Has my password leaked?
Check whether a password you use has appeared in a public data leak. It never leaves your browser, and we never learn what you checked.
Free · runs in your browser · no signupYour password stays in your browser. Nothing you type here reaches us, and we never find out what you checked or what the answer was.
Why you can safely type a real password here
Asking someone to type a password into a web page should make you suspicious. So here is exactly what happens, and a way to check it for yourself.
Your password never leaves your device. Your browser first turns it into a long code, then sends only the first five characters of that code. Those five characters match hundreds of completely unrelated passwords, so on their own they say nothing about yours. What comes back is that whole batch of possibilities, and your browser does the final comparison itself, here on your machine.
That is why we never find out what you typed, and never find out whether it was found. Neither does the service that holds the leak records.
What a match actually means
It does not mean someone has broken into your account, and it does not mean you were careless. It means this exact password sits in data stolen from some company at some point, and that data is now circulating publicly.
The reason that matters is reuse. Attackers take those leaked lists and try them, in bulk, against every other site. So the risk is not really the site the password leaked from. It is every other place you used the same one.
If your password was found
- Start with your email account. Whoever controls your email can reset the password on everything else, so it is the one that protects all the others.
- Then change it anywhere else you have used that password. Be honest with yourself about how many places that is.
- Switch on two-step login on those accounts.
- Give each account its own password from now on. You can make one here, and a password manager will remember them for you.
If it was not found
That is genuinely good news, but it is not a clean bill of health. We can only check against leaks that are public and catalogued. A password like “summer2024” has probably never leaked and would still be guessed in seconds. If it is short or predictable, replace it anyway.
Common questions
Am I really safe typing my password here?
Yes, and not because you have to take our word for it. Your password never leaves your device. Your browser turns it into a long code, then sends only the first five characters of that code. Those five characters match hundreds of unrelated passwords, so they cannot identify yours. Your browser does the final comparison itself, which is why nobody, including us, ever learns your password or the answer.
It found my password. How bad is this?
Bad enough to act on today, and it is not personal. It means this exact password appears in data stolen from some company and now shared publicly. Attackers try those lists first. Change it on your email account first, then anywhere else you have used it.
It was not found. Does that mean it is a good password?
Not by itself. We can only check against leaks that are public and catalogued. A password like "summer2024" may never have leaked and would still be guessed quickly. Length is what makes one hard to break.
Where does the leak information come from?
From Have I Been Pwned, a long-running and widely trusted service that collects passwords exposed in publicly known data breaches. It is the same source many password managers use.
Should I change every password if one is found?
Change the found one everywhere you used it, and start with your email account, because whoever controls your email can reset the rest. If you tend to reuse passwords, that is the habit worth fixing rather than any single password.