๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ Passwords
Have I Been Pwned: Pwned Passwords
NIST guidelines specifically recommend checking user passwords against previously breached datasets. This service provides a simple, secure way to comply with these guidelines. Attackers automate login attempts using leaked credentials from other sites, exploiting password reuse habits.

consumer security website and email alert system

The homepage of haveibeenpwned.com. The website features white text on a black background. Prominently centered is the site's logo in a white and blue gradient. Below the logo is a search box labeled "email address" with a button beside it labeled "Check". Below the search box is a series of statistics about the size of the website's database.
Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a โ€ฆ Wikipedia
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Have I Been Pwned allows you to check whether your email address has been exposed in a data breach.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ Dashboard
Have I Been Pwned: Sign In to Your Dashboard
Sign in to access your Have I Been Pwned dashboard, where you can search sensitive breaches, view stealer logs, manage domains, and access subscription features.
๐ŸŒ
1Password
1password.com โ€บ haveibeenpwned
Have I Been Pwned | 1Password
Discovered your data was breached? Learn about Have I Been Pwned and how 1Password can secure your online accounts and sensitive information.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ NotifyMe
Have I Been Pwned: Get Breach Notifications
We've sent a verification link to your email address. Click the link to complete your notification setup.
๐ŸŒ
Wikipedia
en.wikipedia.org โ€บ wiki โ€บ Have_I_Been_Pwned
Have I Been Pwned? - Wikipedia
1 month ago - Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a valuable resource for Internet users wishing to protect their own security and privacy.
๐ŸŒ
Wikihow
wikihow.com โ€บ computers and electronics โ€บ internet โ€บ website application instructions โ€บ how to use have i been pwned: a complete guide
How to Use Have I Been Pwned: A Complete Guide
August 27, 2019 - Go to HaveIBeenPwned.com and enter your email address. Then, review if your data has been breached or not. If it has, change your passwords for the websites that have been breached.
Find elsewhere
๐ŸŒ
Tines
explained.tines.com โ€บ en โ€บ articles โ€บ 8472679-have-i-been-pwned-authentication-guide
Have I Been Pwned Authentication Guide | Tines Explained
HaveIBeenPwnd is free resource ... in a data breach. Login to/Signup to HaveIBeenPwned and purchase a key at https://haveibeenpwned.com/API/Key....
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ PwnedWebsites
Have I Been Pwned: Who's Been Pwned
A "breach" is an incident where a site's data has been illegally accessed by hackers and then released publicly. Review these breaches to see what personal information was compromised and take appropriate action, such as changing passwords.
๐ŸŒ
Reddit
reddit.com โ€บ r/techsupport โ€บ is the site haveibeenpwned a legit page?
r/techsupport on Reddit: Is the site haveibeenpwned a legit page?
September 16, 2022 -

today ive been trying to keep my account secure over scam anti virus software that I have installed. someone recommended me this site to see if any personal info of mines has been leaked. ran a scan and everything seems to be good for now? i then also did a scan for the site itself after words on virus total and it gave me a message saying "1 security vendor flagged this URL as malicious". not sure if I should be concerned abt that information and hopefully this site isn't a scam innit of itself

Top answer
1 of 7
97

This question was explained by Troy Hunt several times on his blog, on Twitter and in the FAQ of haveibeenpwned.com

See here:

When you search for an email address

Searching for an email address only ever retrieves the address from storage then returns it in the response, the searched address is never explicitly stored anywhere. See the Logging section below for situations in which it may be implicitly stored.

Data breaches flagged as sensitive are not returned in public searches, they can only be viewed by using the notification service and verifying ownership of the email address first. Sensitive breaches are also searchable by domain owners who prove they control the domain using the domain search feature. Read about why non-sensitive breaches are publicly searchable.

See also the Logging paragraph

And from the FAQ:

How do I know the site isn't just harvesting searched email addresses?

You don't, but it's not. The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Of course we have to trust Troy Hunt on his claims, as we have no way of proving that he is not doing something else, when handling your specific request.
But I think it is more than fair to say, that haveibeenpwned is a valuable service and Troy Hunt himself is a respected member of the infosec community.

But let's suppose we don't trust Troy: what do you have to lose? You might disclose your email address to him. How big of a risk is that to you, when you can just enter any email address you want?

At the end of the day, HIBP is a free service for you(!) that costs Troy Hunt money. You can choose to search through all the password databases of the world yourself if you don't want to take the risk that maybe a lot of people are wrong about Troy Hunt, just because then you would disclose your email address.

2 of 7
16

Troy Hunt is a very respected Information Security professional and this service is being used by millions of people worldwide, even by some password managers to verify if the passwords selected by the users have been involved in a data breach.

See for example, https://1password.com/haveibeenpwned/

As per the website, 1Password integrates with the popular site Have I Been Pwned to keep an eye on your logins for any potential security breaches or vulnerabilities.

Entering your email address on this site will tell you which data breaches involve this email address, so that you can go back to the affected website and change your password. This is esp. important if you have used the same password for multiple websites, where credentials stolen from one site can be used to attack other sites in a technique also called Credential Stuffing attack.

The following StackExchange post has a response from Troy himself with further clarification on this service: Is "Have I Been Pwned's" Pwned Passwords List really that useful?

๐ŸŒ
Google Cloud
cloud.google.com โ€บ security โ€บ google security operations โ€บ have i been pwned
Have I Been Pwned | Google Security Operations | Google Cloud
An API Key needs to be purchased ... for the HaveIBeenPwned integration. Note: For more detailed information, see Have I Been Pwned API Documentation. For detailed instructions on how to configure an integration in Google SecOps, see Configure integrations. Check if you have an account that has been compromised in a data ...
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ About
Have I Been Pwned: Who, What & Why
Learn about Have I Been Pwned, why it was created, who runs it, and how it helps people discover if their personal data has been exposed in data breaches.
๐ŸŒ
Hacker News
news.ycombinator.com โ€บ item
https://haveibeenpwned.com Make sure that you don't have any insecure accounts o... | Hacker News
October 3, 2017 - For example, given the email address [email protected], if I were to sign up for facebook with [email protected], does the HIBP site provide a simplified method for checking all variations ยท Does anyone know of a similar site that provides hashes?
๐ŸŒ
Trustpilot
uk.trustpilot.com โ€บ home โ€บ electronics & technology โ€บ internet & software โ€บ software company โ€บ have i been pwned reviews
Have I Been Pwned Reviews | Read Customer Service Reviews of haveibeenpwned.com
5 days ago - Something odd is going on there, if you send us the addresses in a support ticket Iโ€™ll look into it for you: https://support.haveibeenpwned.com/
Address ย  4217, Surfers Paradise, AU
(3.6)
๐ŸŒ
TeamPassword
teampassword.com โ€บ blog โ€บ have-i-been-pwnd-what-to-do-when-it-happens
TeamPassword | What to Do if You've Been Pwned: A Complete Guide
HIBP allows you to quickly check ... of the compromised websites and accounts in its database. Related Reading: The 5-Minute Monthly Security Audit: How to Prevent 90% of Breaches ยท Finding out if your information has been exposed is simple and takes less than a minute. Visit the Website Navigate to the official Have I Been Pwned? website: https://haveibeenpwned.c...