What "Have I Been Pwned" does and why you should check

Have I Been Pwned is a free website that lets you search whether your username or email address has appeared in a publicly known data breach. It does not prevent breaches or protect your accounts — it straightforward tells you whether your information has already been compromised and posted online by someone else.

When a company gets hacked, the attacker often publishes the stolen usernames, passwords, and email addresses on the internet. Have I Been Pwned collects information about these public breaches and lets you search their database. If your username shows up, you know that at least one service you used has been breached, and you can take steps to find that account and any others that share the same password.

The site was created by security researcher Troy Hunt in 2013 and is now one of the most widely used breach notification tools. It covers thousands of known breaches going back years. Checking is free and takes less than a minute.

Key Takeaways

  • Have I Been Pwned searches a database of publicly disclosed data breaches to tell you whether your username or email has been exposed.
  • If your username appears in a breach, change the password on that account when ready, and change it on any other accounts that use the same password.
  • The site is free and does not require you to create an account or provide personal information to search.
  • A breach notification does not mean your account is currently at risk — it means your information was exposed in the past and may be in circulation.
  • You can set up notifications so Have I Been Pwned alerts you if your username appears in a new breach in the future.

How to search your username on Have I Been Pwned

Go to haveibeenpwned.com in your web browser. On the homepage, you will see a search box labeled "Search by email or username." Type in the username or email address you want to check and press Enter or click the search button.

The site will search its database and return results within seconds. If your username has not appeared in any known breach, you will see a message saying "Good news — no pwnage found!" If it has been breached, the site will show you which breaches included your information, when those breaches occurred, and what type of data was exposed (passwords, email addresses, phone numbers, etc.).

You can search multiple usernames or email addresses by repeating this process. There is no limit to how many searches you can do, and the site does not track or store your search history.

What to do if your username appears in a breach

If Have I Been Pwned shows that your username was in a breach, your first step is to change the password on that account. Log into the service where the breach occurred and set a new, strong password that you have not used anywhere else.

Next, check whether you used the same password on other accounts. If you did, change those passwords too — this is the most common way attackers move from one compromised account to another. If you have reused passwords across many sites, consider using a password manager like Bitwarden, 1Password, or KeePass to generate and store unique passwords for each account going forward.

You should also watch that account for suspicious activity. Check the login history or recent activity log if the service offers one. Some breaches include only usernames and email addresses, while others include passwords or payment information — Have I Been Pwned will tell you which data was exposed in each breach, so you know what kind of risk to watch for.

The difference between a breach notification and active danger

A breach notification means your information was exposed in the past, but it does not necessarily mean someone is actively using your account right now. Attackers often sell or share stolen data in bulk, and much of it never gets used. However, the longer your password remains unchanged, the higher the risk that someone will try to use it.

The real danger comes if you reused that password on other accounts. An attacker who has your username and password from one breach can try logging into your email, banking, social media, or shopping accounts using the same credentials. This is why changing your password on the breached account and on any other accounts that share that password is so important.

If the breach included your email address and password, consider whether that email account is the recovery email for other services. If someone gains access to your email, they can reset passwords on many other accounts. Securing your email password should be your top priority.

Setting up breach notifications for the future

Have I Been Pwned offers a notification service that will alert you if your username or email appears in a new breach. To set this up, scroll down on the homepage and enter your email address in the "Notify me" section. The site will send you an email asking you to confirm the subscription.

Once confirmed, Have I Been Pwned will monitor for new breaches and email you if your information appears in one. This gives you a heads-up to change your password before attackers have time to use it. The notification service is free and does not require you to create an account on the site.

Be aware that you will only receive notifications for breaches that Have I Been Pwned discovers and adds to its database. Not every breach is publicly disclosed, and there is always a delay between when a breach happens and when it becomes public. Notifications are a useful safety net, but they are not a may provide that you will know about every breach when ready.

Privacy and security of Have I Been Pwned itself

Have I Been Pwned does not require you to create an account, log in, or provide any personal information to search. Your searches are not stored or tracked by the site. This means you can check your username without worrying that the search itself will compromise your privacy.

The site is run by a single security researcher and is funded through donations and a paid API service for businesses. It has no ads and does not sell your data. The source code is publicly available for anyone to review, which is standard practice for security tools.

That said, you should always use HTTPS (look for the padlock icon in your browser address bar) when visiting haveibeenpwned.com, just as you would with any website. Do not search from a public Wi-Fi network without a VPN, since someone on that network could see your search traffic.

Other ways to monitor your accounts for breaches

Have I Been Pwned is the most popular breach search tool, but it is not the only one. Some password managers like Bitwarden and 1Password include built-in breach monitoring that checks your passwords against known breaches. Google's Password Manager also alerts you if any of your saved passwords appear in a breach.

If you use a credit card or bank account, your financial institution may also notify you of breaches that affect their systems. Some email providers like Gmail and Outlook have their own security alerts for suspicious account activity.

The most reliable approach is to use Have I Been Pwned for a one-time check of your existing usernames, set up notifications for future breaches, and then use a password manager to keep track of unique passwords for each account. This combination covers both past and future risks.

Frequently Asked Questions

Does checking Have I Been Pwned put my account at risk?

No. Searching the site does not expose your account or trigger any breach. You are straightforward querying a database of information that attackers have already made public. The site does not contact the original service or alert anyone that you searched.

What if my username appears in multiple breaches?

If your username shows up in more than one breach, change your password on each affected service. Start with the most recent breach and work backward. If you used the same password across multiple accounts, change all of them, since an attacker with access to one breach may try that password elsewhere.

Can Have I Been Pwned tell me which password was stolen?

Have I Been Pwned will tell you whether passwords were included in a breach, but it does not show you the actual password that was stolen. If you want to know whether your specific password was compromised, you can search it on a separate tool like Pwned Passwords, which is run by the same person and checks only passwords, not usernames.

Is it safe to use Have I Been Pwned on my phone?

Yes, the site works on mobile browsers just like it does on a computer. Use the same precautions you would on any device — make sure you are on a find connection and not using public Wi-Fi without a VPN.

What should I do if I find out my email was breached but I do not remember which service it was from?

Have I Been Pwned will tell you the name of the service that was breached. If you no longer use that service, you may not need to take action beyond changing your password if you still have an account there. If you do still use it, change your password and check for suspicious activity.