๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ Passwords
Have I Been Pwned: Pwned Passwords
NIST guidelines specifically recommend checking user passwords against previously breached datasets. This service provides a simple, secure way to comply with these guidelines. Attackers automate login attempts using leaked credentials from other sites, exploiting password reuse habits.

consumer security website and email alert system

The homepage of haveibeenpwned.com. The website features white text on a black background. Prominently centered is the site's logo in a white and blue gradient. Below the logo is a search box labeled "email address" with a button beside it labeled "Check". Below the search box is a series of statistics about the size of the website's database.
Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a โ€ฆ Wikipedia
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Have I Been Pwned allows you to check whether your email address has been exposed in a data breach.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ NotifyMe
Have I Been Pwned: Get Breach Notifications
We've sent a verification link to your email address. Click the link to complete your notification setup.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ Dashboard
Have I Been Pwned: Sign In to Your Dashboard
Sign in to access your Have I Been Pwned dashboard, where you can search sensitive breaches, view stealer logs, manage domains, and access subscription features.
๐ŸŒ
Wikihow
wikihow.com โ€บ computers and electronics โ€บ internet โ€บ website application instructions โ€บ how to use have i been pwned: a complete guide
How to Use Have I Been Pwned: A Complete Guide
August 27, 2019 - Go to HaveIBeenPwned.com and enter your email address. Then, review if your data has been breached or not. If it has, change your passwords for the websites that have been breached.
๐ŸŒ
1Password
1password.com โ€บ haveibeenpwned
Have I Been Pwned | 1Password
Discovered your data was breached? Learn about Have I Been Pwned and how 1Password can secure your online accounts and sensitive information.
๐ŸŒ
Tines
explained.tines.com โ€บ en โ€บ articles โ€บ 8472679-have-i-been-pwned-authentication-guide
Have I Been Pwned Authentication Guide | Tines Explained
HaveIBeenPwnd is free resource ... in a data breach. Login to/Signup to HaveIBeenPwned and purchase a key at https://haveibeenpwned.com/API/Key....
Find elsewhere
๐ŸŒ
Wikipedia
en.wikipedia.org โ€บ wiki โ€บ Have_I_Been_Pwned
Have I Been Pwned? - Wikipedia
1 month ago - Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a valuable resource for Internet users wishing to protect their own security and privacy.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ About
Have I Been Pwned: Who, What & Why
Learn about Have I Been Pwned, why it was created, who runs it, and how it helps people discover if their personal data has been exposed in data breaches.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ PwnedWebsites
Have I Been Pwned: Who's Been Pwned
A "breach" is an incident where a site's data has been illegally accessed by hackers and then released publicly. Review these breaches to see what personal information was compromised and take appropriate action, such as changing passwords.
๐ŸŒ
Trustpilot
uk.trustpilot.com โ€บ home โ€บ electronics & technology โ€บ internet & software โ€บ software company โ€บ have i been pwned reviews
Have I Been Pwned Reviews | Read Customer Service Reviews of haveibeenpwned.com
5 days ago - Something odd is going on there, if you send us the addresses in a support ticket Iโ€™ll look into it for you: https://support.haveibeenpwned.com/
Address ย  4217, Surfers Paradise, AU
(3.6)
Top answer
1 of 7
97

This question was explained by Troy Hunt several times on his blog, on Twitter and in the FAQ of haveibeenpwned.com

See here:

When you search for an email address

Searching for an email address only ever retrieves the address from storage then returns it in the response, the searched address is never explicitly stored anywhere. See the Logging section below for situations in which it may be implicitly stored.

Data breaches flagged as sensitive are not returned in public searches, they can only be viewed by using the notification service and verifying ownership of the email address first. Sensitive breaches are also searchable by domain owners who prove they control the domain using the domain search feature. Read about why non-sensitive breaches are publicly searchable.

See also the Logging paragraph

And from the FAQ:

How do I know the site isn't just harvesting searched email addresses?

You don't, but it's not. The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Of course we have to trust Troy Hunt on his claims, as we have no way of proving that he is not doing something else, when handling your specific request.
But I think it is more than fair to say, that haveibeenpwned is a valuable service and Troy Hunt himself is a respected member of the infosec community.

But let's suppose we don't trust Troy: what do you have to lose? You might disclose your email address to him. How big of a risk is that to you, when you can just enter any email address you want?

At the end of the day, HIBP is a free service for you(!) that costs Troy Hunt money. You can choose to search through all the password databases of the world yourself if you don't want to take the risk that maybe a lot of people are wrong about Troy Hunt, just because then you would disclose your email address.

2 of 7
16

Troy Hunt is a very respected Information Security professional and this service is being used by millions of people worldwide, even by some password managers to verify if the passwords selected by the users have been involved in a data breach.

See for example, https://1password.com/haveibeenpwned/

As per the website, 1Password integrates with the popular site Have I Been Pwned to keep an eye on your logins for any potential security breaches or vulnerabilities.

Entering your email address on this site will tell you which data breaches involve this email address, so that you can go back to the affected website and change your password. This is esp. important if you have used the same password for multiple websites, where credentials stolen from one site can be used to attack other sites in a technique also called Credential Stuffing attack.

The following StackExchange post has a response from Troy himself with further clarification on this service: Is "Have I Been Pwned's" Pwned Passwords List really that useful?

๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ API โ€บ v3
Have I Been Pwned: API Documentation
This is due to a combination of the size of the data being queried and the nature of the APIs not requiring the same rate of requests. Note: there are no API endpoints that return the password for a user. Passwords are independently searchable via the Pwned Passwords service. This search is based on the full email address captured by an info stealer as the owner authenticated to a website. GET https://haveibeenpwned.com/api/v3/stealerlogsbyemail/{email address} hibp-api-key: [your key]
๐ŸŒ
Hacker News
news.ycombinator.com โ€บ item
https://haveibeenpwned.com Make sure that you don't have any insecure accounts o... | Hacker News
October 3, 2017 - For example, given the email address [email protected], if I were to sign up for facebook with [email protected], does the HIBP site provide a simplified method for checking all variations ยท Does anyone know of a similar site that provides hashes?
๐ŸŒ
Reddit
reddit.com โ€บ r/privacy โ€บ how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
๐ŸŒ
Reddit
reddit.com โ€บ r/privacy โ€บ beware the fakesite havelbeenpwnd
r/privacy on Reddit: Beware the fakesite havelbeenpwnd
June 20, 2025 -

Due to the recent breach news, a lot of people are checking to see if they were involved. Be careful if searching for haveibeenpwned on certain browsers like duckduckgo. Anywhere from the second to the fifth result is a fake site called havelbeenpwnd.com. It will load the old version of the website and can even link to the new version if navigated on. However, any search leads to a 404 error.

This fake site is actually named: have l(lowercase L) been pwnd(no e here).com. Others suspect it is a data harvesting site at the least. The real site is haveibeenpwned.com. Posting this to potentially help others to avoid this pitfall in privacy.

*Edited for clarity.