🌐
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Oh no — pwned! This email address has been found in multiple data breaches.
FAQs
Find answers to frequently asked questions about Have I Been Pwned, including data sources, breach handling, notification services, and account security.
Notify Me
Get notified if your email address appears in a future data breach. Have I Been Pwned will alert you when we find your email address is exposed.
Passwords
Pwned Passwords is a huge corpus of previously breached passwords made freely available to help services block them from being used again.
Who's Been Pwned
Every breached website added to Have I Been Pwned appears here on the Who’s Been Pwned page. As of today, there are 929 breached sites listed.

consumer security website and email alert system

The homepage of haveibeenpwned.com. The website features white text on a black background. Prominently centered is the site's logo in a white and blue gradient. Below the logo is a search box labeled "email address" with a button beside it labeled "Check". Below the search box is a series of statistics about the size of the website's database.
Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a … Wikipedia
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
Factsheet
Type of site Internet security
Created by Troy Hunt
URL haveibeenpwned.com
🌐
Reddit
reddit.com › r/privacy › how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
🌐
Wikipedia
en.wikipedia.org › wiki › Have_I_Been_Pwned
Have I Been Pwned? - Wikipedia
1 month ago - Have I Been Pwned? (HIBP) is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The site has been widely touted as a valuable resource for Internet users wishing to protect their own security and privacy.
Top answer
1 of 7
97

This question was explained by Troy Hunt several times on his blog, on Twitter and in the FAQ of haveibeenpwned.com

See here:

When you search for an email address

Searching for an email address only ever retrieves the address from storage then returns it in the response, the searched address is never explicitly stored anywhere. See the Logging section below for situations in which it may be implicitly stored.

Data breaches flagged as sensitive are not returned in public searches, they can only be viewed by using the notification service and verifying ownership of the email address first. Sensitive breaches are also searchable by domain owners who prove they control the domain using the domain search feature. Read about why non-sensitive breaches are publicly searchable.

See also the Logging paragraph

And from the FAQ:

How do I know the site isn't just harvesting searched email addresses?

You don't, but it's not. The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Of course we have to trust Troy Hunt on his claims, as we have no way of proving that he is not doing something else, when handling your specific request.
But I think it is more than fair to say, that haveibeenpwned is a valuable service and Troy Hunt himself is a respected member of the infosec community.

But let's suppose we don't trust Troy: what do you have to lose? You might disclose your email address to him. How big of a risk is that to you, when you can just enter any email address you want?

At the end of the day, HIBP is a free service for you(!) that costs Troy Hunt money. You can choose to search through all the password databases of the world yourself if you don't want to take the risk that maybe a lot of people are wrong about Troy Hunt, just because then you would disclose your email address.

2 of 7
16

Troy Hunt is a very respected Information Security professional and this service is being used by millions of people worldwide, even by some password managers to verify if the passwords selected by the users have been involved in a data breach.

See for example, https://1password.com/haveibeenpwned/

As per the website, 1Password integrates with the popular site Have I Been Pwned to keep an eye on your logins for any potential security breaches or vulnerabilities.

Entering your email address on this site will tell you which data breaches involve this email address, so that you can go back to the affected website and change your password. This is esp. important if you have used the same password for multiple websites, where credentials stolen from one site can be used to attack other sites in a technique also called Credential Stuffing attack.

The following StackExchange post has a response from Troy himself with further clarification on this service: Is "Have I Been Pwned's" Pwned Passwords List really that useful?

🌐
Vertex Cyber Security
vertexcybersecurity.com.au › should-i-use-have-i-been-pwned-hibps
Should I use Have I been pwned (HIBP) ? - Vertex Cyber Security
August 15, 2024 - The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it. So is this enough of a ...
🌐
Have I Been Pwned
haveibeenpwned.com › FAQs
Have I Been Pwned: Frequently Asked Questions
Further background on unverified breaches can be found in the blog post titled Introducing unverified breaches to Have I Been Pwned. Some breaches may be flagged as "fabricated". In these cases, it is highly unlikely that the breach contains legitimate data sourced from the alleged site but it may still be sold or traded under the auspices of legitimacy.
🌐
Trustpilot
ca.trustpilot.com › home › electronics & technology › internet & software › software company › have i been pwned reviews
Have I Been Pwned is rated "Average" with 3.6 / 5 on Trustpilot
5 days ago - We don't know what those sources are, only that your email address is in it. More: https://www.troyhunt.com/2-billion-email-addresses-were-exposed-and-we-indexed-them-all-in-have-i-been-pwned/ FWIW, more than 90% of data breaches are discrete incidents from a single source which is clearly indicated.
Address   4217, Surfers Paradise, AU
(3.6)
🌐
F-Secure
f-secure.com › en › articles › have-i-been-pwned-4-steps-to-take-if-your-email-has-been-compromised
Have I been pwned? 4 steps to take if your email has been compromised | F‑Secure
May 16, 2024 - If your account has been pwned, here are four things you can do to mitigate the risk: Viruses and spyware can steal personal information and login credentials. Having up-to-date antivirus and operating systems on your devices is the best way ...
Find elsewhere
🌐
Quora
quora.com › Is-Haveibeenpwned-safe
Is Haveibeenpwned safe? - Quora
It has been vetted by a lot of security professionals and is run by someone who works at Microsoft and has an excellent reputation. The site does NOT retain any information when you plug in your address. It merely compares that email address ...
🌐
PowerDMARC
powerdmarc.com › blog
Have I Been Pwned? Steps To Check, Fix, And Stay Safe
July 11, 2025 - Instead, focus on changing your passwords, enabling two-factor authentication, and monitoring your accounts for any unusual activity to keep your information secure. Yes, it is safe. Have I Been Pwned is a reputable and trusted service that ...
🌐
Have I Been Pwned
haveibeenpwned.com › About
Have I Been Pwned: Who, What & Why
The FAQs page goes into a lot more detail, but all the data on this site comes from "breaches" where data is exposed to persons that should not have been able to view it.
🌐
Have I Been Pwned
haveibeenpwned.com › Passwords
Have I Been Pwned: Pwned Passwords
This password has been seen 0 times before in data breaches! This password has previously appeared in a data breach and should never be used. If you've ever used it anywhere before, change it immediately!
🌐
Clean Email
clean.email › have-you-been-pwned
Have I Been Pwned? What It Means And How To Protect Your Email
January 12, 2020 - Instead, it means your email address, password, or personal data was exposed in a data breach. This use of the term reflects the fact that hackers have "owned" or compromised your information.
🌐
Have I Been Pwned
haveibeenpwned.com › privacy
Have I Been Pwned: Privacy Policy
However, it does not represent all leaked information, and there may be breaches or exposures that we are unaware of or have not been made public. As a result, a User’s data could still be compromised even if it is not reflected on our Website · The Pwned Passwords feature searches compromised passwords from data leaks for the presence of a user-provided password.
🌐
Consumer Reports
consumerreports.org › electronics & computers › how to use 'have i been pwned' to see if your data was compromised
How to Use 'Have I Been Pwned' to See If Your Data Was Compromised via @ConsumerReports
October 24, 2022 - Have I Been Pwned is a useful resource for finding out when you’ve been affected by a data breach, but it’s best to get ahead of the problem by making your accounts more secure.
🌐
Malwarebytes
malwarebytes.com › home › “have i been pwnd?”– what is it and what to do when you *are* pwned
"Have I been pwnd?"-- What is it and what to do when you *are* pwned
May 18, 2021 - You use Have I Been Pwned (HIBP) to check if your data has been compromised. What you do next when pwned takes a couple of steps.
🌐
SlashGear
slashgear.com › 1826787 › have-i-been-pwned-legit-safety-concerns-explained
Is 'Have I Been Pwned' Legit? Here's How The Website Works - SlashGear
April 8, 2025 - How it handles the data is what makes Have I Been Pwned so legit: The site doesn't even log search queries, and everything is transmitted over encrypted connections.
🌐
Bogleheads.org
bogleheads.org › board index › community › personal consumer issues
Is the security check website "Have I Been Pwned?" legit? - Bogleheads.org
Through our partnership with Troy Hunt’s “Have I Been Pwned,” your email address will be scanned against a database that serves as a library of data breaches. We’ll let you know if your email address and/or personal info was involved in a publicly known past data breach.
🌐
1Password
1password.com › haveibeenpwned
Have I Been Pwned | 1Password
Discovered your data was breached? Learn about Have I Been Pwned and how 1Password can secure your online accounts and sensitive information.
🌐
F-Secure
f-secure.com › en › articles
Useful online security tips and articles | F‑Secure
If your email has been pwned, your personal information is in danger.