Home / Tools

Has my password been leaked?

Check if a password appeared in a data breach without revealing it. Your password never leaves your device; only part of a scrambled code is sent.

  1. On your device: your password is turned into a scrambled code (a SHA-1 hash).
  2. Sent: only the first 5 characters of that code, like 5BAA6. Hundreds of different passwords share every 5-character start.
  3. Back on your device: the list of matching leaked codes is checked here, so nobody else learns your password or the result.

Checks use Have I Been Pwned's free Pwned Passwords service. We never see or store what you type.

Billions of passwords have leaked in data breaches, and attackers try them first. If a password you use appears on those lists, it's no longer safe anywhere, no matter how clever it looks.

Is it safe to type my password here?

We designed this check so your password never leaves your browser. It uses a method called k-anonymity: your device sends only the first 5 characters of a scrambled code made from your password, gets back every leaked code that starts the same way, and compares them itself. Even if someone watched the request, they couldn't tell which password you checked. If you'd still rather not type a current password, check old passwords you might be reusing.

What to do if it's been leaked

  1. Change it on every account where you use it, starting with email and banking.
  2. Use a unique password for each account. Our password generator creates strong ones.
  3. Turn on two-step verification, so a leaked password alone can't get anyone in.

Want a full picture of your safety? Take the security checkup.

Last updated October 2026.

More tools