← Blog

How to Check if a Password Has Been Leaked

A new data breach makes the news almost every week. Credit card numbers, emails, and millions of plaintext or weakly hashed passwords get dumped online. If you are like most people, some of your passwords are already out there, and you have no idea which ones. That is the exact problem this post solves: how to check if a password has been leaked in a breach, safely and without exposing it to anyone in the process.

Why Checking if a Password Has Been Leaked Matters

Most people discover they were breached weeks or months after the fact, usually after seeing an ominous email from “haveibeenpwned.com.” But by the time an attacker emails you, your password has already been circulating in paste sites and credential-stuffing lists. Attackers do not need to crack your password anymore; they just buy the dump and try it everywhere. That is why checking whether a password was exposed is not paranoia, it is basic hygiene.

Two things decide how much damage a leaked password does. First, whether the password was stored as plaintext or a weak hash in the breach. Second, whether you reused that password anywhere else. A password that only guards a forum account you abandoned is a nuisance. The same password guarding your bank login is an emergency.

How Have I Been Pwned Works

Have I Been Pwned (HIBP), run by security researcher Troy Hunt, maintains one of the largest collections of breached credential data in existence, now spanning billions of passwords. The site lets you check an email address or a phone number for free. For passwords specifically, HIBP offers a Pwned Passwords service: a searchable corpus of every password that has ever appeared in a public breach.

There is a real privacy problem to solve here. You should not send your full password to a third-party website, because that hands a database of the exact password you use over the wire. HIBP solves this with an elegant trick called k-anonymity. You take the SHA-1 hash of your password, send only the first five hex characters of that hash, and the API returns every hash in its corpus that starts with those five characters. You then compare the remainder locally on your own machine. The full password hash never leaves your device, and the service learns only a five-character prefix shared by thousands of other passwords.

This is worth understanding even if you never touch the API directly, because it is the pattern the best breach-checking tools use. If you prefer to run the comparison locally with zero network traffic, checksec.dev has a free password breach check tool that does the hashing and comparison right in your browser, nothing uploaded.

What to Do When a Password Shows Up in a Breach

If your check comes back positive, act like a breach is a fire alarm, not a suggestion. Do these in order:

  1. Change the leaked password immediately on every account that used it. If it was reused anywhere, start with the most sensitive accounts first: email, banking, and cloud storage.
  2. Turn on two-factor authentication wherever it is offered, starting with your email address, because your email is the recovery key for every other account.
  3. Use a password manager so you generate a unique, random password per site and never have to remember any of them.
  4. Run a quick scan on the sites you use most; the password strength checker tells you how a potential replacement password holds up before you commit to it.

Do not waste time resetting passwords you no longer use. Just stop using them and let the accounts rot. The priority order is sensitive and reused first, everything else second.

Why Password Reuse Is the Real Danger

Here is the uncomfortable truth about breaches: most of the damage is not caused by the breach itself but by password reuse. Credential stuffing is a fully automated attack. Attackers take a list of leaked username and password pairs, and they try every pair against dozens of popular services: Google, Facebook, Amazon, banking portals. The tools check millions of pairs per hour, so even a low hit rate produces thousands of compromised accounts.

That is why security guidance always says “unique password per site.” When you reuse a password, you are not defending one account; you are tying them all to the weakest site in the chain. A message board that stores passwords in plaintext and gets breached becomes the key to your entire online life.

The Fastest Way to Check if a Password Has Been Leaked

The safest single step you can take right now is a simple one. Check your most important passwords against the breach corpus using a password breach check tool that never sends your actual password anywhere. Enter a password, get an instant verdict: found in a breach, or clear.

If anything comes back positive, change it now, generate a unique replacement, and turn on two-factor authentication. Ten minutes of cleanup today is far cheaper than a drained bank account or a hijacked email later. Run the check on your passwords, starting with the ones you reuse the most.

Try it now: open the password breach check tool — free, runs entirely in your browser, nothing is uploaded.