Check your password against known breaches using Have I Been Pwned
The fastest way to learn about your password appeared in a public data breach is to use Have I Been Pwned (haveibeenpwned.com), a free website that searches a database of over 600 million compromised passwords. You type in your password once, and the site tells you whether it has shown up in any known breach. The search happens on your device — the site does not store what you enter.
Go to haveibeenpwned.com, click the "Passwords" tab at the top, paste your password into the box, and click the search button. If the site says "Good news — no pwnage found," your password has not appeared in any breach they track. If it says "Oh no — pwned," the password has been exposed and you should change it when ready on every account where you use it.
The site also lets you check your email address instead of your password. Click the "Notify" tab, enter your email, and the site will tell you if that email was part of any known breach. This is useful if you want to check without typing a password into any website, even a trusted one.
Key Takeaways
- Have I Been Pwned is a free tool that checks whether your password or email address appeared in a known data breach.
- If your password shows up as breached, change it on every account where you use that same password.
- A breached password does not mean someone has already accessed your account — it means the password is now public and anyone could try it.
- You can also set up breach notifications so the site emails you if your email address appears in a future breach.
- Passwords that appear in breaches are usually old ones; if you have already changed your password since the breach date, your account is already safer.
What happens when a password is leaked
When a company gets hacked, attackers often steal the password database along with usernames and email addresses. Those passwords are then posted online or sold, and security researchers add them to breach databases. Your password being in that database does not mean someone has used it yet — it means it is now public information that anyone can read and try.
Attackers use leaked passwords in two ways. First, they try the password on the same account it came from — if you used the same password on your email, bank, or social media, they might get in there too. Second, they try the password on other sites, betting that people reuse passwords across multiple accounts. This is why changing a breached password everywhere you used it matters more than changing it on just one account.
The date the breach occurred is usually different from the date you find out about it. A breach might have happened years ago but only become public recently. If you have already changed your password since the breach date, your account is already protected — the old leaked password no longer works.
How to change passwords after a breach
Once you know a password was breached, change it on every account where you use that password. Start with the most important ones: email, banking, and any account tied to payment methods. Then work through social media, work accounts, and other services.
When you create a new password, make it different from the old one and different from passwords on other accounts. A password manager like Bitwarden, 1Password, or KeePass can generate strong passwords and store them so you do not have to remember them. If you do not use a password manager, aim for at least 12 characters mixing uppercase, lowercase, numbers, and symbols.
If you used the same breached password on many accounts, you do not have to change them all in one day. Prioritize based on what matters most: accounts with payment information first, then email and social media, then everything else. Most people can work through the list over a week without much trouble.
Set up breach notifications so you know when ready
Have I Been Pwned offers a free notification service. Enter your email address on the "Notify" tab, and the site will email you if that address appears in any future breach they discover. This means you will know within days of a breach becoming public, rather than finding out months or years later.
The notification service does not require you to check the site repeatedly. You just get an email when something happens. You can set up notifications for multiple email addresses if you use different ones for different accounts.
Other password managers like Bitwarden and 1Password also include breach monitoring. If you use one of those, the tool will alert you when it detects that a password in your vault has appeared in a breach. This is convenient because the alert appears right where you store your passwords.
Why you should not rely on the site telling you about old breaches
Have I Been Pwned is comprehensive for breaches that have been publicly reported or shared with the site's creator, Troy Hunt. But not every breach becomes public. Some companies discover a breach, fix it quietly, and never announce it. Others get hacked but do not realize it for months. This means a password could have been stolen without appearing in Have I Been Pwned's database.
The site is still the best free tool available, and checking it is worth doing. But a clean result does not mean your password is definitely safe — it means it has not appeared in any breach that Hunt has collected. If you have used the same password for years, or if you reuse it across many accounts, changing it anyway is reasonable.
If you have ever received a notification from a company saying your account was compromised, change that password when ready regardless of what Have I Been Pwned says. The company's own notification is more reliable than any third-party database.
What to do if your email was breached but you do not know the password
If Have I Been Pwned shows your email address in a breach but you do not know which password was stolen, you have two options. First, you can change the password on that account right now — go to the site where you have the account, use the "Forgot Password" link, and set a new one. You do not need to know the old password to do this.
Second, you can check the breach details on Have I Been Pwned to see what information was stolen. Click on the breach name to see what data the attackers got — sometimes it was just your email and username, sometimes it included passwords, phone numbers, or security questions. If only your email was exposed, changing your password is still a good idea but less urgent than if your password was also stolen.
Frequently Asked Questions
Is it safe to type my password into Have I Been Pwned?
Yes. The site uses a technique called k-anonymity where it only sends the first five characters of your password's hash to its servers, never the full password. The search happens on your device. You can also read the site's password list and search it offline if you want to avoid sending anything to the internet.
What if Have I Been Pwned says my password was pwned but I just created it?
This usually means the password is a common one that has appeared in many breaches. Passwords like "password123" or "qwerty" show up in breach databases even though millions of people create them independently. Switch to a longer, less common password using a password manager.
Do I need to change my password if the breach happened years ago?
If you have already changed your password since the breach date, your account is already protected. If you have not changed it, change it now. Check the breach date on Have I Been Pwned to see when it happened.
What should I do if my password was breached on a site I no longer use?
If you still have an account there, change the password anyway — attackers sometimes use old breached passwords to access dormant accounts and use them for spam or fraud. If you do not use the account anymore, consider deleting it instead. If you used that same password elsewhere, change it on those accounts too.
Can I get my password removed from Have I Been Pwned?
No. The site does not remove passwords from its database because the goal is to help people learn about their passwords were breached. The password is already public from the original breach; removing it from Have I Been Pwned would not make it private. The solution is to stop using that password.