Have I Been Pwned
Check if your email or phone has been compromised in a data breach.
Open the official app on haveibeenpwned.com
This tool is hosted by its maintainers. Click below to open haveibeenpwned.com in a new tab — it's their official demo.
Browse network tools →What's next with Have I Been Pwned?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Have I Been Pwned?
Have I Been Pwned is an open-source web tool designed to check whether an email address has been exposed in known data breaches. It aggregates and analyzes breach data from public records, helping users identify if their personal information has been compromised. The tool is primarily used by individuals, cybersecurity professionals, and organizations to assess the risk of data exposure. By providing historical breach timelines and breach-specific details, it users to take proactive steps to protect their accounts. The tool addresses the growing concern of data breaches by offering transparency about which email addresses have been involved in security incidents, enabling users to mitigate potential harm from identity theft or credential stuffing attacks. The tool solves the problem of users being unaware of their data's exposure. Many breaches are not immediately known to affected individuals, but Have I Been Pwned centralizes this information, making it accessible without requiring technical expertise. It also highlights the importance of password management and account security by linking breaches to compromised credentials. Its open-source nature allows for community contributions, ensuring the tool remains updated with the latest breach data. Users can leverage this information to strengthen their online security practices, such as changing passwords or enabling two-factor authentication.
How it works
Have I Been Pwned is a web-based service that checks if an email address has appeared in public data breaches. It provides users with a clear overview of their exposure risk by querying a database of breach records. The tool is maintained as an open-source project, allowing developers to contribute to its growth and adaptability. Its primary purpose is to inform users about the security status of their email addresses. By revealing whether an email has been part of a breach, it helps individuals and organizations take action to secure their accounts. The tool also tracks the history of breaches associated with an email, offering insights into when and how data may have been compromised. The tool can check if an email has been exposed in breaches, display the number of breaches linked to it, and provide details about each incident. For example, it might show the date of the breach, the source of the data leak, and the number of affected addresses. It also includes a feature to notify users if their email appears in future breaches, though this requires opting in for email alerts.
How to use it
- 1Open the Have I Been Pwned page
- 2Use the tool directly in your browser
- 3Results appear instantly — no waiting, no downloads
What it can do
- AI Tools
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/haveibeenpwned
- license: Open source
- privacy: Opens an external demo
Limitations
- Does not check for exposure of other personal data beyond email addresses
- Relies on a database that may not include all known breaches
- Does not provide real-time alerts for new breaches unless users opt in
- Lacks features for checking password strength or generating secure passwords
- Cannot verify if an email is linked to compromised credentials directly
Understanding the result
Check if your email or phone has been compromised in a data breach.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by haveibeenpwned (MIT).
- Built with
- haveibeenpwned (https://github.com/haveibeenpwned)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Text
- Output
- Output
Built with https://github.com/haveibeenpwned. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- haveibeenpwned
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- /haveibeenpwned — GitHub Repository
Upstream project · GitHub
Frequently asked
How does Have I Been Pwned determine if an email has been breached?
The tool queries a database of known breaches compiled from public records, text-sharing sites, and data leaks. When an email is entered, it cross-references it against these records to identify matches. Breach details, such as the date and source of the leak, are retrieved from the database to provide context about the exposure.
How does the tool handle large-scale breach data?
Have I Been Pwned uses a k-anonymity approach to anonymize breach data, ensuring privacy while allowing efficient searches. This method groups data in a way that prevents individual identification, making it possible to check for breaches without exposing sensitive information. The tool's architecture is optimized to handle the massive scale of breach data, with millions of compromised addresses indexed for quick lookup.
How can I check if my email was part of a specific breach?
Navigate to the Have I Been Pwned website and enter your email address. If the email is linked to a breach, click 'Review details' to see a list of associated breaches. Each entry will include the breach name, date, and the number of affected addresses. This allows users to identify specific incidents and take targeted action, such as changing passwords for affected accounts.
How does Have I Been Pwned compare to other breach-checking tools?
Have I Been Pwned is notable for its open-source model and extensive breach database, which includes over 17 billion compromised email addresses. Unlike some proprietary tools, it allows community contributions and transparency in data curation. Alternatives like BreachDB or Have I Been Pwned's GitHub repositories offer similar functionality but may have smaller datasets or less active maintenance.
What should I do if my email is found in a breach?
If your email is linked to a breach, immediately change your password for the affected account. Enable two-factor authentication (2FA) if available, and monitor your accounts for suspicious activity. Consider using a password manager to generate unique, strong passwords for all accounts. If the breach involved sensitive data, contact the affected service provider for further guidance.