The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving. Answer from lo________________ol on reddit.com
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving. Answer from lo________________ol on reddit.com
🌐
Reddit
reddit.com › r/privacy › how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
🌐
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Have I Been Pwned allows you to check whether your email address has been exposed in a data breach.
Discussions

passwords - Is it safe to give my email address to a service like haveibeenpwned in light of the publication of "Collection #1"? - Information Security Stack Exchange
To be honest - can it be - has it been - independantly verified that haveibeenpwned.com is safe? I don't doubt it is, but really what I'm going on is little more than trust. Has there been any 3rd party penetration testing analysis? More on security.stackexchange.com
🌐 security.stackexchange.com
Is the security check website "Have I Been Pwned?" legit? - Bogleheads.org
I have recently been told about a email security website check website called: "Have I Been Pwned?" Is it legitimate? Thoughts? Here is a link to Wikipedia talking about the website: haveibeenpwned (wikipedia link with definition) I have not included a live link to the website: "Have I been ... More on bogleheads.org
🌐 bogleheads.org
January 18, 2019
Is Haveibeenpwned safe? I typed my gmail id and clicked pwned? And now i am scared to get hacked - Google Account Community
Skip to main content · Google Account Help · Sign in · Google Help · Help Center · Community · Google Account · Terms of Service · Submit feedback · Send feedback on More on support.google.com
🌐 support.google.com
March 6, 2021
Anybody using and any thoughts on legitimacy?
Hi! Ran across https://haveibeenpwned.com/ and I am not sure if it is good to enter passwords and check of they have been compromised. Any thoughts? More on community.spiceworks.com
🌐 community.spiceworks.com
23
35
October 21, 2018
🌐
Vertex Cyber Security
vertexcybersecurity.com.au › should-i-use-have-i-been-pwned-hibps
Should I use Have I been pwned (HIBP) ? - Vertex Cyber Security
August 15, 2024 - Firstly volunteering information to any service should have an appropriate privacy policy as part of the signup or data submission. “Have I been pwned” has no such privacy policy or agreement when submitting an email address.
Top answer
1 of 7
97

This question was explained by Troy Hunt several times on his blog, on Twitter and in the FAQ of haveibeenpwned.com

See here:

When you search for an email address

Searching for an email address only ever retrieves the address from storage then returns it in the response, the searched address is never explicitly stored anywhere. See the Logging section below for situations in which it may be implicitly stored.

Data breaches flagged as sensitive are not returned in public searches, they can only be viewed by using the notification service and verifying ownership of the email address first. Sensitive breaches are also searchable by domain owners who prove they control the domain using the domain search feature. Read about why non-sensitive breaches are publicly searchable.

See also the Logging paragraph

And from the FAQ:

How do I know the site isn't just harvesting searched email addresses?

You don't, but it's not. The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Of course we have to trust Troy Hunt on his claims, as we have no way of proving that he is not doing something else, when handling your specific request.
But I think it is more than fair to say, that haveibeenpwned is a valuable service and Troy Hunt himself is a respected member of the infosec community.

But let's suppose we don't trust Troy: what do you have to lose? You might disclose your email address to him. How big of a risk is that to you, when you can just enter any email address you want?

At the end of the day, HIBP is a free service for you(!) that costs Troy Hunt money. You can choose to search through all the password databases of the world yourself if you don't want to take the risk that maybe a lot of people are wrong about Troy Hunt, just because then you would disclose your email address.

2 of 7
16

Troy Hunt is a very respected Information Security professional and this service is being used by millions of people worldwide, even by some password managers to verify if the passwords selected by the users have been involved in a data breach.

See for example, https://1password.com/haveibeenpwned/

As per the website, 1Password integrates with the popular site Have I Been Pwned to keep an eye on your logins for any potential security breaches or vulnerabilities.

Entering your email address on this site will tell you which data breaches involve this email address, so that you can go back to the affected website and change your password. This is esp. important if you have used the same password for multiple websites, where credentials stolen from one site can be used to attack other sites in a technique also called Credential Stuffing attack.

The following StackExchange post has a response from Troy himself with further clarification on this service: Is "Have I Been Pwned's" Pwned Passwords List really that useful?

🌐
Bogleheads.org
bogleheads.org › board index › community › personal consumer issues
Is the security check website "Have I Been Pwned?" legit? - Bogleheads.org
January 18, 2019 - ... Popular today due to this: https://www.marketwatch.com/story/773-m ... 2019-01-18 ... Yes, although they don't have every exploit in their database. They tend to just have the major ones reported on in the news. ... Big fan of Troy Hunt and his blog and the HaveIBeenPwned website.
Find elsewhere
🌐
Trustpilot
trustpilot.com › home › electronics & technology › internet & software › software company › have i been pwned reviews
Have I Been Pwned Reviews | Read Customer Service Reviews of haveibeenpwned.com
4 days ago - People who write reviews have ownership to edit or delete them at any time, and they’ll be displayed as long as an account is active. Companies can ask for reviews via automatic invitations. Labeled Verified, they’re about genuine experiences. Learn more about other kinds of reviews. We use dedicated people and clever technology to safeguard our platform.
Address   4217, Surfers Paradise, AU
(3.6)
🌐
Washburn
blog.washburn.edu › security › 2024 › 03 › hibp.html
Have you been pwned, Ichabod?
It is highly recommended that all Ichabods use and subscribe to HIBP for their Washburn accounts to prevent any loss of data, and malicious activity. Additionally, it’s a good idea to frequently change your passwords and never reuse them on other sites. Keep an eye out for fraudulent emails ...
🌐
Quora
quora.com › Is-Haveibeenpwned-safe
Is Haveibeenpwned safe? - Quora
Answer: Yes. It has been vetted by a lot of security professionals and is run by someone who works at Microsoft and has an excellent reputation. The site does NOT retain any information when you plug in your address.
🌐
Nudge Security
nudgesecurity.com › security-profile › haveibeenpwned-com
Security - Have I Been Pwned
Review the complete security profile for Have I Been Pwned, including supply chain details, privacy policy, terms of service, GDPR compliance, breach history, and more.
🌐
PCMAG
pcmag.com › home › news › security
Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email | PCMag
March 25, 2025 - However, the hacker behind the phishing attack appears to have only stolen the email addresses of those who subscribed to Troy Hunt's blog, rather than Haveibeenpwned.com.
🌐
Have I Been Pwned
haveibeenpwned.com › Privacy
Have I Been Pwned: Privacy Policy
We do not collect or store your personal information when you conduct a search in the HIBP database. Searching for an email address or phone number only ever retrieves the data from storage then returns it in the response.
🌐
Have I Been Pwned
haveibeenpwned.com › FAQs
Have I Been Pwned: Frequently Asked Questions
As with any website, if you're concerned about the intent or security, don't use it. Sure, you can construct a link so that the search for a particular account happens automatically when it's loaded, just pass the name after the "account" path.
🌐
Have I Been Pwned
haveibeenpwned.com › Passwords
Have I Been Pwned: Pwned Passwords
Password reuse is extremely common and puts your accounts at risk.
🌐
F-Secure
f-secure.com › us-en › articles
Useful online security tips and articles | F‑Secure
True cyber security combines advanced technology and best practice. Get tips and read articles on how to take your online security even further.
🌐
SlashGear
slashgear.com › 1826787 › have-i-been-pwned-legit-safety-concerns-explained
Is 'Have I Been Pwned' Legit? Here's How The Website Works - SlashGear
April 8, 2025 - While it may look simple on the surface, the service is actually a powerful tool to help protect your privacy online.
🌐
Malwarebytes
malwarebytes.com › home › “have i been pwnd?”– what is it and what to do when you *are* pwned
"Have I been pwnd?"-- What is it and what to do when you *are* pwned
May 19, 2021 - You use Have I Been Pwned (HIBP) to check if your data has been compromised. What you do next when pwned takes a couple of steps.
🌐
1Password
1password.com › haveibeenpwned
Have I Been Pwned | 1Password
Discovered your data was breached? Learn about Have I Been Pwned and how 1Password can secure your online accounts and sensitive information.