Digital Safety

What Is Have I Been Pwned and How Do I Use It?

One security researcher's side project quietly became the internet's most trusted breach checker. Here's how to actually use it.

Have I Been Pwned (HIBP) is a free website, created by security researcher Troy Hunt, that lets anyone check whether their email address or phone number has appeared in a known data breach. You use it by simply entering your email at haveibeenpwned.com, and it instantly tells you which breaches, if any, exposed that address, along with what type of data was compromised in each one.

In 2013, an Australian security researcher named Troy Hunt got curious about how many times his own email address had shown up in publicly leaked data breaches.

He built a small tool to check. Over a decade later, that tool has grown into a database of billions of breached records, used by ordinary people, journalists, and even government agencies to check whether their information has been caught up in a leak — all searchable in seconds, for free.

Illustration of a magnifying glass checking an email address against a database of breach records
Created bySecurity researcher Troy Hunt
Launched2013
Cost to checkFree
What you searchEmail address or phone number

TL;DR

Quick answer

Have I Been Pwned is a free website that lets you check whether your email or phone number has appeared in a known data breach, and offers a free ongoing notification service and a separate password-checking tool.

Last reviewed2026-07-26
Reading time7 min read
DifficultyBeginner
EvidenceStrong
What it checksEmail/phone against known breach databases
Result speedInstant lookup
Password checkerSeparate tool checks if a password has leaked
Doesn't doRemove your data or stop future breaches
Trusted bySecurity researchers, journalists, some government agencies

The Basics

A free lookup for a genuinely common problem

Have I Been Pwned works on a fairly simple principle: when a company gets breached and the stolen data becomes publicly known or circulates among researchers, the site ingests that dataset — specifically the email addresses (and sometimes phone numbers) involved — into a searchable database. It doesn't store your actual stolen passwords in a way you can browse; it stores which breaches your email address appeared in.

To use it, you go to haveibeenpwned.com, type in your email address, and hit search. Within seconds, it lists every known breach your address has appeared in, including the name of the breached company, the approximate date, and what type of data was exposed — passwords, physical addresses, phone numbers, and so on.

The site also offers a separate 'Pwned Passwords' tool, letting you check whether a specific password has appeared in known breach data, and a free notification service that alerts you automatically if your email shows up in a new breach in the future, rather than requiring you to check manually every time.

The three main things you can do on the site

  • Search your email or phone number against known breaches instantly
  • Check a specific password against a database of previously leaked passwords
  • Sign up for free ongoing notifications if your email appears in a future breach

How a Have I Been Pwned search actually works

What happens between typing in your email and seeing your results.

Flow diagram showing an email search being checked against a breach database and returning results
1

Enter your email

Type your email address into the search bar on the site

2

Instant database check

The site checks your address against its indexed collection of known breaches

3

Results displayed

A list appears showing which breaches, if any, included your address and what data was exposed

One person's side project became infrastructure that governments now rely on

Have I Been Pwned started as a single researcher's personal curiosity project. Today, it's been integrated into government cybersecurity awareness campaigns and browser password managers, effectively becoming quiet, unofficial public infrastructure for basic breach awareness.

It's a reminder of how much of the internet's actual safety net is held together by small, independently run tools rather than large official institutions — a single well-maintained project can end up doing work no formal agency got around to building.

Misconception

If Have I Been Pwned shows no results for your email, your data has never been leaked anywhere.

Reality

A clean result means your email hasn't appeared in any of the breaches HIBP has indexed — not that it's guaranteed safe everywhere. The database, while extensive, can't include every breach that has ever occurred, especially smaller or unreported ones.

A practical step-by-step walkthrough

Here's exactly what to do, in order.

Go to the site

Visit haveibeenpwned.com directly, and enter your email address in the main search bar.

Like typing your name into a library's card catalog search.

Review your breach list

If your email has appeared in any indexed breach, the results page lists each one with the company name, breach date, and what data was exposed.

A receipt showing exactly which stores' records you turned up in.

Check your passwords separately

Use the site's Pwned Passwords tool to check whether a specific password you use has appeared in leaked data, without needing to submit your actual email.

Checking if a specific key design has ever been reported as compromised, without saying which door it opens.

Sign up for notifications

Register your email with the site's free notification service to get an alert automatically if it appears in any future breach.

Subscribing to a smoke alarm service instead of manually checking for smoke every day.

Act on any exposure found

For any breach listed, change the password used on that specific account, and on any other account where you reused the same password.

Replacing a specific lock once you learn its key design has been compromised.

A tool built to expose bad news has become genuinely reassuring to use

You'd expect a site whose entire purpose is telling you when your data has been stolen to feel unsettling. In practice, most users describe the opposite reaction — simply knowing, one way or the other, turns out to be far less stressful than not knowing at all.

If it's free, how does a single person maintain a database of billions of breach records?

What's actually sustaining a free service handling this much sensitive, high-stakes data?

The project has grown well past a solo effort over the years, now supported by a mix of donations, corporate partnerships (including integration with browser password managers and some government cybersecurity programs), and the reputational value of being the trusted, canonical source for this kind of lookup. The core commitment to keeping personal searches free has remained a defining principle of the project since its founding.

Government adoption of the tool

Have I Been Pwned's breach data has been integrated into national cybersecurity awareness initiatives in multiple countries, including partnerships that allow certain government domains to be monitored in bulk for breach exposure across an entire organization.

A tool built for individual curiosity scaled up naturally into organizational and even national-level use, showing that good, transparent design can serve very different audiences without needing a fundamental redesign.

How it compares to other ways of checking exposure

Several tools solve a version of this problem, but not identically.

Have I Been PwnedPassword Manager Breach AlertsFull Identity Theft Protection Service
CostFreeOften bundled free with password managerUsually a paid subscription
ScopeKnown public breach databaseSimilar breach checking, integrated into your passwordsBroader monitoring including credit, SSN, dark web forums
Ongoing monitoringYes, via free notification signupYes, built into the appYes, as the core paid feature
confirmed

Is Have I Been Pwned worth using?

Yes, unambiguously — it's free, well-maintained, and one of the simplest, highest-value security habits available to anyone.

There's essentially no downside to checking, it costs nothing, takes seconds, and the notification signup turns a one-time check into ongoing protection with no extra effort required.

What this tool says about transparency as a form of protection

Have I Been Pwned's entire value rests on a simple idea: that knowing what's already happened to your data is itself a form of protection, even when you can't undo the original leak. In a security landscape often built around trying to prevent every possible bad outcome, HIBP represents the quieter, equally important half of the equation — making sure people at least find out when prevention has already failed somewhere upstream.

Questions people ask

If this got you curious, go here next

What is credential monitoring?

The broader category of ongoing protection HIBP's notification feature belongs to.

What is dark web monitoring and how does it work?

A deeper, paid layer of protection beyond what a free breach check covers.

What is stealer log monitoring?

A more specific type of exposure that breach checkers like this help catch.

What is exit scamming on the dark web?

One of the ways stolen data ends up circulating in the first place.

What is an escrow system on the dark web?

How some stolen data ultimately gets bought and sold after a breach.

Thirty seconds of knowing beats a lifetime of wondering

Have I Been Pwned won't undo a breach that's already happened. What it offers is something smaller but genuinely valuable — the chance to stop guessing, and start actually knowing, in about the time it takes to type an email address.

You now know

  • Have I Been Pwned lets anyone check their email or phone number against known data breaches for free
  • It shows which breaches you appeared in and what data was exposed, not your actual leaked password
  • A separate Pwned Passwords tool checks a specific password without linking it to your identity
  • Signing up for its free notification service turns a one-time check into ongoing protection

Common myth

Myth vs reality

Myth

A clean search result means your data has never been breached anywhere.

Reality

It only means your email isn't in any breach the site has indexed so far.

FAQs

Questions people ask

Sources

Further reading

  • Have I Been Pwned official documentationhaveibeenpwned.com
  • Public commentary from the project's creatorTroy Hunt's blog

Continue learning

Next useful step

Keep going

The next door is usually the interesting one

The answer you came for touches a few neighboring questions. These are the ones most likely to make the picture click.

What you should remember

Thirty seconds of knowing beats a lifetime of wondering

  • Have I Been Pwned won't undo a breach that's already happened. What it offers is the chance to stop guessing and start actually knowing, in about the time it takes to type an email address.
  • Have I Been Pwned lets anyone check their email or phone number against known data breaches for free
  • It shows which breaches you appeared in and what data was exposed, not your actual leaked password
  • A separate Pwned Passwords tool checks a specific password without linking it to your identity

A few useful next steps

Where this question wanders next

The dark web is less a single tunnel than a set of side passages. These are the useful ones from here.

If this made you wonder

Have I Been Pwned collection

what

What Is Credential Monitoring?

Your email and password could already be circulating in a criminal database somewhere. Credential monitoring is how you'd actually find out.

6 min read
what

What Is Dark Web Monitoring and How Does It Work?

Somewhere in a hidden corner of the internet, your personal information might already be for sale. Here's how you'd actually find out.

6 min read
what

Dark Web Monitoring: What It Is and How It Works

Dark web monitoring is a security service that searches selected breach datasets, criminal forums, leak sources and other monitored repositories for information associated with a person or organization. When matching information is detected, the service can generate an alert so the affected user can respond.

6 min read
what

What Does a Dark Web Monitoring Alert Actually Mean?

The subject line says 'your information was found on the dark web.' The actual mechanics behind that sentence are a lot less dramatic, and a lot more useful to understand.

6 min read
what

What Is a Data Broker Removal Service?

You never agreed to be a product on a shelf. Hundreds of companies decided that for you anyway — and this is who tries to take you back off it.

6 min read
what

I Got a Dark Web Alert — What Do I Do Now?

The notification lands with a jolt: your information was found on the dark web. Before you panic, here's what that actually means and the exact order of things to do about it.

6 min read

Build the basics

1

What Is Credential Monitoring?

Your email and password could already be circulating in a criminal database somewhere. Credential monitoring is how you'd actually find out.

2

What Is Dark Web Monitoring and How Does It Work?

Somewhere in a hidden corner of the internet, your personal information might already be for sale. Here's how you'd actually find out.

3

Dark Web Monitoring: What It Is and How It Works

Dark web monitoring is a security service that searches selected breach datasets, criminal forums, leak sources and other monitored repositories for information associated with a person or organization. When matching information is detected, the service can generate an alert so the affected user can respond.

4

What Does a Dark Web Monitoring Alert Actually Mean?

The subject line says 'your information was found on the dark web.' The actual mechanics behind that sentence are a lot less dramatic, and a lot more useful to understand.

5

What Is a Data Broker Removal Service?

You never agreed to be a product on a shelf. Hundreds of companies decided that for you anyway — and this is who tries to take you back off it.

Questions people ask first

Choose by the time in your pocket