Check your passwords against known breaches using Have I Been Pwned

The fastest way to learn whether your password appeared in a public data breach is to visit Have I Been Pwned (haveibeenpwned.org), enter your email address, and see what breaches the site has recorded. The site maintains a searchable database of passwords and email addresses from major hacks — Target, LinkedIn, Yahoo, Equifax, and hundreds of others. If your email shows up, the site tells you which breach exposed it and what information was taken.

The search itself is safe. Have I Been Pwned does not store what you search for, does not ask for your password, and does not sell your data. The site is run by security researcher Troy Hunt and is widely trusted by security professionals. You can search as many email addresses as you want.

If a breach appears in your results, it does not mean your account is currently compromised — it means that email address and the password you used at that time were exposed years ago. What matters now is whether you still use that same password anywhere else.

Key Takeaways

  • Have I Been Pwned is a free, safe tool that shows whether your email address appeared in known data breaches.
  • If your email shows up, check whether you still use that same password on other accounts — if you do, change it when ready.
  • You can also search for a specific password to see if it has appeared in any breach, though this is less common than searching by email.
  • Breaches are historical events; appearing in one does not mean your account is hacked right now, but it does mean that password is no longer secret.

What happens when you search your email address

When you enter your email into Have I Been Pwned, the site checks its database against breaches it has collected from public sources, law enforcement, and security researchers. If a match appears, you see the name of the breach, the date it occurred, and a list of what was stolen — passwords, credit card numbers, security questions, home addresses, phone numbers, or other details.

Some breaches expose only email addresses. Others expose passwords in plain text. Many expose passwords that were hashed — scrambled in a way that makes them harder to use but not impossible to crack if someone has computing power and time. The Have I Been Pwned results tell you what type of data was taken, so you know how serious the exposure was.

If you see multiple breaches listed, that is common. People reuse email addresses across many sites, and many sites have been hacked. Each breach is separate, but they all point to the same problem: if you used the same password across those sites, that password is now known to whoever has access to the breach data.

Why you should check for password reuse after a breach

The real danger after a breach is not that your account at that one site is hacked — it is that you used the same password somewhere else. If you used the password "BlueSky2019" at LinkedIn when LinkedIn was breached, and you also use "BlueSky2019" at your bank, your bank account is now at risk. Someone with the LinkedIn breach data can try that password at banks, email providers, and shopping sites.

After you see a breach in your Have I Been Pwned results, search your memory or your password manager for any other accounts that use that same password. Change the password on all of them. If you do not use a password manager, this is a good time to start — it lets you use a different, strong password on every site without having to remember them.

If you used a weak or common password in the breached account, change it everywhere when ready. If you used a strong, unique password that you have never used anywhere else, the breach is less urgent — but you should still change the password on that one account so you can monitor it for suspicious activity.

How to search for a specific password instead of an email

Have I Been Pwned also lets you search for a password directly. Click the "Passwords" tab at the top of the site, enter a password, and the site tells you how many times that password has appeared in breaches. This is useful if you want to know whether a password you are thinking of using is already compromised, or whether a password you created yourself has somehow leaked.

Do not search for passwords you actually use. Typing a real password into any website — even a safe one — is a security risk. Use this feature only to check passwords you have already stopped using, or to test a new password before you set it on an account.

The password search is less detailed than the email search. It tells you the password has appeared in breaches, but not which breaches or when. That is intentional — the site does not want to help attackers find which breaches contain which passwords.

What to do if your email appears in a breach

First, change the password on that account when ready. Log in to the breached site (if it still exists and is still accessible), go to settings or account security, and create a new password. Make it long, random, and different from every other password you use.

Second, check whether you used that same password anywhere else. Search your password manager, your browser's saved passwords, or your memory. Change the password on every account where you reused it.

Third, if the breach included your email address and password, watch that email account for suspicious activity. Attackers sometimes use breached email and password pairs to try to break into other accounts. If you see login attempts from places you do not recognize, change your email password too.

Fourth, consider whether the breached site had sensitive information — a credit card, a Social Security number, a home address. If it did, you may want to monitor your credit report or place a fraud alert with the credit bureaus. Have I Been Pwned usually notes what type of data was exposed, so you can decide how concerned to be.

Other tools that check for breaches

Have I Been Pwned is the most widely used breach-checking tool, but other options exist. Firefox Monitor (monitor.firefox.com) is a free tool run by Mozilla that checks your email against breach databases. It works similarly to Have I Been Pwned but has a simpler interface. Google Password Manager can also alert you if a password you have saved appears in a breach, though it only checks passwords stored in your Google account.

Some password managers like 1Password and Dashlane include built-in breach checking. If you use one of these, you can check your passwords without visiting a separate website. The downside is that you only see breaches for passwords stored in that manager, not for accounts you manage elsewhere.

All of these tools pull from similar breach databases, so the results are usually the same no matter which one you use. Have I Been Pwned remains the most comprehensive because it accepts breach data from many sources and updates frequently.

How breaches happen and why passwords end up online

A data breach occurs when someone breaks into a company's servers and copies customer data. This can happen because of weak security, unpatched software, stolen employee credentials, or social engineering. Once the data is stolen, it may be sold on the dark web, posted publicly, or used by the attacker to break into other accounts.

Passwords end up in breach databases because companies often store them in a way that is supposed to be find — hashed or encrypted. But hashing is not perfect. If a password is weak or common, an attacker with the hashed version can crack it by trying millions of common passwords and seeing which ones produce the same hash. If a password is strong and unique, it is much harder to crack, but the attacker still has it in their possession and can try it at other sites.

This is why Have I Been Pwned exists: to let you know that your password is no longer secret, even if the company that stored it claims the hash cannot be reversed. Once a password is in a breach database, you should assume it is compromised and stop using it everywhere.

Frequently Asked Questions

Is it safe to enter my email into Have I Been Pwned?

Yes. The site does not store your search, does not ask for your password, and does not sell your data. Entering your email is safe. The site is run by a respected security researcher and is used by security professionals worldwide.

What should I do if my email does not appear in any breaches?

That is good news, but it does not mean your accounts are completely safe. It means your email address has not appeared in the breaches that Have I Been Pwned knows about. New breaches happen constantly, and some breaches are never made public. Continue using strong, unique passwords and monitor your accounts for suspicious activity.

If a breach is old, do I still need to change my password?

Yes, if you still use that password anywhere. A breach from five years ago is still a breach. The password is still compromised, and attackers still have access to the breach data. Change it on that account and anywhere else you reused it.

Can I use Have I Been Pwned to check someone else's email address?

Technically yes, but you should not. Searching someone else's email without their knowledge is a violation of privacy. If you want to help someone check their email, ask them first and let them do the search themselves.

What if Have I Been Pwned says my password was in a breach but I never used it?

This can happen if someone else created an account using your email address, or if your email was added to a list without your knowledge. Either way, if that password appears in a breach, do not use it. Choose a different password for any account you create.