Have I Been Pwned explained: how it works, what it shows, and what to do with a hit

Password & accounts. Updated 2026-09-13. About 5 minutes to read.

Treat each breach that included passwords as a to do item: change that password everywhere you used it, then sign up for Notify me so the next breach reaches you.

Have I Been Pwned, usually shortened to HIBP, is a free service that tells you whether an email address appears in data from known breaches. It was created in December 2013 by Troy Hunt, an Australian security researcher, and at the time of writing in September 2026 it lists 1,035 breached websites and about 17.8 billion breached accounts.

DataExposed is independent and is not affiliated with Have I Been Pwned or Troy Hunt. We explain the service because it is the most widely used breach checker in the world, and because most people read its results wrong.

A result tells you your address was in a dataset. It does not tell you that someone logged in to your account, and a clean result does not mean your data is safe. Both points are covered below.

How the email search works

When a breach becomes public and the data circulates, HIBP loads the email addresses into its database along with the name of the breach and the types of data exposed, such as passwords, phone numbers, dates of birth or physical addresses. According to its FAQ, it stores only the email address or username and the list of breaches it appeared in. No password is stored next to an email address.

When you search, you see each breach your address appeared in, when it happened, and which data classes were included. That list is your to do list: every breach that included passwords means changing that password everywhere you used it.

The free features most people never use

  • Notify me: register an address and HIBP emails you when it appears in a newly loaded breach. This is more useful than any one-off search.
  • Sensitive breaches: breaches from sites such as adult or dating services are hidden from public search. They only show after you verify you own the address through Notify me.
  • Stealer logs: HIBP now loads data captured by infostealer malware, which records email addresses, passwords and the sites they were typed into. Verified owners can see which websites were involved.
  • Domain search: if you own a domain, verify it and monitor every address on it. It is free for domains with up to 10 breached addresses, and paid plans cover larger domains.
  • Pwned Passwords: check whether a password appears in breach data, without sending the password. Explained in the next section.
  • Opt out: you can remove your address from public search if you do not want others to see your results.

How Pwned Passwords checks a password without seeing it

The password check uses a technique called k-anonymity. Your password never leaves your device, and HIBP never learns which password you checked.

  1. Your device hashes the password with SHA-1. The password password becomes 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8.
  2. Only the first five characters of that hash, 5BAA6 in this example, are sent to the Pwned Passwords range API.
  3. The API returns every hash suffix that starts with those five characters, typically around 800 of them, with a count of how many times each appeared in breaches.
  4. Your device compares the rest of your hash against that list locally. A match means the password is known to attackers.
  5. Clients can add a padding option so every response contains between 800 and 1,000 results, which stops anyone watching the traffic guessing which prefix was checked.

The Pwned Passwords API is free, needs no API key and has no rate limit, which is why password managers, browsers and security tools build it in. The FBI has fed compromised passwords into it since 2021.

What a result cannot tell you

  • Whether anyone actually used your credentials. A hit means exposure, not a confirmed break in.
  • Which password was exposed. HIBP deliberately does not show it.
  • Breaches that have not surfaced publicly, or data held privately by criminals.
  • What data brokers and people search sites publish about you, which comes from records and marketing data, not breaches.
  • Whether your identity has been used for credit. For that you need your credit reports.
  • Anything about accounts registered with a different email address, or a phone number that is not tied to a loaded breach.

A clean result only means your address is not in the breaches HIBP has loaded. Keep unique passwords and two factor authentication anyway.

What to do with a hit, in order

  1. Look at the data classes for each breach. Start with any that include passwords.
  2. Change the password on the breached site if you still use it, then on every other account where you used the same or a similar password.
  3. Turn on two factor authentication, starting with your email account, using an authenticator app or passkey.
  4. If the breach included your phone number, date of birth or address, expect more convincing phishing and consider a credit freeze where available.
  5. If you appear in stealer logs, assume a device was infected. Run a full malware scan, update the device, then change passwords from a clean device.
  6. Register for Notify me so the next breach reaches you by email.

Is it safe and legitimate?

Yes. HIBP is used by individuals, companies and government agencies, and national governments use it to monitor their own domains. Law enforcement agencies including the FBI and the UK's National Crime Agency have contributed data to Pwned Passwords. The service funds itself through paid API and domain subscriptions, while searching your own address and the password check stay free.

The risk is copycats. HIBP never asks for your email password, your bank details or a payment to see your own results. If a site that looks like a breach checker asks for any of those, close it.

Frequently asked questions

Is Have I Been Pwned safe to use?

Yes. Searching an email address only reveals which public breaches it appeared in, and the password check uses k-anonymity so your password is never sent. Use the real site, haveibeenpwned.com, and never enter an email password into any breach checker.

Does HIBP show me my leaked password?

No. It shows which breaches your address was in and whether passwords were part of the data, but it never displays the password. Assume the password you used on that site at the time is known, and change it everywhere.

Why isn't a breach I know about listed on HIBP?

HIBP only loads breaches where the data has surfaced and can be verified. Some breaches are announced but the data never circulates publicly, and some are too small or unverifiable to load.

Is Have I Been Pwned free?

Searching your own email address, Notify me alerts, the Pwned Passwords check and domain monitoring for small domains are free. Programmatic email searches through the API and monitoring larger domains require a paid subscription.

Can HIBP tell me who hacked me or when?

It tells you which breach your data came from and roughly when that breach happened. It cannot tell you whether a specific person accessed your accounts. For that, check each account's recent sign in activity and security alerts.

Tools that help

Related guides

Sources