Password Leak Checker (Has My Password Been Leaked?)

Your password never leaves your device: only the first 5 characters of its SHA-1 fingerprint are sent to Have I Been Pwned.

Only the first 5 characters of its SHA-1 fingerprint are sent. The password itself never leaves your device.

This password leak checker tells you whether a password appears in the Pwned Passwords list from Have I Been Pwned, a large collection of real passwords exposed in data breaches. If yours is there, criminals can try it on your accounts, so change it everywhere you use it.

The check is private. Your password never leaves your device: only the first 5 characters of its SHA-1 fingerprint are sent.

How to use the password leak checker

  1. Type the password into Password to check. Tick Show password if you want to see what you typed.
  2. Select Check password.
  3. Read the result: Found … times in data breaches in red, or Not found in known breaches in green.
  4. If it was found, change that password on every account that uses it. The steps are below.

By default the box is cleared after each check, so the password doesn’t sit on screen. Untick Clear the box after checking if you want to check the same password again or fix a typo.

Check the passwords you use most: your email, your phone account (Apple Account, Google Account or Samsung account) and your bank. Your email matters most, because it can reset every other password.

How the check keeps your password private

Typing a real password into a website should make you nervous. This one is built so that it never needs to see it. It uses a method from Have I Been Pwned’s Pwned Passwords service called k-anonymity. Here is what happens when you select Check password:

  1. Your browser turns the password into a SHA-1 fingerprint (a hash): 40 letters and numbers. You can’t turn a hash back into the password, but the same password always gives the same hash.
  2. It sends only the first 5 characters of that hash to api.pwnedpasswords.com.
  3. The service replies with every leaked hash that starts with those 5 characters, usually hundreds of them, each with a count.
  4. Your browser looks for the rest of your hash in that list. The match happens on your device.

So the service only learns that someone checked one of hundreds of passwords that share a 5-character start. It never gets your password or its full hash. The tool also asks for padding: the reply is topped up with fake entries (with a count of zero) so the size of the reply gives nothing away either. The tool ignores those.

Nothing is stored. The tool doesn’t save, log or remember the password, and Being Tricky’s server isn’t involved in the check at all.

The number in a “Found” result is how many times that password appears in the breach data, not how many of your accounts were hacked. A common password like password appears millions of times because millions of people used it.

What your result means

ResultWhat it meansWhat to do
Found many timesA common password. It’s in the lists attackers try first.Change it now on every account that uses it. Never use it again.
Found once or a few timesThis exact password leaked from at least one site. Someone may have your email and this password together.Change it everywhere you use it, starting with email and banking.
Not found in known breachesIt isn’t in the Pwned Passwords data.Keep it only if it’s long, random and used for one account.
Couldn’t reach Have I Been PwnedThe request didn’t get through.See “If the checker doesn’t work” below.

What to do if your password was leaked

A leaked password is a problem wherever you use it, because criminals take passwords from one breach and try them on other sites. The FTC and the US Cybersecurity and Infrastructure Security Agency (CISA) give the same core advice:

  • Change it everywhere you use it. The FTC says to change the exposed password right away, and any similar password you use elsewhere. Start with your email account.
  • Use a different password for every account. CISA recommends a unique password of at least 16 characters for each account, so one leak can’t open the rest. Our password and passphrase generator makes one in your browser.
  • Let a password manager remember them. CISA describes a password manager as a program that creates, stores and fills in your passwords, so you only need to remember one strong main password. The FTC adds that many browsers can create strong passwords for you too.
  • Turn on two-step verification. CISA calls it multi-factor authentication (MFA): even if someone steals your password, they still need the second step. The FTC notes an authenticator app or a security key is more secure than a text message code.
  • Switch to passkeys where you can. A passkey replaces the password with your phone or computer’s screen lock, so there’s nothing to leak or reuse. Our guide on how to set up passkeys covers Google, Apple and Microsoft accounts.

Then check for signs that someone already got in: sign-in alerts you don’t recognize, password reset emails you didn’t ask for, or new forwarding rules in your email. If an account was taken over, see our guides to recovering a hacked Instagram account and checking whether your phone is hacked. If the breach also exposed your Social Security number or bank details, the FTC points to IdentityTheft.gov for next steps.

Be wary of emails that say your password was found and ask you to “verify” it through a link. That’s a common phishing trick. Change passwords by going to the site or app yourself.

“Not found” doesn’t mean the password is strong

A green result only means the password isn’t in the known breach data. It says nothing about how easy it is to guess. Summer2026! may not be in the list yet, but a computer guessing common patterns would find it quickly. A password can also be “not found” simply because the breach it leaked in hasn’t been made public.

Treat a password as safe only if it’s long (CISA suggests 16 characters or more), random, and used for one account only. A random string or a passphrase of several unrelated words both work. For more ways to protect your accounts, see our security hub.

If the checker doesn’t work

  • “Couldn’t reach Have I Been Pwned”: check your internet connection and try again. Ad blockers, privacy extensions and some work or school networks block requests to other sites; allow api.pwnedpasswords.com on this page, or try another network.
  • “Your browser can’t do the secure check here”: the hashing needs the Web Crypto feature, which browsers only offer on secure (https) pages. Make sure the address starts with https, and update your browser: Chrome, Edge, Firefox and Safari all support it.
  • Nothing happens on iPhone or iPad: Safari is updated with iOS and iPadOS, so install the latest software update, then reload the page.
  • The button stays greyed out: a check is still running. Wait a few seconds; on a very slow connection, reload the page and try again.

Privacy

Your password never leaves your device. The only thing sent is the first 5 characters of its SHA-1 fingerprint, and it goes straight from your browser to Have I Been Pwned, not to us. The tool sends no cookies with that request and keeps nothing afterwards. Like any site you visit, Have I Been Pwned can see your IP address when your browser connects to it.

Related free tool: our link safety checker.

FAQ

Is it safe to type my real password into a password leak checker?

Into this one, yes: the password is hashed on your device and only the first 5 characters of the hash are sent. Don’t type real passwords into checkers that don’t explain how they work.

Where does the breach data come from?

From Have I Been Pwned’s Pwned Passwords service, a free collection of passwords exposed in public data breaches. Its range API needs no account or key.

My password was found. Does that mean I was hacked?

Not necessarily. It means someone, somewhere, used the same password and it leaked. But anyone who has it can try it on your accounts, so change it everywhere you use it.

Can it tell me which site leaked my password?

No. Pwned Passwords only lists passwords and counts, with no email addresses or site names. To see which breaches include your email address, use the search on haveibeenpwned.com.

How often should I check my passwords?

Whenever you hear about a breach at a service you use, and when you set up a password manager. Some password managers can also check your saved passwords against breach lists for you.

Sources