Where to check if your password was leaked

The fastest way to check if your password appears in a known data breach is to use Have I Been Pwned (haveibeenpwned.com), a free website that searches a database of hundreds of millions of leaked passwords and email addresses. You enter your email address, and the site tells you whether that address has shown up in any public breaches.

Other services that do the same thing include Firefox Monitor (monitor.firefox.com), which is run by Mozilla, and Google Password Manager's built-in breach detection. Each searches different databases and may find different breaches, so checking more than one gives you a more complete picture.

These tools do not store your password or email — they only search existing records of breaches that have already been made public. If a breach has not been publicly disclosed or added to their database, these tools will not find it.

Key Takeaways

  • Have I Been Pwned is the most widely used free tool for checking whether your email address appears in known data breaches.
  • These tools search only breaches that have already been publicly disclosed, so a negative result does not mean your information is completely safe.
  • If your password is found in a breach, change it immediately on that website and on any other site where you use the same password.
  • You can set up notifications so these services alert you if your email appears in a new breach in the future.

How to use Have I Been Pwned

Go to haveibeenpwned.com. In the text box labeled "Enter your email address", type the email address you want to check. Click the "pwned?" button or press Enter.

The site will either tell you "Good news — no pwnage found!" or show you a list of breaches where that email address has appeared. For each breach, you will see the name of the company or service, the date the breach occurred, and what types of information were exposed (passwords, email addresses, credit card numbers, and so on).

You can also check a password directly on Have I Been Pwned by clicking the "Passwords" tab at the top. Type in a password you use, and the site will tell you how many times that exact password has appeared in breaches. This is useful if you want to know whether a password you have been using is compromised, even if you are not sure which breach it came from.

What to do if your password was found in a breach

If your email address or password appears in a breach, change that password immediately on the website where it was exposed. Do not wait — attackers often try leaked passwords on other popular sites to see if they work.

If you use the same password on multiple websites, change it on all of them. This is why security experts recommend using a different password for every important account. If you do not already use a password manager, this is a good time to start — services like Bitwarden, 1Password, or the password manager built into your browser can generate and store unique passwords for each site.

Check your account activity on the breached site if possible. Look for logins from places you do not recognize or changes to your account settings. If you see suspicious activity, change your security questions and recovery email address as well.

How to set up breach notifications

Have I Been Pwned lets you sign up for notifications so you are alerted if your email address appears in a new breach. Click "Notify me" on the results page after you search your email, or go to the "Notifications" section of the site. You will need to confirm your email address by clicking a link in a confirmation email.

Firefox Monitor also offers notifications. After you search your email on monitor.firefox.com, you can create a free Firefox account and opt in to alerts. Google Password Manager checks your passwords automatically if you are signed into a Google account and will show you a warning in your browser if any of your saved passwords appear in a breach.

These notifications are useful because new breaches are discovered and added to public databases regularly. A password that was safe last month might appear in a newly disclosed breach this month.

Understanding what "pwned" means

Pwned is internet slang for "owned" or compromised. When a website or service is hacked and user data is stolen, the data often ends up in public databases or is sold on the dark web. Security researchers collect these breaches and add them to searchable databases so people can check whether their information was exposed.

A breach does not always mean your password was stolen in plain text. Sometimes only email addresses were exposed, or passwords were encrypted in a way that makes them harder to use. Have I Been Pwned shows you what type of data was exposed in each breach so you know what information is at risk.

Being in a breach does not mean someone has already used your information. It means your data is now in a pool of millions of exposed records that attackers can attempt to use. Changing your password and monitoring your account for suspicious activity reduces the chance that a breach will lead to actual harm.

Other ways to protect yourself after a breach

If the breach included your full name, address, phone number, or date of birth, consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion). This makes it harder for someone to open accounts in your name, though it does not prevent all fraud.

Enable two-factor authentication on important accounts like email, banking, and social media. Two-factor authentication requires a second form of verification — usually a code from your phone or an authenticator app — in addition to your password. Even if someone has your password, they cannot log in without this second factor.

Check your credit report for accounts you do not recognize. You can view your credit report for free once a year at annualcreditreport.com. If you see fraudulent accounts, report them to the credit bureau and the company that opened the account.

Frequently Asked Questions

Is it safe to enter my password on Have I Been Pwned?

Yes. Have I Been Pwned does not store passwords you enter, and the site uses HTTPS encryption so your password is protected while it travels to the server. The site is run by Troy Hunt, a well-known security researcher, and has been audited by security professionals. However, if you are uncomfortable entering your actual password, you can check a password without entering the full thing by using the "range search" feature on the Passwords tab.

What if Have I Been Pwned says my email was not in a breach?

A negative result means your email does not appear in the breaches that Have I Been Pwned has in its database. This does not mean your information is completely safe — breaches that have not been publicly disclosed will not show up. It also does not mean your account has not been compromised through other methods, like phishing or weak passwords. Keep using strong, unique passwords and monitor your accounts for suspicious activity.

Can I check someone else's email address?

Yes, you can search any email address on Have I Been Pwned. However, you should only check your own email addresses or those of people who have asked you to check for them. Checking someone else's email without permission is not appropriate.

How often are new breaches added to Have I Been Pwned?

New breaches are added regularly as they are discovered and verified. The frequency varies — sometimes multiple breaches are added in a week, sometimes it takes longer. This is why setting up notifications is useful: you will be alerted as soon as your email appears in a newly added breach rather than having to check manually.

Do I need to pay for breach checking services?

No. Have I Been Pwned, Firefox Monitor, and Google Password Manager all offer breach checking for free. Some paid services offer additional features like credit monitoring or identity theft insurance, but basic breach checking does not require payment.