Password Breach Checker

关于 Password Breach Checker

Our free Password Breach Checker tells you whether a password has ever appeared in a known data breach, using the Have I Been Pwned Pwned Passwords database of hundreds of millions of exposed passwords.


Your password is never sent anywhere. It's hashed in your browser (SHA-1), and only the first 5 characters of that hash are sent to Have I Been Pwned's k-anonymity API to check for a match - the full hash and password never leave your device.


Your password is hashed in your own browser and never transmitted - only the first 5 characters of the hash are sent to check for a match (a privacy technique called k-anonymity), so your actual password stays private.

Frequently asked questions

Is my password sent to your server?

No. The password is hashed (SHA-1) directly in your browser using the Web Crypto API. Only the first 5 characters of that hash are sent to the Have I Been Pwned API - a technique called k-anonymity - so neither we nor Have I Been Pwned ever see your actual password.

What does it mean if my password was found?

It means that exact password has appeared in at least one known data breach and is in wordlists attackers commonly use for credential-stuffing attacks. Change it immediately, especially anywhere else you've reused it.

Where does the breach data come from?

Have I Been Pwned's Pwned Passwords database, which aggregates hundreds of millions of passwords exposed in real, confirmed data breaches.

搜索工具