Find out in one second whether a password has appeared in a known data breach. This tool uses the Have I Been Pwned range API with k-anonymity: your browser hashes the password and sends only the first 5 characters of the hash. The password itself never leaves your device.
If a password appears in a breach, replace it everywhere it is still used.
Credential stuffing works because people reuse passwords — one leak unlocks many accounts.
It means the password was in a known dataset. Treat it as compromised and rotate it.
Generating unique passwords per site is the only durable fix.
Find out in one second whether a password has appeared in a known data breach. This tool uses the Have I Been Pwned range API with k-anonymity: your browser hashes the password and sends only the first 5 characters of the hash. The password itself never leaves your device.
Enter the exact password on its own — not your username, and not a variation you have never used.
Your browser computes the SHA-1 hash and asks the breach database about the first five characters only.
If it appears in breaches, change it everywhere and replace it with a unique generated password.
| Password | Typical result | Action |
|---|---|---|
| password | Found in millions | Change now |
| 123456 | Found in millions | Change now |
| Kx!9#mP2@vLq7$dR | Not found | Keep it unique |
The absence of a hit is good news, but it does not guarantee a password is strong — check strength too.
It is completely free, private and requires no signup.
Use the tool nowYes. The password is hashed in your browser. Only a 5-character prefix of the SHA-1 hash is sent, and that prefix matches hundreds of thousands of different passwords, so the request cannot reveal yours.
A service by Troy Hunt that aggregates billions of records from public data breaches. The range API answers by hash prefix, which is what makes k-anonymity possible.
It means the password appeared in a breach somewhere. Attackers test such lists automatically, so treat the password as compromised and replace it now.
No. Nothing is stored or logged — the hash is used for the request and discarded immediately.
Explore the whole collection — no signup, 100% free & private.