Security Guides
How to check if your password was leaked: using Have I Been Pwned safely, and the checks already built into your browser and phone
How to check whether your password or email was leaked: what Have I Been Pwned can and cannot tell you, why it never receives your password, built-in checks in Google, iPhone and Edge, and what to do first.
Who this is for: anyone who wants to check whether their passwords or email address have leaked, or who is unsure whether "Have I Been Pwned" is safe to use. This guide is based on Have I Been Pwned's own documentation, official help pages from Google, Apple and Microsoft, and Japan's IPA (Information-technology Promotion Agency). The steps assume you are checking your own accounts on your own devices.
What Have I Been Pwned can and cannot tell you
Have I Been Pwned (HIBP) is a free service started by an independent security researcher. "Pwned" is internet slang for "taken over" or "compromised". On October 6, 2026 its home page listed 1,039 breached websites and about 17.8 billion breached accounts.
| What it can tell you | What it cannot tell you |
|---|---|
| Whether an email address appears in the data of a breach it has loaded | The password that leaked with it (HIBP does not store passwords next to email addresses) |
| Which service was breached and what kinds of data were exposed (passwords, phone numbers and so on) | Breaches whose data was never published (HIBP's FAQ says it holds "but a small subset" of breached records) |
| Whether a given password has appeared in breach data (Pwned Passwords) | Which of your accounts that password leaked from |
| Alerts when your address shows up in a future breach (Notify Me) | Every breach at a Japanese service (some are not included) |
Some breaches, such as those of dating sites where simply being named could cause harm, are classed as "sensitive". Only people who have verified that they own the email address can see those results.
How a password check works without sending your password
HIBP's Pwned Passwords uses a method called k-anonymity: you send only enough information to narrow the answer down to a large group of candidates, so the service cannot tell which one is yours. According to the official API documentation, the steps are:
1 Your device: hash the password
e.g. password → 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8 (SHA-1)
2 Send only the first five characters
5BAA6 → HIBP (the other 35 characters stay on your device)
3 HIBP returns every hash that starts with those five characters
Around 800 hash suffixes, each with a count of how often it appears in breach data
4 Your device: look for your own hash in the list
A match means the password has appeared in a breach. HIBP cannot tell which entry was yours
Hashing turns a password into a different string using a fixed calculation, and the result cannot be turned back into the password. See What is password hashing? for more. HIBP's own Pwned Passwords page says the password is hashed locally and only the first five characters of the SHA-1 hash are sent.
Using Have I Been Pwned safely
Type the official address yourself
Type haveibeenpwned.com into the address bar yourself. Do not open it from search ads or from links in email or social media. Any site that calls itself a "leak check" and asks for your password or card number is not HIBP.
Enter your email address and select Check
Type your email address into the box on the home page ("Check if your email address is in a data breach") and select Check. Searching by email address needs no account and no password.
Read the breach names and the data exposed
If there is a match, each breach is listed with when it happened and what kinds of data were exposed. Whether "Passwords" is among the exposed data decides how urgent the next steps are.
Optionally sign up for Notify Me
Notify Me sends you an email if your address appears in a future breach. You will first receive an email asking you to confirm that you own the address.
Do not type passwords you currently use into a website to check them
As described above, Pwned Passwords does not send your password. Even so, this site does not recommend checking a password you currently use by typing it into a website. A fake site that looks identical can steal it through exactly the same steps, and the habit of "typing my password to see if it leaked" is itself what scammers rely on. Check current passwords with the tools in the next section, which already store them.
Checks already built into your browser and phone
If you save passwords in your browser or phone, the same tool can compare them against breach data for you, without you typing anything in. Each vendor says passwords are hashed or encrypted before the comparison.
| Tool | Where to find it (labels from the official help pages) | Coverage and notes |
|---|---|---|
| Google Password Manager "Password Checkup" (Chrome on a computer) | More (top right) → "Passwords and autofill" → "Google Password Manager" → "Checkup" on the left | Shows passwords that are exposed, used in multiple accounts, or weak |
| Same (other browsers and phones) | Open passwords.google.com → "Go to Password Checkup" → "Check passwords" | Covers passwords saved to your Google Account |
| Chrome Safety Check (computer) | More → "Settings" → "Privacy and security" → "Go to Safety Check" under Safety Check | Turn on breach warnings in "Security" → "Warn you if a password was compromised in a data breach" |
| Chrome Safety Check (Android) | More → "Settings" → "Safety check" | Tap any item with an issue and follow the instructions |
| iPhone (iOS 18 and later) | Passwords app → "Security" | Turn detection on or off in Settings → "Apps" → "Passwords" → "Detect Compromised Passwords" |
| iPhone (iOS 17 and earlier) | Settings → "Passwords" → "Security Recommendations" | "Detect Compromised Passwords" is on the same screen |
| Microsoft Edge "Password Monitor" | "Settings and more" (…) → "Settings" → "Passwords and autofill" → "Microsoft Password Manager" → "Password security check" | Turn on "Enable leaked password scan in settings". Windows and macOS only |
| 1Password "Watchtower" | "Watchtower" in the app's sidebar (main menu on mobile) | Shows compromised, reused and weak passwords, missing two-factor authentication and more |
| Bitwarden "Reports" | "Reports" on the left in the web app | The Exposed Passwords report needs a premium plan; the free Data Breach report checks an email address against HIBP |
Bitwarden's help page also says it searches using only the first five characters of each password's hash and never exposes the password, the same method HIBP uses.
This site's view: check where your passwords are stored, not by typing them in
Searching for "check if my password was leaked" turns up many sites that ask you to type your password in. Even when such a site works correctly, you cannot confirm on the spot that it hashes the password before sending anything.
Built-in checks compare the passwords you have already saved without you entering anything, and they also flag passwords you reuse across sites on the same screen. Since real damage most often spreads through reused passwords, checking in the place where your passwords are stored is both easier and safer. If you do not save passwords anywhere yet, starting with a password manager is the first step to being able to check them.
What to do if a password shows up as leaked
Change that password everywhere you used it
Change it not only on the breached service but on every service where you used the same password or a small variation of it. Attackers try leaked email and password pairs on other sites, an attack known as credential stuffing, and Japan's IPA names "do not reuse passwords" as a basic defense against unauthorized logins. Change your email account's password first, because email is used to reset passwords for everything else.
Turn on multi-factor authentication for your main accounts
Multi-factor authentication asks for a second factor, such as an authenticator app or a passkey, in addition to the password. IPA explains that it stops a login even if someone has your ID and password. Start with email, your Apple, Google and Microsoft accounts, online banking and shopping. For which method to choose, see Which 2FA method is safest?
Check sign-in activity and settings changes
In each service's security settings, look for sign-ins from devices or places you do not recognize, and for changes you did not make to your recovery email, phone number or mail forwarding. For email accounts, how to tell if you were hacked walks through the three places to look.
Use a password manager to give every service its own password
With a long random password for each service, a future leak at one site stays at that site. For how this compares with paper or a notes app, see how to store passwords safely.
If the exposed data did not include passwords (only email addresses or names, for example), you may still receive phishing emails pretending to be the breached company or your card issuer. Do not sign in through links in emails or text messages.
What these checks cannot tell you
What the checks can find
- Passwords and email addresses from breach data that has circulated and been loaded into these services
- Saved passwords that are reused or easy to guess
What the checks cannot find
- Breaches a company has not announced, or whose data has not circulated
- Breaches at Japanese services that HIBP and similar sources have not loaded (some are missing)
- A password stolen moments ago by malware on your own device
Breaches at Japanese companies usually become known through the company's own announcement. This site keeps a list of incidents announced in 2026 in Japan and worldwide in the 2026 data breach and cyberattack timeline. If a service you use is listed, its article explains what leaked and what users should do.
Sources
The specifications and on-screen labels in this guide were checked against the following official pages on October 6, 2026.
- Have I Been Pwned, "API v3" (Pwned Passwords range API and k-anonymity) — haveibeenpwned.com
- Have I Been Pwned, "Pwned Passwords" — haveibeenpwned.com
- Have I Been Pwned, "FAQs" — haveibeenpwned.com
- Google, "Change compromised passwords in your Google Account" (Google Account Help) — support.google.com
- Google, "Manage Chrome safety and security" (computer and Android) — support.google.com
- Apple, "Change weak or compromised passwords on iPhone" (iOS 27 and iOS 17 editions) — support.apple.com
- Apple, "Password Monitoring" (Apple Platform Security) — support.apple.com
- Microsoft, "Use Password Monitor to help protect your passwords in Microsoft Edge" — support.microsoft.com
- 1Password, "Use Watchtower to find account details you need to change" — support.1password.com
- Bitwarden, "Vault Health Reports" — bitwarden.com
- IPA, "Special page on preventing unauthorized logins" (Japanese) — ipa.go.jp
Read next
FAQ
QIs Have I Been Pwned safe to use?
The official site, haveibeenpwned.com, is a free service started by an independent security researcher. It tells you whether your email address appears in known data breaches. Its FAQ says that when breach data is loaded, no passwords are loaded alongside the email addresses. The real risk is look-alike sites, so make sure the address bar shows haveibeenpwned.com before you use it.
QIs it safe to type my password in to check whether it leaked?
HIBP's Pwned Passwords hashes your password in the browser (turns it into a value that cannot be turned back) and sends only the first five characters of that hash, so the password itself is not sent. A fake site, however, can steal it from the same kind of form. For passwords you currently use, it is safer to rely on the checks in the browser or phone where they are already saved, such as Google Password Checkup or the iPhone Passwords app.
QHIBP says I've been pwned. What should I do?
It means your email address was in the data from the breaches listed. Look at each breach and the types of data exposed. If passwords were included, change the password for that service and for every other service where you used the same password. Then turn on multi-factor authentication for your main accounts and check their sign-in activity for anything you do not recognize.
QIf HIBP finds nothing, does that mean my data was never leaked?
No. HIBP's FAQ says it holds only a small subset of all breached records, and many breaches never lead to the data being published. Breaches at Japanese services, for example, are not always included. Also pay attention to breach notices from companies and to warnings from your browser's password check.
QCan I check for leaked passwords on my phone only?
Yes. On iPhone, open the Passwords app and tap Security (iOS 18 and later), or go to Settings > Passwords > Security Recommendations (iOS 17 and earlier). On Android, open Chrome and go to Settings > Safety check, or open passwords.google.com in a browser and select Go to Password Checkup.
QDoes Have I Been Pwned include breaches at Japanese services?
Not always. HIBP can only add a breach once the leaked data itself has been obtained and loaded. Many Japanese incidents are known only from the company's announcement, with no data circulating, and those will not show up in HIBP. For them, rely on the company's notice and this site's incident timeline.