What Is Have I Been Pwned? How to Check If You've Been Hacked

Have I Been Pwned is a free, legitimate breach-notification service run by security researcher Troy Hunt for checking your email and passwords.

Have I Been Pwned website logo and hero graphic
Image: Have I Been Pwned.

Have I Been Pwned is a free breach-notification website, at haveibeenpwned.com, that lets you check whether your email address, phone number, or password has turned up in a known data breach — and yes, it is legitimate, run by independent security researcher Troy Hunt since 2013. Here is what it actually does, how it works under the hood, and exactly how to use it if you think you might have been pwned.

Key facts
  • Have I Been Pwned (HIBP) was created in December 2013 by security researcher Troy Hunt, after he noticed the same compromised accounts appearing in breach after breach.
  • As of this writing, HIBP tracks more than 1,000 breaches covering roughly 17.8 billion breached accounts, according to its own homepage stats.
  • Checking an email address is free. So is Pwned Passwords, the separate tool for checking passwords.
  • Pwned Passwords never sends your actual password anywhere — it uses a privacy technique called k-anonymity, explained below.
  • HIBP is not affiliated with any of the companies whose breaches it lists; it only aggregates data that has already been exposed.

What is Have I Been Pwned?

Have I Been Pwned is a search engine for data breaches. Type in an email address and it tells you which known breaches — hacked services where usernames, emails, passwords, or other personal data were stolen and later leaked or sold — included that address. The name comes from "pwned," gamer slang derived from "owned," meaning your account or data has been compromised, according to Have I Been Pwned's own FAQ.

The site was built by Troy Hunt, a Microsoft Regional Director and security researcher, after the 2013 Adobe breach, when he noticed the same email addresses and passwords recurring across multiple leaked datasets he was analyzing. He built HIBP as, in his words, "a free resource for anyone to quickly assess if they may have been put at risk due to an online account of theirs having been compromised," per the HIBP About page. Have I Been Pwned is a registered trademark of Hunt's company, Superlative Enterprises Pty Ltd, and the project is run day to day by Hunt along with his wife Charlotte Hunt handling operations and a part-time developer, Stefán Jökull Sigurðsson, on infrastructure.

Is Have I Been Pwned legitimate and safe to use?

Yes. HIBP is one of the most widely trusted tools in the security industry precisely because it is independent, transparent about its methodology, and does not require you to hand over sensitive information to search. According to the FAQ, individual email searches on the site are not logged, and the service states it does not store your password when you search for one. To subscribe to alerts, HIBP stores only "the email address, the date they subscribed on and a random token," and all traffic to the site runs over encrypted (HTTPS) connections.

Before adding a breach to its database, HIBP performs due diligence: checking whether the affected organization has acknowledged the incident, verifying the data is unique rather than recycled from an older leak, checking the structural legitimacy of the fields, and assessing the credibility of whoever is distributing the data, per the FAQ. Breaches are then labeled — "sensitive" (requires email verification to search, used for breaches like adult-content sites), "unverified" (plausible but unconfirmed origin), "fabricated" (likely fake), or "retired" (removed from search) — so you can gauge how much confidence to place in any given result.

How does Have I Been Pwned actually work?

HIBP works by aggregating data from breaches that have already happened and already circulated — it does not hack anyone or go looking for new leaks proactively; researchers and the security community submit breach corpora, which Hunt vets and loads into the database, per the FAQ. When you search an email address, the site checks it against every breach and "paste" (public data dumps posted to sites like Pastebin) in its index and returns a list of which ones it appeared in, along with what kind of data was exposed in each one — the API v3 documentation lists dozens of possible data classes, from email addresses and passwords to physical addresses, security questions, and government IDs.

Under the hood, HIBP also exposes this functionality as a paid API (an hibp-api-key header and a valid user agent are required) with endpoints such as breachedAccount, breachedDomain, pasteAccount, and a public breaches list — this is how third-party tools, browsers, and password managers plug HIBP's data into their own breach-alert features.

How to check if your email has been pwned

The core check is free and takes seconds:

  1. Go to haveibeenpwned.com.
  2. Type your email address into the search box on the homepage and press enter.
  3. If it comes back "Good news — no pwnage found!", your address has not appeared in any breach HIBP has indexed. If it comes back "Oh no — pwned!", you'll get a list of every breach it turned up in, with a short description of what happened and which data classes (passwords, phone numbers, dates of birth, etc.) were exposed in each one.
  4. Some breaches are marked "sensitive" and won't show in a plain search — HIBP requires you to verify you own the address (via a confirmation email) before revealing those results, to prevent someone else from using the tool to snoop on you.

You can also search a phone number on the same site for breaches that included phone numbers, and organizations can verify ownership of an entire domain to see every breached address across their company at once.

Setting up Notify Me alerts

A one-time search only tells you about breaches already in the database. Since new breaches surface constantly, HIBP's Notify Me feature runs an ongoing check on your behalf:

  1. Go to the Notify Me page and enter the email address you want monitored.
  2. HIBP sends a verification email to that address — click the link inside it to confirm you actually own it (check your spam folder if it doesn't arrive quickly).
  3. Once verified, HIBP will email you automatically any time that address turns up in a newly loaded breach.

HIBP states plainly that it "will never share your email with anyone else." You can subscribe as many personal addresses as you want, and unsubscribe at any time.

Pwned Passwords and the k-anonymity model

Separate from the breach search is Pwned Passwords, a tool built from a huge corpus of passwords that have previously appeared in breaches. You can check any password against it — but the obvious worry is: won't that mean sending your real password to a third-party server? HIBP's design specifically avoids that, using a privacy technique called k-anonymity.

Here's how it works, per the Pwned Passwords page: your device hashes the password locally using SHA-1 (a one-way scramble), then sends only the first five characters of that hash to the API — never the password itself, and never the full hash. The API responds with every hash suffix in its corpus that starts with those same five characters, often hundreds of them, along with how many times each one has been seen in breaches. Your device then checks locally whether your full hash is anywhere in that returned list. Because the server only ever sees an ambiguous five-character prefix shared by hundreds of other hashes, it can't work out which actual password you checked.

The Pwned Passwords API is free, requires no API key, and Hunt says it handles billions of requests a month via Cloudflare's network — which is how it gets baked directly into products like browsers' built-in password-breach warnings and password managers' security dashboards, and why sites can use it to block people from choosing a known-compromised password at signup. The full dataset is also downloadable from GitHub for organizations that want to run the check entirely offline.

Have I Been Pwned's tools at a glance
ToolWhat it checksWhat you provideCost
Email searchWhether an address appears in known breaches or pastesThe email address itselfFree
Notify MeOngoing alerts for future breaches involving your addressEmail address + one-time verificationFree
Pwned Passwords (web)Whether a password has appeared in a breach corpusNothing sent in full — only a 5-character hash prefix, via k-anonymityFree
Pwned Passwords APISame check, for developers to build into apps and password managersA SHA-1 or NTLM hash prefix; no API key requiredFree
Domain searchEvery breached address across an entire company domainVerified ownership of the domainFree, verification required
HIBP API v3Programmatic breach, paste, and (on higher tiers) stealer-log lookupsAn hibp-api-key subscriptionPaid

What Have I Been Pwned can't tell you

It's worth being clear-eyed about the limits. HIBP can only surface breaches that have already been discovered, submitted, and verified — a "no pwnage found" result means your address isn't in HIBP's index yet, not that it has never been exposed anywhere. It also can't tell you whether a specific password you're currently using on a specific site was the one leaked in a given breach, only that the address showed up in that incident and which categories of data (per the breach's listing) were involved. That's part of why the Pwned Passwords check exists as a separate tool — to test actual passwords, not just email addresses, against the aggregated corpus.

What to do if you've been pwned

If Have I Been Pwned turns up a match, the fix is straightforward and doesn't require panic:

  1. Change the password on the affected account, and on any other account where you reused that same password — password reuse is exactly how one breach turns into many account takeovers.
  2. Use unique, randomly generated passwords going forward, stored in a password manager rather than memorized or reused. If you don't already use one, see Pandromeda's comparison of Bitwarden, 1Password, and Proton Pass for pricing and features.
  3. Turn on two-factor authentication or switch to passkeys wherever the affected service offers it, so a leaked password alone isn't enough to get into your account. Pandromeda's guide to setting up an authenticator app for two-factor authentication walks through the process.
  4. Check the Pwned Passwords tool for any password you're still using anywhere, not just the ones flagged in a specific breach — reused passwords can surface in future leaks you haven't been notified about yet.
  5. Watch for follow-on scams. Breached data — especially names, addresses, or ID numbers rather than just email/password pairs — often gets used for targeted phishing. Pandromeda's coverage of the IDScan.net breach that exposed driver's license data is a recent example of the kind of exposure that's worth checking for specifically if you've used age-verification or ID-scanning services.
  6. Set up Notify Me on your main addresses so you find out about the next breach immediately rather than stumbling onto it months later.

Bottom line

Have I Been Pwned is a free, legitimate, well-documented tool for finding out whether your email, phone number, or password has surfaced in a known data breach, built and run independently by a named security researcher rather than a marketing arm of any company trying to sell you something. The email and Pwned Passwords checks cost nothing, take under a minute, and — thanks to the k-anonymity design of Pwned Passwords — never require you to hand your actual password to anyone. If a search turns up a hit, the response is the same regardless of which breach it was: change the reused password, move to a password manager, and turn on 2FA or passkeys so a single leaked credential can't be reused against you elsewhere.

Frequently asked questions

Is Have I Been Pwned legit and safe to use?

Yes. It's run independently by security researcher Troy Hunt since 2013, individual searches aren't logged, and the service doesn't store the password you check, according to its own FAQ.

Is Have I Been Pwned free?

Checking an email address, setting up Notify Me alerts, and checking a password with Pwned Passwords are all free. A paid API subscription is only needed for programmatic or bulk lookups.

Does Have I Been Pwned store my password when I check it?

No. Pwned Passwords uses a technique called k-anonymity: your device sends only the first five characters of your password's SHA-1 hash and does the final match locally, so your full password or hash never reaches the server.

What does "pwned" mean?

It's gamer slang derived from "owned," meaning an account or system has been compromised, according to Have I Been Pwned's FAQ.

What should I do if Have I Been Pwned says I've been breached?

Change the password on that account and any other account reusing it, switch to a password manager, enable two-factor authentication or passkeys, and set up Notify Me for future breaches.

How is Pwned Passwords different from the main email search?

The email search checks whether an address appeared in a specific breach. Pwned Passwords separately checks whether a specific password string has ever appeared in any breach corpus, using k-anonymity so the password itself is never exposed.

Sources

More on Have I Been Pwned →have i been pwneddata breachpassword securitytroy huntpwned passwordstwo-factor authentication
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all