Check your password against known breaches in seconds

You can learn about your password appears in a known data breach by entering it into Have I Been Pwned (haveibeenpwned.com), a free database that collects passwords from publicly disclosed breaches. The site checks your password against millions of compromised credentials without storing what you type. If your password shows up, change it when ready on any account where you use it — the same password on multiple sites means one breach exposes all of them.

The check takes about 10 seconds and requires nothing but your password. You do not need to create an account, pay a fee, or provide your email address. The site was built by security researcher Troy Hunt specifically so people could check without risk.

Key Takeaways

  • Have I Been Pwned lets you search your password against millions of breached credentials for free, with no account required.
  • If your password appears in a breach, change it on every account where you use that same password, starting with email and banking.
  • A leaked password does not mean your account is currently compromised — it means someone has that password from an old breach and might try it.
  • Use a password manager to create unique passwords for each site so one breach cannot expose multiple accounts.
  • Check your email address separately on Have I Been Pwned to see which breaches included your account, even if the password was not leaked.

Why a leaked password matters even if you changed it

When a password leaks, attackers get a list of real passwords paired with real email addresses. They test those combinations on other sites — your email plus your old password on Netflix, on your bank, on PayPal. If you still use that password anywhere, they get in. If you changed it only on one site, they get into the others.

The breach itself is usually old. Have I Been Pwned includes breaches from 2012 and earlier. But attackers keep using old password lists because people reuse passwords. A password that leaked five years ago is still dangerous if you have not changed it.

How to search your password safely

Go to haveibeenpwned.com and look for the section labeled "Check if your password has been pwned". Type your password into the box and click the button. The site checks it against its database and tells you how many times that exact password appears in known breaches — usually a number between 0 and several thousand.

The site does not store your password, log it, or send it to a server in a way that records it. The search happens through a system called k-anonymity that breaks your password into pieces, sends only part of it, and matches the rest locally on your device. You can read the technical details on their site if you want to verify how it works.

If the result is 0, your password has not appeared in any known breach. If it is higher than 0, change that password on every account where you use it. Start with email, banking, and any account tied to payment methods, because those are what attackers target first.

What to do if your password was leaked

Change the password on every account where you use it. If you use the same password on 10 sites, you need to change it on all 10. Write down which sites use that password if you are not sure — check your browser's saved passwords by going to Settings > Passwords (on Chrome or Edge) or Preferences > Passwords (on Safari).

Make each new password different. A password manager like Bitwarden, 1Password, or Dashlane generates strong unique passwords and remembers them for you, so you only have to remember one master password. If you do not use a password manager, create passwords that are at least 12 characters long and mix uppercase, lowercase, numbers, and symbols.

After you change your passwords, check your email address on Have I Been Pwned separately. Search the "Check if your email has been pwned" section to see which breaches included your account. This tells you which companies had your data, even if the password itself did not leak. You may want to enable two-factor authentication on those accounts for extra protection.

Check your email address for breaches too

Enter your email address into the "Check if your email has been pwned" section on Have I Been Pwned. The site shows you every known breach that included that email. You might see 5 breaches, 15 breaches, or none. The number depends on how long you have used that email and which services you have signed up for.

If your email appears in a breach, it does not automatically mean your password was exposed — some breaches only steal email addresses and usernames. But it does mean someone has your email on a list. Attackers use email lists to send phishing messages or to test passwords they have from other breaches.

If you see your email in many breaches, consider changing your email address on accounts that matter most: banking, email itself, and any account with payment information. You do not have to change it everywhere, but the accounts where money is involved are worth the effort.

Set up breach monitoring so you know when new leaks happen

Have I Been Pwned offers a free notification service. Enter your email address on the site and click "Notify me" to get an email alert if that address appears in a new breach. You do not need to check manually every month — the site watches for you and tells you when something new happens.

The notification is free and comes from Troy Hunt's site directly. You will not get spam or marketing emails. If you want to stop notifications, you can unsubscribe from any alert email.

Other ways to protect yourself after a password leak

Turn on two-factor authentication on accounts that support it. Two-factor means even if someone has your password, they cannot get in without a second thing — usually a code from your phone. Banks, email providers, and social media sites all offer it. It takes a few minutes to set up and stops most account takeovers.

Use a password manager so every account has a different password. If one site gets breached, only that one password is exposed. A password manager also fills in passwords for you, so you do not have to type them and risk someone watching your screen.

Check your account activity on sites where you have been breached. Look for logins from places you do not recognize or changes you did not make. Most email and banking sites show you a list of recent logins and let you sign out of sessions remotely.

Frequently Asked Questions

Is it safe to type my real password into Have I Been Pwned?

Yes. The site uses a system that does not store or log your password. It breaks your password into pieces and only sends part of it to the server, so the full password never travels across the internet in a way that can be recorded. You can read their technical explanation if you want to verify how it works before you use it.

What if my password shows up in a breach but I do not remember using it?

Someone may have created an account in your name, or you may have signed up for a service years ago and forgotten about it. Search your email for password reset messages or account confirmations from that time period. If you find an account you do not use, delete it or change its password.

Do I need to change my password if it was leaked but I have not used it in years?

Only if you still use it on another account. If the leaked password is old and you have already changed it everywhere, you do not need to do anything. But if you use it anywhere now, change it on that account when ready.

Can Have I Been Pwned tell me which company leaked my password?

No. Have I Been Pwned shows you which breaches included your email address, but it cannot tell you which company leaked a specific password. Passwords in breaches are usually mixed together from multiple sources. You can see which companies had your email by searching your email address on the site.

What should I do if my email address appears in hundreds of breaches?

That usually means you have used that email for a long time or signed up for many services. It does not mean your accounts are all compromised right now. Focus on the accounts that matter most — email, banking, and payment sites — and make sure they have strong unique passwords and two-factor authentication turned on.