Your Security Tools Hub
Check if your password appears in known data breaches using Have I Been Pwned database
Powered by Have I Been Pwned database
Only first 5 characters sent for k-anonymity protection
Waiting for input...
Enter a password to get security recommendation
Password check results will appear here
We check against 613+ million real breached passwords
Database updated: Loading...
Data from Have I Been Pwned
Click "Test Common Passwords" to see results
Your password is converted to SHA-1 hash locally in your browser before any network request
Only first 5 characters of hash sent to API. Your full password or hash never exposed
We query Troy Hunt's Have I Been Pwned database of 613+ million real breached passwords
Results matched locally. We never know which password you checked or the result
Yes! Your password never leaves your browser. It's converted to a SHA-1 hash locally, and only the first 5 characters of that hash are sent to the API. This is called k-anonymity and ensures your password remains private.
We use the Have I Been Pwned (HIBP) database maintained by security researcher Troy Hunt. It contains over 613 million real passwords from known data breaches.
Immediately change that password on ALL accounts where you use it. Enable two-factor authentication and consider using a password manager to generate unique, strong passwords for each service.
The HIBP database is updated regularly as new breaches are discovered and verified. We check for updates daily to ensure our tool uses the most current data available.