What Is Have I Been Pwned and How Do I Use It?
One security researcher's side project quietly became the internet's most trusted breach checker. Here's how to actually use it.
Have I Been Pwned (HIBP) is a free website, created by security researcher Troy Hunt, that lets anyone check whether their email address or phone number has appeared in a known data breach. You use it by simply entering your email at haveibeenpwned.com, and it instantly tells you which breaches, if any, exposed that address, along with what type of data was compromised in each one.
In 2013, an Australian security researcher named Troy Hunt got curious about how many times his own email address had shown up in publicly leaked data breaches.
He built a small tool to check. Over a decade later, that tool has grown into a database of billions of breached records, used by ordinary people, journalists, and even government agencies to check whether their information has been caught up in a leak — all searchable in seconds, for free.

TL;DR
Quick answer
Have I Been Pwned is a free website that lets you check whether your email or phone number has appeared in a known data breach, and offers a free ongoing notification service and a separate password-checking tool.
The Basics
A free lookup for a genuinely common problem
Have I Been Pwned works on a fairly simple principle: when a company gets breached and the stolen data becomes publicly known or circulates among researchers, the site ingests that dataset — specifically the email addresses (and sometimes phone numbers) involved — into a searchable database. It doesn't store your actual stolen passwords in a way you can browse; it stores which breaches your email address appeared in.
To use it, you go to haveibeenpwned.com, type in your email address, and hit search. Within seconds, it lists every known breach your address has appeared in, including the name of the breached company, the approximate date, and what type of data was exposed — passwords, physical addresses, phone numbers, and so on.
The site also offers a separate 'Pwned Passwords' tool, letting you check whether a specific password has appeared in known breach data, and a free notification service that alerts you automatically if your email shows up in a new breach in the future, rather than requiring you to check manually every time.
The three main things you can do on the site
- Search your email or phone number against known breaches instantly
- Check a specific password against a database of previously leaked passwords
- Sign up for free ongoing notifications if your email appears in a future breach
How a Have I Been Pwned search actually works
What happens between typing in your email and seeing your results.

Enter your email
Type your email address into the search bar on the site
Instant database check
The site checks your address against its indexed collection of known breaches
Results displayed
A list appears showing which breaches, if any, included your address and what data was exposed
One person's side project became infrastructure that governments now rely on
Have I Been Pwned started as a single researcher's personal curiosity project. Today, it's been integrated into government cybersecurity awareness campaigns and browser password managers, effectively becoming quiet, unofficial public infrastructure for basic breach awareness.
It's a reminder of how much of the internet's actual safety net is held together by small, independently run tools rather than large official institutions — a single well-maintained project can end up doing work no formal agency got around to building.
Misconception
If Have I Been Pwned shows no results for your email, your data has never been leaked anywhere.
Reality
A clean result means your email hasn't appeared in any of the breaches HIBP has indexed — not that it's guaranteed safe everywhere. The database, while extensive, can't include every breach that has ever occurred, especially smaller or unreported ones.
A practical step-by-step walkthrough
Here's exactly what to do, in order.
Go to the site
Visit haveibeenpwned.com directly, and enter your email address in the main search bar.
Like typing your name into a library's card catalog search.
Review your breach list
If your email has appeared in any indexed breach, the results page lists each one with the company name, breach date, and what data was exposed.
A receipt showing exactly which stores' records you turned up in.
Check your passwords separately
Use the site's Pwned Passwords tool to check whether a specific password you use has appeared in leaked data, without needing to submit your actual email.
Checking if a specific key design has ever been reported as compromised, without saying which door it opens.
Sign up for notifications
Register your email with the site's free notification service to get an alert automatically if it appears in any future breach.
Subscribing to a smoke alarm service instead of manually checking for smoke every day.
Act on any exposure found
For any breach listed, change the password used on that specific account, and on any other account where you reused the same password.
Replacing a specific lock once you learn its key design has been compromised.
A tool built to expose bad news has become genuinely reassuring to use
You'd expect a site whose entire purpose is telling you when your data has been stolen to feel unsettling. In practice, most users describe the opposite reaction — simply knowing, one way or the other, turns out to be far less stressful than not knowing at all.
If it's free, how does a single person maintain a database of billions of breach records?
What's actually sustaining a free service handling this much sensitive, high-stakes data?The project has grown well past a solo effort over the years, now supported by a mix of donations, corporate partnerships (including integration with browser password managers and some government cybersecurity programs), and the reputational value of being the trusted, canonical source for this kind of lookup. The core commitment to keeping personal searches free has remained a defining principle of the project since its founding.
Government adoption of the tool
Have I Been Pwned's breach data has been integrated into national cybersecurity awareness initiatives in multiple countries, including partnerships that allow certain government domains to be monitored in bulk for breach exposure across an entire organization.
A tool built for individual curiosity scaled up naturally into organizational and even national-level use, showing that good, transparent design can serve very different audiences without needing a fundamental redesign.
How it compares to other ways of checking exposure
Several tools solve a version of this problem, but not identically.
| Have I Been Pwned | Password Manager Breach Alerts | Full Identity Theft Protection Service | |
|---|---|---|---|
| Cost | Free | Often bundled free with password manager | Usually a paid subscription |
| Scope | Known public breach database | Similar breach checking, integrated into your passwords | Broader monitoring including credit, SSN, dark web forums |
| Ongoing monitoring | Yes, via free notification signup | Yes, built into the app | Yes, as the core paid feature |
Is Have I Been Pwned worth using?
Yes, unambiguously — it's free, well-maintained, and one of the simplest, highest-value security habits available to anyone.
There's essentially no downside to checking, it costs nothing, takes seconds, and the notification signup turns a one-time check into ongoing protection with no extra effort required.
What this tool says about transparency as a form of protection
Have I Been Pwned's entire value rests on a simple idea: that knowing what's already happened to your data is itself a form of protection, even when you can't undo the original leak. In a security landscape often built around trying to prevent every possible bad outcome, HIBP represents the quieter, equally important half of the equation — making sure people at least find out when prevention has already failed somewhere upstream.
Questions people ask
If this got you curious, go here next
What is credential monitoring?
The broader category of ongoing protection HIBP's notification feature belongs to.
What is dark web monitoring and how does it work?
A deeper, paid layer of protection beyond what a free breach check covers.
What is stealer log monitoring?
A more specific type of exposure that breach checkers like this help catch.
What is exit scamming on the dark web?
One of the ways stolen data ends up circulating in the first place.
What is an escrow system on the dark web?
How some stolen data ultimately gets bought and sold after a breach.
Thirty seconds of knowing beats a lifetime of wondering
Have I Been Pwned won't undo a breach that's already happened. What it offers is something smaller but genuinely valuable — the chance to stop guessing, and start actually knowing, in about the time it takes to type an email address.
You now know
- Have I Been Pwned lets anyone check their email or phone number against known data breaches for free
- It shows which breaches you appeared in and what data was exposed, not your actual leaked password
- A separate Pwned Passwords tool checks a specific password without linking it to your identity
- Signing up for its free notification service turns a one-time check into ongoing protection
Common myth
Myth vs reality
A clean search result means your data has never been breached anywhere.
It only means your email isn't in any breach the site has indexed so far.
FAQs
Questions people ask
Sources
Further reading
- Have I Been Pwned official documentationhaveibeenpwned.com
- Public commentary from the project's creatorTroy Hunt's blog
Glossary
Terms in this guide
Continue learning