Check your username against known breaches using Have I Been Pwned

The fastest way to find out whether your username appears in a known data breach is to visit Have I Been Pwned (haveibeenpwned.com), a free database maintained by security researcher Troy Hunt. Type your username or email address into the search box. The site will tell you whether that name appears in any of the breaches it has catalogued — currently over 700 breaches affecting more than 13 billion accounts.

The search takes seconds and costs nothing. Have I Been Pwned does not store what you search for, does not require you to create an account, and does not sell your information. It is one of the most reliable sources for this type of check because Hunt works directly with law enforcement and security researchers to add newly discovered breaches to the database.

If your username shows up, the site will list which breaches included it and what type of data was exposed — passwords, email addresses, phone numbers, or other details. This tells you which accounts to prioritize for password changes and which services to monitor for suspicious activity.

Key Takeaways

  • Have I Been Pwned is a free, reputable tool that searches over 700 known data breaches to see if your username or email appears in any of them.
  • The search results show you which specific breaches exposed your information and what data types were included in each one.
  • If your username appears in a breach, change the password for that account when ready, especially if you use the same password elsewhere.
  • You can set up breach notifications on Have I Been Pwned so the site emails you if your username appears in a newly discovered breach.
  • A breach showing your username does not mean your account is currently compromised — it means your information was exposed at some point in the past.

What happens when a breach includes your username

When a company suffers a data breach, attackers gain access to whatever data that company stored about you. If your username was part of that breach, it is now in the hands of people who should not have it. What they can do with it depends on what else was exposed alongside it.

If only your username was taken, the risk is moderate — someone could use it to guess at your accounts on other sites or to send you targeted phishing emails. If your password was also exposed, the risk is much higher, because attackers will try that username-and-password combination on every major website (a technique called credential stuffing). If your username, password, and recovery email were all exposed, an attacker could potentially lock you out of your own account.

The breach itself is not your fault. You cannot prevent a company from being hacked. What you can control is how quickly you respond once you know your username is in a breach.

Steps to take after finding your username in a breach

First, change the password for the breached account when ready. Make it long, random, and different from every other password you use. If you used the same password on other sites, change those too — this is the main reason attackers collect breached passwords, and credential stuffing attacks happen within hours of a breach becoming public.

Second, check the breach details on Have I Been Pwned to see what data was exposed. If your password was included, treat it as compromised everywhere. If only your username was exposed, focus on the accounts where that username is most valuable — email, banking, social media, and work accounts.

Third, turn on two-factor authentication (2FA) for the breached account if it is not already on. This means that even if someone has your password, they cannot log in without a second form of verification — usually a code from your phone. Most major services offer this: Gmail, Facebook, Microsoft, Apple, Amazon, and most banks.

Fourth, monitor that account for suspicious activity for the next few months. Watch for login notifications from places you do not recognize, unexpected password reset emails, or charges you did not make. If you see something odd, change your password again and contact the company's support team.

Why Have I Been Pwned is trustworthy

Have I Been Pwned has become the standard tool for breach checking because Troy Hunt operates it transparently and updates it constantly. He publishes detailed information about each breach, including when it happened, what company was affected, and what data was exposed. He works with law enforcement, security researchers, and the companies themselves to verify breaches before adding them to the database.

The site is free and does not require registration. It does not track you, does not sell your data, and does not use your searches for marketing. Hunt has been doing this work since 2013 and has built a reputation for accuracy and integrity in the security community.

Other breach-checking tools exist, but many require you to create an account or pay for premium features. Have I Been Pwned remains the most widely used because it is free, fast, and reliable.

Setting up notifications for future breaches

Have I Been Pwned offers a notification feature that emails you if your username appears in a newly discovered breach. To set this up, enter your email address on the site's "Notify Me" page and confirm the email address. From then on, if your username shows up in a breach that Hunt adds to the database, you will receive an email alert.

This is useful because new breaches are discovered regularly, and you may not think to check Have I Been Pwned again for months. The notification means you will know within days if your username appears in a new breach, giving you time to change your password before attackers can use it.

The notification is optional — you can check Have I Been Pwned once and never return, or you can set up alerts and check periodically. Either way, the information is there if you need it.

Other places to check for breaches

Have I Been Pwned is the most comprehensive, but other tools exist. Firefox Monitor (monitor.firefox.com) is a free service run by Mozilla that checks breaches and offers password information. Google's Password Manager will notify you if a password you have saved is found in a breach. Microsoft's account security dashboard shows if your Microsoft account has been compromised.

These tools pull from similar breach databases, so they often show the same results. The advantage of checking multiple sources is that they do not all add breaches at the same time — a newly discovered breach might appear on Have I Been Pwned before it reaches Firefox Monitor, or vice versa. If you want the most current information, checking Have I Been Pwned first is usually sufficient.

What a breach does not tell you

Finding your username in a breach is not the same as finding your account actively compromised right now. A breach can be years old. The attackers who stole the data may have moved on. The password they have may have been changed since the breach. The account may have additional security layers now that did not exist when the breach happened.

A breach is a warning sign, not a crisis. It tells you that your information was exposed at some point and that you should take action to protect yourself going forward. It does not mean your account is currently being used by someone else or that your money is being stolen. It means you need to change your password, turn on 2FA, and stay alert.

Frequently Asked Questions

Is Have I Been Pwned safe to use?

Yes. The site does not store your search history, does not require an account, and does not track you. Troy Hunt is a respected security researcher, and the site has been audited by security professionals. Entering your username or email is safe.

What should I do if my username is in multiple breaches?

Change the password for that account once, and make it strong and unique. You do not need to change it multiple times for multiple breaches. Focus on turning on two-factor authentication and monitoring the account for suspicious activity. If the password was exposed in any of the breaches, treat it as compromised everywhere you used it.

Can I remove my username from Have I Been Pwned?

No, and you should not want to. Have I Been Pwned is a historical record of breaches that have already happened. Removing your entry would not remove your information from the attackers' hands — it would only hide the fact that you were exposed. The point of the database is to help you know what happened so you can protect yourself.

What if Have I Been Pwned says my username was not in any breach?

That is good news, but it does not mean your account is completely safe. It means your username has not appeared in any of the breaches Hunt has catalogued so far. New breaches are discovered regularly, so check back periodically or set up notifications. Also, not every breach makes it into the database when ready.

Should I change my password even if only my username was exposed?

If only your username was exposed and your password was not, changing your password is not urgent. However, if you use the same password on multiple sites, change it everywhere. If your password is old or weak, change it regardless. The safest approach is to assume that any breach is a sign to review your account security.