๐ŸŒ
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Oh no โ€” pwned! This email address has been found in multiple data breaches.
FAQs
Find answers to frequently asked questions about Have I Been Pwned, including data sources, breach handling, notification services, and account security.
Notify Me
Get notified if your email address appears in a future data breach. Have I Been Pwned will alert you when we find your email address is exposed.
Passwords
Pwned Passwords is a huge corpus of previously breached passwords made freely available to help services block them from being used again.
Who's Been Pwned
Every breached website added to Have I Been Pwned appears here on the Whoโ€™s Been Pwned page. As of today, there are 929 breached sites listed.

consumer security website and email alert system

The homepage of haveibeenpwned.com. The website features white text on a black background. Prominently centered is the site's logo in a white and blue gradient. Below the logo is a search box labeled "email address" with a button beside it labeled "Check". Below the search box is a series of statistics about the size of the website's database.
Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a โ€ฆ Wikipedia
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
๐ŸŒ
Reddit
reddit.com โ€บ r/privacy โ€บ how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
Discussions

Is Haveibeenpwned safe? I typed my gmail id and clicked pwned? And now i am scared to get hacked - Google Account Community
Skip to main content ยท Google Account Help ยท Sign in ยท Google Help ยท Help Center ยท Community ยท Google Account ยท Terms of Service ยท Submit feedback ยท Send feedback on More on support.google.com
๐ŸŒ support.google.com
March 6, 2021
passwords - Is it safe to give my email address to a service like haveibeenpwned in light of the publication of "Collection #1"? - Information Security Stack Exchange
There is a new big case of stolen login/password data in the news. At the same time, I am reading that there are services that let you check if your own login data is affected, e.g. Have I Been Pwned. Is it safe to enter my email address there to find out whether I need to change my passwords? More on security.stackexchange.com
๐ŸŒ security.stackexchange.com
Anybody using and any thoughts on legitimacy?
Hi! Ran across https://haveibeenpwned.com/ and I am not sure if it is good to enter passwords and check of they have been compromised. Any thoughts? More on community.spiceworks.com
๐ŸŒ community.spiceworks.com
23
35
October 21, 2018
Haveibeenpwned - new feature _very_ expensive
Data hosting is noT cheap man, Troy cant give this away for free as more people become aware of his project. More on reddit.com
๐ŸŒ r/cybersecurity
28
170
February 26, 2025
๐ŸŒ
Vertex Cyber Security
vertexcybersecurity.com.au โ€บ should-i-use-have-i-been-pwned-hibps
Should I use Have I been pwned (HIBP) ? - Vertex Cyber Security
August 15, 2024 - The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it. So is this enough of a ...
๐ŸŒ
Google Support
support.google.com โ€บ accounts โ€บ thread โ€บ 101022937 โ€บ is-haveibeenpwned-safe-i-typed-my-gmail-id-and-clicked-pwned-and-now-i-am-scared-to-get-hacked
Is Haveibeenpwned safe? I typed my gmail id and clicked pwned? And now i am scared to get hacked - Google Account Community
March 6, 2021 - Skip to main content ยท Google Account Help ยท Sign in ยท Google Help ยท Help Center ยท Community ยท Google Account ยท Terms of Service ยท Submit feedback ยท Send feedback on
๐ŸŒ
1Password
1password.com โ€บ haveibeenpwned
Have I Been Pwned | 1Password
Discovered your data was breached? Learn about Have I Been Pwned and how 1Password can secure your online accounts and sensitive information.
Top answer
1 of 7
97

This question was explained by Troy Hunt several times on his blog, on Twitter and in the FAQ of haveibeenpwned.com

See here:

When you search for an email address

Searching for an email address only ever retrieves the address from storage then returns it in the response, the searched address is never explicitly stored anywhere. See the Logging section below for situations in which it may be implicitly stored.

Data breaches flagged as sensitive are not returned in public searches, they can only be viewed by using the notification service and verifying ownership of the email address first. Sensitive breaches are also searchable by domain owners who prove they control the domain using the domain search feature. Read about why non-sensitive breaches are publicly searchable.

See also the Logging paragraph

And from the FAQ:

How do I know the site isn't just harvesting searched email addresses?

You don't, but it's not. The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Of course we have to trust Troy Hunt on his claims, as we have no way of proving that he is not doing something else, when handling your specific request.
But I think it is more than fair to say, that haveibeenpwned is a valuable service and Troy Hunt himself is a respected member of the infosec community.

But let's suppose we don't trust Troy: what do you have to lose? You might disclose your email address to him. How big of a risk is that to you, when you can just enter any email address you want?

At the end of the day, HIBP is a free service for you(!) that costs Troy Hunt money. You can choose to search through all the password databases of the world yourself if you don't want to take the risk that maybe a lot of people are wrong about Troy Hunt, just because then you would disclose your email address.

2 of 7
16

Troy Hunt is a very respected Information Security professional and this service is being used by millions of people worldwide, even by some password managers to verify if the passwords selected by the users have been involved in a data breach.

See for example, https://1password.com/haveibeenpwned/

As per the website, 1Password integrates with the popular site Have I Been Pwned to keep an eye on your logins for any potential security breaches or vulnerabilities.

Entering your email address on this site will tell you which data breaches involve this email address, so that you can go back to the affected website and change your password. This is esp. important if you have used the same password for multiple websites, where credentials stolen from one site can be used to attack other sites in a technique also called Credential Stuffing attack.

The following StackExchange post has a response from Troy himself with further clarification on this service: Is "Have I Been Pwned's" Pwned Passwords List really that useful?

Find elsewhere
๐ŸŒ
Wikipedia
en.wikipedia.org โ€บ wiki โ€บ Have_I_Been_Pwned
Have I Been Pwned? - Wikipedia
1 month ago - Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a valuable resource for Internet users wishing to protect their own security and privacy.
๐ŸŒ
PCMAG
pcmag.com โ€บ home โ€บ news โ€บ security
Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email | PCMag
March 25, 2025 - If you buy through affiliate links, ... However, the hacker behind the phishing attack appears to have only stolen the email addresses of those who subscribed to Troy Hunt's blog, rather than Haveibeenpwned.com....
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ privacy
Have I Been Pwned: Privacy Policy
However, it does not represent all leaked information, and there may be breaches or exposures that we are unaware of or have not been made public. As a result, a Userโ€™s data could still be compromised even if it is not reflected on our Website ยท The Pwned Passwords feature searches compromised passwords from data leaks for the presence of a user-provided password.
๐ŸŒ
PowerDMARC
powerdmarc.com โ€บ blog
Have I Been Pwned? Steps To Check, Fix, And Stay Safe
July 11, 2025 - Instead, focus on changing your passwords, enabling two-factor authentication, and monitoring your accounts for any unusual activity to keep your information secure. Yes, it is safe. Have I Been Pwned is a reputable and trusted service that ...
๐ŸŒ
Quora
quora.com โ€บ Is-Haveibeenpwned-safe
Is Haveibeenpwned safe? - Quora
It has been vetted by a lot of security professionals and is run by someone who works at Microsoft and has an excellent reputation. The site does NOT retain any information when you plug in your address. It merely compares that email address ...
๐ŸŒ
Trustpilot
trustpilot.com โ€บ home โ€บ electronics & technology โ€บ internet & software โ€บ software company โ€บ have i been pwned reviews
Have I Been Pwned is rated "Average" with 3.6 / 5 on Trustpilot
5 days ago - We don't know what those sources are, only that your email address is in it. More: https://www.troyhunt.com/2-billion-email-addresses-were-exposed-and-we-indexed-them-all-in-have-i-been-pwned/ FWIW, more than 90% of data breaches are discrete incidents from a single source which is clearly indicated.
Address ย  4217, Surfers Paradise, AU
(3.6)
๐ŸŒ
BBC
bbc.com โ€บ news โ€บ technology-66451970
How safe is my data after a hack or leak?
August 9, 2023 - If you believe your password to an account may have been compromised, it makes sense to change it. But you should be mindful not to respond to any emails recommending this, as they could be attempting to scam you - instead you should visit the website as normal, and change your password there. This is also why it is important to have different passwords for different accounts. By always keeping different log-in credentials, a future hack is less likely to affect you seriously as the hackers will not be able to use your data beyond accessing a single service you used.
๐ŸŒ
Consumer Reports
consumerreports.org โ€บ electronics & computers โ€บ how to use 'have i been pwned' to see if your data was compromised
How to Use 'Have I Been Pwned' to See If Your Data Was Compromised via @ConsumerReports
October 24, 2022 - Have I Been Pwned is a useful resource for finding out when youโ€™ve been affected by a data breach, but itโ€™s best to get ahead of the problem by making your accounts more secure.
๐ŸŒ
SlashGear
slashgear.com โ€บ 1826787 โ€บ have-i-been-pwned-legit-safety-concerns-explained
Is 'Have I Been Pwned' Legit? Here's How The Website Works - SlashGear
April 8, 2025 - How it handles the data is what makes Have I Been Pwned so legit: The site doesn't even log search queries, and everything is transmitted over encrypted connections.
๐ŸŒ
Have I Been Pwned
haveibeenpwned.com โ€บ FAQs
Have I Been Pwned: Frequently Asked Questions
Further background on unverified breaches can be found in the blog post titled Introducing unverified breaches to Have I Been Pwned. Some breaches may be flagged as "fabricated". In these cases, it is highly unlikely that the breach contains legitimate data sourced from the alleged site but it may still be sold or traded under the auspices of legitimacy.
๐ŸŒ
Malwarebytes
malwarebytes.com โ€บ home โ€บ โ€œhave i been pwnd?โ€โ€“ what is it and what to do when you *are* pwned
"Have I been pwnd?"-- What is it and what to do when you *are* pwned
May 19, 2021 - You use Have I Been Pwned (HIBP) to check if your data has been compromised. What you do next when pwned takes a couple of steps.
๐ŸŒ
Washburn
blog.washburn.edu โ€บ security โ€บ 2024 โ€บ 03 โ€บ hibp.html
Have you been pwned, Ichabod?
โ€œ;-- have I been pwnedโ€, found at https://haveibeenpwned.com, is a free online website that monitors internet forum, internet pastebins, and other locations likely to disclose personal data on the dark web, in order to quickly notify the general public if their information has been compromised.