Leaked password check

Passwords stolen from breached sites end up on lists, and attackers try those lists on every other login page they can find. Find out whether yours is on one. The password never leaves your device.

What you type stays in this browser. It is hashed here, and only the first 5 characters of the hash are transmitted. We keep no record.

Why a leaked password is worse than a weak one

When a website gets breached, the stolen account table usually goes up for sale, and a while later it’s free. Over the years these dumps have been merged into collections holding billions of email and password pairs. Attackers stopped guessing a long time ago. They feed the pairs to a script that tries each one on banks, mail providers and shops. It’s called credential stuffing, and it works every time somebody reused a password.

So a password that sits in those collections is burned, however long or complicated it looks. Tr0ub4dor&3 impresses any strength meter, and it’s in the lists.

This check asks Pwned Passwords, the public database run by the Have I Been Pwned project. It holds the passwords from the breaches the project has processed, each with the number of times it was seen.

Checking without handing over the password

Sending your password to a website to ask if it’s safe would be a strange way to protect it. The check gets around that with a method called k-anonymity:

  1. Your browser computes the SHA-1 hash of what you typed. A hash is a fixed-length code derived from the text. For Summer2024! it is 7E8B0A3433F1210A9699D85420E363A1B162ECAC.
  2. Only the first five characters, here 7E8B0, go to our server, which passes them on to the Pwned Passwords service.
  3. The service sends back every leaked hash that begins with those five characters, typically one to two thousand of them, padded with decoy lines so that even the size of the answer reveals nothing.
  4. Your browser looks through that list for the remaining 35 characters of your hash.

There are 1,048,576 possible five-character prefixes. Whoever sees yours learns that your password is one of the thousands that share it, or none of them. That’s all they get. The line under the result shows the prefix that was sent and how many hashes came back, so you can watch the exchange yourself.

Reading the two answers

Found in leaks, with a count
The count is the number of times this exact password occurs in the breached data. A count in the thousands means lots of people picked it and it sits near the top of every attack list. A count of 1 or 2 may well be your own account from an old breach. Either way, consider the password public.
No leak found
The password isn’t in the database. Good news, but only half of it: a breach that hasn’t surfaced yet isn’t covered, and a short password can still be guessed directly.

Because of that second half, the page also estimates strength while you type, on your device. The estimate starts from length multiplied by the variety of characters used (lowercase, uppercase, digits, symbols), expressed in bits. Then it takes points off for the habits attackers try first: a very common word, even with letters swapped for digits; four consecutive keys or letters such as qwer or 1234; the same character three times in a row; a year. Under 28 bits is rated very weak, under 45 weak, under 65 fair, and 65 or more strong. A password that isn’t leaked but rates below “fair” gets a warning.

The meter is a rough guide. It knows a few dozen common words, not a dictionary, and it has no idea that a password is your street name or your dog’s. The breach lookup is the only hard fact on this page.

What to do when it’s on the list

  1. Change it on your email account first. Your mailbox receives the reset links for everything else, which makes it the account an attacker wants most.
  2. Change it everywhere else you used it, including the versions with a different digit at the end. Scripts try those too.
  3. Let a password manager come up with the replacements. Bitwarden, 1Password, KeePassXC or the manager built into your browser or phone will generate and remember a different random password for each site. If you have to memorize one, four or five unrelated words are stronger and easier than a short mix of symbols.
  4. Turn on two-step verification wherever it’s offered, preferably with an authenticator app or a passkey. After that, a stolen password isn’t enough to sign in.

This check handles one password at a time and doesn’t know which of your accounts were breached. To search by email address, go to the Have I Been Pwned site directly. Most password managers can also audit a whole vault with the same k-anonymity method.

Questions people ask

Is it safe to type my real password into this page?

The password isn’t transmitted. Your browser hashes it and sends five characters of the hash, which match thousands of different passwords. You don’t have to take a web page’s word for it, though: your browser’s network tab shows exactly what this page sends, and password managers and the Pwned Passwords API offer the same lookup.

My password was found but I was never hacked. How is that possible?

The count belongs to the password, not to you. Someone else may have used the same one on a site that was breached, or a site where you had an account leaked without telling you. In both cases the password is now on the lists attackers use.

Does “no leak found” mean my password is strong?

No. It means the password is absent from the breaches collected so far. Something like Kq7! isn’t on any list and would still fall in seconds. Look at the strength line as well, and aim for at least 12 characters.

Why SHA-1, if SHA-1 is considered broken?

SHA-1 is a bad choice for digital signatures and for storing passwords on a server. Here it’s only a way to index a public list, and the full hash never leaves your browser, so its weaknesses don’t come into play.

How often should I change my passwords?

Current guidance from NIST in the United States and the NCSC in the United Kingdom is to stop changing them on a schedule. Change one when there’s a reason: it appears in a breach, you shared it, or the service reports an intrusion.

Why did the check tell me to come back later?

Lookups are limited to 60 per hour from one connection, so the relay can’t be used for bulk testing.