FREE TOOL · CHECKS AGAINST 800M+ LEAKED PASSWORDS

Password Breach Checker

See if a password has already turned up in a known data breach — using the same privacy-preserving method built into Firefox and Chrome. Your actual password is never sent anywhere.


VERIFIED METHOD

Only a tiny hash fragment is ever sent — never your actual password. This tool computes a SHA-1 hash of your password in your browser, then sends only the first 5 characters of that hash to check for a match. This technique is called k-anonymity — it's the same method used by Firefox Monitor, Chrome's password checkup, and 1Password.

Test a password
Result

What counts as "leaked"?

A match means this exact password has appeared in at least one publicly known data breach — meaning it's already in the hands of attackers and being tried automatically against other accounts. Even a "strong-looking" password can be leaked if it's ever been used on a site that was breached. If your password shows up here, change it everywhere you've reused it.

Why this is different from the Password Strength Checker

Strength and leaked status are two different things. A short, common password is usually both weak and leaked. But a long, complex password can still be leaked if it's ever appeared in a breach — strength alone doesn't protect you once a password is publicly known. Use both tools together for the full picture.

Breach data provided by Have I Been Pwned, used under Creative Commons Attribution 4.0.

How Breach Checking Works Without Sending Your Password Anywhere

This tool uses a privacy-preserving technique: it checks only a fragment of the password’s fingerprint against a local database of breach hashes. Your password is never transmitted, logged, or stored — the entire comparison happens inside your browser. That design matters, because typing a real password into a random website’s “breach checker” is exactly how passwords get stolen.

What to Do If Your Password Shows Up

The Rule That Makes Breaches Harmless

Credential-stuffing attacks succeed because people reuse passwords. If every account has its own password, a breach of any single service stays confined to that service — annoying, but not catastrophic. Uniqueness is the cheapest, highest-impact security upgrade that exists.

What a data breach actually means for you

When a company is breached, attackers usually walk away with a database table: email addresses, usernames, and scrambled versions of passwords called hashes. Depending on how carelessly that company stored them, those hashes range from effectively uncrackable to trivially reversible. Older sites that used fast algorithms such as unsalted MD5 can have most of their passwords recovered within hours.

The recovered pairs then get traded, combined with pairs from other breaches, and fed into automated tools. Those tools try your email and password against hundreds of other services — banks, email providers, shopping sites, streaming accounts. This is credential stuffing, and it is the single most common way ordinary people lose accounts. It does not require anyone to target you personally. It is industrial, automated, and constant.

The consequence is worth stating plainly: a breach at a forum you joined in 2013 and forgot about can cost you your email account today, if you used the same password in both places.

How breach checking works without exposing your password

Reputable breach-checking services never receive your password. They use a method called k-anonymity. Your browser hashes the password locally, sends only the first five characters of that hash, and receives back every known leaked hash that begins with those five characters — often several hundred of them. Your browser then does the final comparison on your own device.

The service therefore learns that somebody asked about one of a few hundred possible passwords, and nothing more. It cannot tell which, cannot tell who, and never holds the password itself. It is a genuinely elegant piece of design, and it is why breach checking can be done safely at all.

Reading your result

Found in a breach. This does not mean your account was hacked. It means this exact password appears somewhere in the corpus of leaked passwords, so it is now in every attacker's first-guess list. Stop using it everywhere it appears, starting with your email and anything financial.

Not found. This does not mean the password is strong. It means it has not turned up in a known public leak. A password can be absent from every breach list and still be guessed in seconds if it is short or predictable. Run it through our password strength checker as well.

What to do if your password shows up

  1. Start with your email account. Whoever controls your email can reset most of your other accounts, which makes it the master key. Change it first, to something long and unique.
  2. Then anything holding money. Banking, payment apps, anywhere a card is saved.
  3. Then everywhere you reused it. Be honest about the list. Most people reuse more widely than they remember.
  4. Turn on two-factor authentication on each account as you go. Our two-factor setup guide walks through the options and which are worth using.
  5. Check the active sessions and recovery settings on your email: look for forwarding rules, filters, recovery phone numbers or backup email addresses you did not add. Attackers routinely add a quiet forwarding rule so they keep receiving your reset codes long after you change the password.

Living with breaches sensibly

You cannot prevent a company you use from being breached. What you control is the blast radius. Unique passwords everywhere means one breach costs you one account. Two-factor authentication means a leaked password on its own is not enough to get in. A password manager makes both of these practical rather than aspirational.

It is also worth signing up for breach notifications with your main email address so you hear about incidents when they are disclosed rather than months later. And treat any email claiming "your password was found in a breach, click here" with suspicion — that framing is itself one of the most common phishing hooks. Go to the service directly instead of clicking.


Frequently asked questions

Does a breach result mean someone has my account?

Not necessarily. It means the password appears in leaked data, so it is in attackers' guess lists. Whether anyone has tried it against your specific accounts is a separate question. Treat it as a password that must be retired everywhere.

Is my password sent anywhere when I check it?

No. Only a short prefix of a hash leaves your browser, and the final comparison happens on your device. The service cannot determine which password you asked about.

How often should I check?

Once when you first set a password, and again if you hear about a breach at a service you use. If you use unique passwords everywhere and a password manager, most managers monitor this for you automatically.

A password I never used anywhere shows as breached. Why?

Breach lists contain passwords, not accounts. If somebody else, anywhere in the world, ever chose the same password and their service was breached, that password is on the list. Common and pattern-based passwords are almost all on it already.

What should I do first if several of my passwords are breached?

Your email account, without exception. It can be used to reset almost everything else you own. Secure it with a long unique passphrase and two-factor authentication, then work outward to financial accounts and then everything else.