It's safe -- You can even put your password in there to check. The way it works is pretty clever: Your password gets hashed, and the first 5 characters of that hash are sent to the server Server responds with all known passwords that have a hash that share the same first 5 characters The password you entered is compared to the list of passwords returned (this step is done entirely in your browser) https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/#cloudflareprivacyandkanonymity Answer from bothunter on reddit.com
🌐
Reddit
reddit.com › r/techsupport › is the site haveibeenpwned a legit page?
r/techsupport on Reddit: Is the site haveibeenpwned a legit page?
September 16, 2022 -

today ive been trying to keep my account secure over scam anti virus software that I have installed. someone recommended me this site to see if any personal info of mines has been leaked. ran a scan and everything seems to be good for now? i then also did a scan for the site itself after words on virus total and it gave me a message saying "1 security vendor flagged this URL as malicious". not sure if I should be concerned abt that information and hopefully this site isn't a scam innit of itself

🌐
Reddit
reddit.com › r/privacy › how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
🌐
Reddit
reddit.com › r/privacy › beware the fakesite havelbeenpwnd
r/privacy on Reddit: Beware the fakesite havelbeenpwnd
June 20, 2025 -

Due to the recent breach news, a lot of people are checking to see if they were involved. Be careful if searching for haveibeenpwned on certain browsers like duckduckgo. Anywhere from the second to the fifth result is a fake site called havelbeenpwnd.com. It will load the old version of the website and can even link to the new version if navigated on. However, any search leads to a 404 error.

This fake site is actually named: have l(lowercase L) been pwnd(no e here).com. Others suspect it is a data harvesting site at the least. The real site is haveibeenpwned.com. Posting this to potentially help others to avoid this pitfall in privacy.

*Edited for clarity.

Find elsewhere
🌐
Reddit
reddit.com › r › HaveIBeenPwned
Have I been Pwned?
December 6, 2016 - I would like to know whether any password I use has been seen before I actually visit the website, but I've got hundreds. ... Maybe a leaked email spam list, but it only contained emails and IP addresses. No names or anything. Would that be added to the haveibeenpwnd database? ... Just found out about this website. Turns out I was compromised in the old nexusmods and dueling nexus data breaches a few years back. However, when testing any important password on pwned passwords its comes back clean with no instances of pwnage.
🌐
Reddit
reddit.com › r/youshouldknow › ysk there is a website called haveibeenpwned.com that tells you if your email address has been involved in data breaches.
r/YouShouldKnow on Reddit: YSK There is a website called haveibeenpwned.com that tells you if your email address has been involved in data breaches.
January 9, 2019 -

https://haveibeenpwned.com/ allows you to check if your email address has been involved in a data breach. It can tell you if your password has been exposed as well as many other personal details such as your name, IP address, age, gender and even financial details. Scammers can then use this information to their advantage.

This website was a huge eye-opener for me and it saved me from trouble following a recent data breach. Make sure your information is safe!

🌐
Reddit
reddit.com › r/technews › have i been pwned adds 183 million more emails from major new breach
r/technews on Reddit: Have I Been Pwned adds 183 million more emails from major new breach
October 25, 2025 - Why won't they tell you what the password was that was breached? My info has been breached so many times the fact an email is out there in the wild isn't concerning, but it would be hugely helpful to know the password paired with it and whether it is compromised or not. But Have I Been Pwned and the paid
🌐
Reddit
reddit.com › r/privacy › haveibeenpwned.com passwords
r/privacy on Reddit: HaveIBeenPwned.com Passwords
January 26, 2022 -

I know this website is safe to check your email addresses. I noticed that there is a 'Passwords' section and you can enter your passwords in there to see if they have been breached.

This might sound like a stupid question, but is it actually safe to enter your password here to check to see if it has been breached?

🌐
Reddit
reddit.com › r/cybersecurity_help › can i trust https://haveibeenpwned.com?
r/cybersecurity_help on Reddit: Can I trust https://haveibeenpwned.com?
August 14, 2022 -

I just want to check my emails for a data breach, but can i enter my email safely or could I get hacked?

🌐
Reddit
reddit.com › r/asknetsec › is haveibeenpwned accurate???
r/AskNetsec on Reddit: Is haveibeenpwned accurate???
November 4, 2021 -

I have heard about haveibeenpwned and checked if my email or password was pwned but it wasn't still I recieved login attempt on instagram so is it accurate ?

But there was data breach from instagram of 2.6 million users same day when i got login attempt..

Note - I have not clicked any phis link etcc.....

🌐
Reddit
reddit.com › r/cybersecurity_help › i have been pwned. what should i do?
r/cybersecurity_help on Reddit: I have been pwned. What should I do?
October 30, 2023 -

I tried my email on haveibeenpwned.com and found out that it was included in 2 breaches, one was Chess.com back in November 2023, which isn't too big of a deal I presume as I use different passwords through all my accounts, but the second was Naz.API which I have no idea what it is.

It says it's a breach that happened in September 2023, it says that "the incident contained a combination of email address and plain text password pairs alongside the service they were entered into, and standalone credential pairs obtained from unnamed sources."

I'm not sure if I should be worried or not, because differently to the chess breach, I don't know if only specific passwords were included or if all of them were, and I don't know what's the best thing to do right now to secure my accounts even though it had been several months since the breach where I haven't had any problems.

🌐
Reddit
reddit.com › r/cybersecurity_help › i found my email in have i been pwned
r/cybersecurity_help on Reddit: I found my email in have i been pwned
December 4, 2024 -

Basically this morning I was subscribed to a youtube channel I wasn’t subscribed to and it was like a bot channel. I do some digging and my email was in one data breach but no pastes in have i been pwned and my google account doesn’t look like there’s suspicious activity, but i checked that dark web alert thing and it says one thing was found on the dark web (maybe my email?) didn’t exactly tell me what, but i’m terrified and not really sure what to do, so far i just changed my password on my email.