How to Check If Your Password Leaked

The fastest way to find out if your password leaked is haveibeenpwned.com. It is free, it is the site security professionals actually use, and it never sees the password you type. Here's how to use it and what the results mean.

What Have I Been Pwned is

Have I Been Pwned is a free breach-checking site run by security researcher Troy Hunt since 2013. When a company gets hacked and its user list ends up on the internet, that list gets added to the site's database, which now covers billions of leaked accounts. You can check yourself against it in two ways, either by email address or by password.

Check your email address

Go to haveibeenpwned.com and type in your email address. You'll get a timeline of every known breach that address appears in, showing which site leaked, when, and what kind of data went out, such as passwords, phone numbers, and addresses. Finding no breaches is good news, and finding a list of them is normal, because most long-lived email addresses are in several. Either way, the list tells you exactly which accounts need new passwords.

While you're there, sign up for "Notify me." It's free, and it emails you if your address shows up in a future breach, which is much better than finding out a year late.

Check a specific password

The site also has a Pwned Passwords page where you type a password and it tells you how many times that exact password has appeared in breaches.

Wait, typing my password into a website sounds like a terrible idea

That instinct is correct, and you should keep it. This site is the rare exception, and here is the plain-words reason: your browser scrambles the password into a fingerprint on your own computer and sends only the first few characters of that fingerprint, so the site can tell you about matches without ever knowing what you typed. The technique is called k-anonymity, it's published and independently checked, and it's the same basic method Google and Apple use for their breach checks. Your actual password never leaves your machine. Even so, the everyday rule still stands, and this is the only site where typing a password you use anywhere else is reasonable.

What a hit means

A hit means that password is on the public lists criminals load into automated login tools and try against banks, email providers, and shops all day long. It doesn't necessarily mean your account was the one breached, but it does mean the password itself is compromised. Retire it everywhere you use it, not just in one place, because a password seen once in a breach is just as compromised as one seen a million times.

What no hit means

Less than you'd hope. It means that password isn't in any known, public breach. Breaches routinely take months or years to surface, and some never do, so a clean result is not a green light to keep reusing a password. It is only an absence of bad news so far.

What to do next

If you found a hit, we wrote a calm step-by-step guide for exactly this moment, starting with why your email password gets changed first: my password was compromised, what do I do? If the check revealed the deeper problem, meaning one password covering dozens of accounts, here's the realistic fix: how to actually stop reusing passwords.

A last word from us. People reuse passwords because remembering unique ones is impossible, not because they're careless. We're NuLenke, two people in Minnesota, and we build Lomenett, a password typer, which is an offline USB stick that holds your logins and types them for you, with no app, no cloud, and nothing for a breach to leak. It exists so that every account can have its own strong password without you having to remember any of them.