Password & accounts. Updated 2026-09-13. About 5 minutes to read.
Treat each breach that included passwords as a to do item: change that password everywhere you used it, then sign up for Notify me so the next breach reaches you.
Have I Been Pwned, usually shortened to HIBP, is a free service that tells you whether an email address appears in data from known breaches. It was created in December 2013 by Troy Hunt, an Australian security researcher, and at the time of writing in September 2026 it lists 1,035 breached websites and about 17.8 billion breached accounts.
DataExposed is independent and is not affiliated with Have I Been Pwned or Troy Hunt. We explain the service because it is the most widely used breach checker in the world, and because most people read its results wrong.
A result tells you your address was in a dataset. It does not tell you that someone logged in to your account, and a clean result does not mean your data is safe. Both points are covered below.
When a breach becomes public and the data circulates, HIBP loads the email addresses into its database along with the name of the breach and the types of data exposed, such as passwords, phone numbers, dates of birth or physical addresses. According to its FAQ, it stores only the email address or username and the list of breaches it appeared in. No password is stored next to an email address.
When you search, you see each breach your address appeared in, when it happened, and which data classes were included. That list is your to do list: every breach that included passwords means changing that password everywhere you used it.
The password check uses a technique called k-anonymity. Your password never leaves your device, and HIBP never learns which password you checked.
The Pwned Passwords API is free, needs no API key and has no rate limit, which is why password managers, browsers and security tools build it in. The FBI has fed compromised passwords into it since 2021.
A clean result only means your address is not in the breaches HIBP has loaded. Keep unique passwords and two factor authentication anyway.
Yes. HIBP is used by individuals, companies and government agencies, and national governments use it to monitor their own domains. Law enforcement agencies including the FBI and the UK's National Crime Agency have contributed data to Pwned Passwords. The service funds itself through paid API and domain subscriptions, while searching your own address and the password check stay free.
The risk is copycats. HIBP never asks for your email password, your bank details or a payment to see your own results. If a site that looks like a breach checker asks for any of those, close it.
Yes. Searching an email address only reveals which public breaches it appeared in, and the password check uses k-anonymity so your password is never sent. Use the real site, haveibeenpwned.com, and never enter an email password into any breach checker.
No. It shows which breaches your address was in and whether passwords were part of the data, but it never displays the password. Assume the password you used on that site at the time is known, and change it everywhere.
HIBP only loads breaches where the data has surfaced and can be verified. Some breaches are announced but the data never circulates publicly, and some are too small or unverifiable to load.
Searching your own email address, Notify me alerts, the Pwned Passwords check and domain monitoring for small domains are free. Programmatic email searches through the API and monitoring larger domains require a paid subscription.
It tells you which breach your data came from and roughly when that breach happened. It cannot tell you whether a specific person accessed your accounts. For that, check each account's recent sign in activity and security alerts.