth money, so it is not spread around.

If the shop stored passwords badly, and many do, those get cracked in the same week. Anything using a common password, or a password that appears in an earlier breach, falls immediately. Length is what saves you here, and nothing else.

The first year

The data gets combined.

This is the part that matters and the part that is invisible. Your address from the shop breach gets matched against your address in three other breaches. Now somebody has a profile: this address, this name, this city, this password from 2019, this phone number, this employer. None of the four breaches contained all of it. Together they do.

The technical term for this is credential stuffing when it is used to log in, and enrichment when it is sold. You never see either happen.

Years later

It settles into the background. Your address ends up in the bulk lists that get resold indefinitely, and the spam that arrives is no longer connected to the original breach in any way you could trace.

By then you have no idea which shop leaked it, so you have no idea what to shut off. That is the actual damage: not the spam, the loss of the thread.

What an alias changes

Nothing about the breach. Everything about what follows.

If the shop had x7k2f@skudo.me instead of your real address, three things are different.

You know exactly who leaked it. That address was given to one shop and one shop only. When it starts receiving mail from someone else, you have learned something specific rather than something vague.

The correlation breaks. Enrichment works by matching the same address across datasets. An address used once matches nothing. The profile does not assemble.

You can end it. Switch the alias off and the mail stops at our servers. Not filtered into a folder you still have to look at: stopped, before it reaches you. Your real inbox never knew the address existed.

What to do the day you find out

Concretely, in order.

If the breached account shared a password with anything else, change those first. Not the breached one, the others. That is where the loss actually happens.

Then look at what the address was used for. If it was an alias, switch it off if you are done with that shop, or leave it if you still want their mail and just accept that it will attract some noise.

If it was your real address, there is no clean move, which is the honest answer. You cannot un-leak it. What you can do is stop the next one from being the same address: use a different one for the next shop.

The part nobody says

Aliases do not prevent breaches. They do not make you anonymous. The shop still has your name, your address, your card's last four digits, and everything else you gave them.

What they do is unpick the single thread running through all of it. Your email address is the identifier that ties every account you own to every other one, because it is the one thing every service asks for and the one thing you reuse everywhere. Cutting it into a hundred pieces does not make you invisible. It makes you unjoinable.

That is a smaller claim than most privacy tools make, and it is one we can actually keep.