See if a password has already turned up in a known data breach — using the same privacy-preserving method built into Firefox and Chrome. Your actual password is never sent anywhere.
Only a tiny hash fragment is ever sent — never your actual password. This tool computes a SHA-1 hash of your password in your browser, then sends only the first 5 characters of that hash to check for a match. This technique is called k-anonymity — it's the same method used by Firefox Monitor, Chrome's password checkup, and 1Password.
A match means this exact password has appeared in at least one publicly known data breach — meaning it's already in the hands of attackers and being tried automatically against other accounts. Even a "strong-looking" password can be leaked if it's ever been used on a site that was breached. If your password shows up here, change it everywhere you've reused it.
Strength and leaked status are two different things. A short, common password is usually both weak and leaked. But a long, complex password can still be leaked if it's ever appeared in a breach — strength alone doesn't protect you once a password is publicly known. Use both tools together for the full picture.
Breach data provided by Have I Been Pwned, used under Creative Commons Attribution 4.0.
This tool uses a privacy-preserving technique: it checks only a fragment of the password’s fingerprint against a local database of breach hashes. Your password is never transmitted, logged, or stored — the entire comparison happens inside your browser. That design matters, because typing a real password into a random website’s “breach checker” is exactly how passwords get stolen.
Credential-stuffing attacks succeed because people reuse passwords. If every account has its own password, a breach of any single service stays confined to that service — annoying, but not catastrophic. Uniqueness is the cheapest, highest-impact security upgrade that exists.
When a company is breached, attackers usually walk away with a database table: email addresses, usernames, and scrambled versions of passwords called hashes. Depending on how carelessly that company stored them, those hashes range from effectively uncrackable to trivially reversible. Older sites that used fast algorithms such as unsalted MD5 can have most of their passwords recovered within hours.
The recovered pairs then get traded, combined with pairs from other breaches, and fed into automated tools. Those tools try your email and password against hundreds of other services — banks, email providers, shopping sites, streaming accounts. This is credential stuffing, and it is the single most common way ordinary people lose accounts. It does not require anyone to target you personally. It is industrial, automated, and constant.
The consequence is worth stating plainly: a breach at a forum you joined in 2013 and forgot about can cost you your email account today, if you used the same password in both places.
Reputable breach-checking services never receive your password. They use a method called k-anonymity. Your browser hashes the password locally, sends only the first five characters of that hash, and receives back every known leaked hash that begins with those five characters — often several hundred of them. Your browser then does the final comparison on your own device.
The service therefore learns that somebody asked about one of a few hundred possible passwords, and nothing more. It cannot tell which, cannot tell who, and never holds the password itself. It is a genuinely elegant piece of design, and it is why breach checking can be done safely at all.
Found in a breach. This does not mean your account was hacked. It means this exact password appears somewhere in the corpus of leaked passwords, so it is now in every attacker's first-guess list. Stop using it everywhere it appears, starting with your email and anything financial.
Not found. This does not mean the password is strong. It means it has not turned up in a known public leak. A password can be absent from every breach list and still be guessed in seconds if it is short or predictable. Run it through our password strength checker as well.
You cannot prevent a company you use from being breached. What you control is the blast radius. Unique passwords everywhere means one breach costs you one account. Two-factor authentication means a leaked password on its own is not enough to get in. A password manager makes both of these practical rather than aspirational.
It is also worth signing up for breach notifications with your main email address so you hear about incidents when they are disclosed rather than months later. And treat any email claiming "your password was found in a breach, click here" with suspicion — that framing is itself one of the most common phishing hooks. Go to the service directly instead of clicking.
Not necessarily. It means the password appears in leaked data, so it is in attackers' guess lists. Whether anyone has tried it against your specific accounts is a separate question. Treat it as a password that must be retired everywhere.
No. Only a short prefix of a hash leaves your browser, and the final comparison happens on your device. The service cannot determine which password you asked about.
Once when you first set a password, and again if you hear about a breach at a service you use. If you use unique passwords everywhere and a password manager, most managers monitor this for you automatically.
Breach lists contain passwords, not accounts. If somebody else, anywhere in the world, ever chose the same password and their service was breached, that password is on the list. Common and pattern-based passwords are almost all on it already.
Your email account, without exception. It can be used to reset almost everything else you own. Secure it with a long unique passphrase and two-factor authentication, then work outward to financial accounts and then everything else.