Password Breach Checker
Find out if a password is in the 1 billion+ passwords exposed in data breaches — without ever sending it. Then audit your whole password manager for breached, reused and weak logins, and see if your device is ready for passkeys.
Free · No sign-upHow to use Password Breach Checker
- 1. Type or paste a password and press Check. It's hashed on your device; only the first 5 characters of the hash are sent.
- 2. See how many times it appeared in breaches, plus a strength rating and crack-time estimate with tips.
- 3. To check everything at once, export your passwords as CSV from your browser or password manager and drop the file in Check my password manager. You get breached, reused and weak logins — never the passwords themselves.
- 4. Open Passkeys to see if this device supports them, then switch your most important accounts over. Delete the CSV export when you're done.
Frequently asked questions
Is it safe to type my real password here?
Yes. The password is hashed with SHA-1 in your browser, and only the first 5 of the 40 hash characters are sent to Have I Been Pwned. The service returns hundreds of possible matches (padded with fake ones), and the final comparison happens on your device. The password itself never leaves it and nothing is stored.
Where does the breach data come from?
From Have I Been Pwned's Pwned Passwords, a free database of more than a billion real passwords exposed in public data breaches, run by security researcher Troy Hunt.
My password wasn't found. Is it safe?
It hasn't appeared in a known breach, which is good. It can still be weak or reused — check the strength result, and make sure you use it on one site only.
How does the password-manager audit work?
You export a CSV from Chrome, Edge, Firefox, Safari, Bitwarden, 1Password, Proton Pass or LastPass. The file is read in memory, each unique password is checked the same k-anonymous way, and you get a list of breached, reused and weak logins. The report you can download contains no passwords. Delete the export file afterwards.
What is a passkey?
A passkey replaces a password with a key pair stored on your device or in your password manager. You unlock it with your face, fingerprint or PIN, and it can't be phished or leaked in a breach. Google, Apple, Microsoft, Amazon, PayPal and thousands of other sites support them.
How is the strength calculated?
With zxcvbn, an open-source estimator that looks for dictionary words, names, keyboard patterns, dates and repeats, and estimates how many guesses an attacker would need.