Has My Password Leaked?

Checks a password against known breaches without ever sending it.

Free. Runs in your browser: nothing you enter or open is uploaded.

How it stays private: your browser turns the password into a SHA-1 fingerprint and sends only its first 5 characters to the free Pwned Passwords service run by Have I Been Pwned. The service returns every leaked fingerprint that starts the same way, and the match is checked here on your device. The password itself never leaves your browser.

How to use it

  1. Type or paste the password and press Check.
  2. If it has appeared in a breach, stop using it everywhere and change it on every account that shares it.
  3. Turn on two-step sign-in where you can, and use a different password for every site.

Questions

Is it safe to check my password here?

Yes. Only the first 5 characters of a SHA-1 fingerprint of the password are sent, which matches hundreds of different passwords, and the comparison happens in your browser. This is the k-anonymity method Have I Been Pwned designed for exactly this check.

My password was found. What now?

Change it on every site where you use it, starting with email and banking. Attackers feed leaked passwords into automated sign-in attempts across many sites.

It was not found. Is it safe?

Not necessarily. It only means it is not in the breaches the service has collected. A short or guessable password can still be cracked.

Can I check my email address too?

Email lookups need a paid key from Have I Been Pwned and a server request, so this tool checks passwords only.