Password Breach Checker
Check if a password was leaked: find out if it is on the lists attackers use, while the password itself stays on your device.
- Runs on your device
- No watermark
- Free, no signup needed
- Available offline
Make a list
Generated on your device with crypto.getRandomValues. Nothing is sent or stored. Passphrases use the EFF long word list (7,776 words).
A username that does not contain your name, birth year or town keeps your accounts harder to link and your security answers harder to guess.
Make a list
Made on your device from a hand-picked list of friendly words. Nothing is sent, so names are not checked against existing accounts.
Has this password appeared in a data breach?
Optional, and only when you press the button. Your password never leaves this device: it is turned into a SHA-1 fingerprint here and only the first 5 of its 40 characters are sent to Have I Been Pwned. The list of matching fingerprints comes back and is compared on your device.
Strength
How to use it
- Type the password you want to check.
- Press Check breaches. Only 5 characters of its SHA-1 fingerprint are sent.
- If it was found, change it everywhere you use it.
Questions
Does my password get sent to Have I Been Pwned?
No. Your browser turns the password into a SHA-1 fingerprint on your device and sends only the first 5 of its 40 characters to the Pwned Passwords service. Hundreds of unrelated fingerprints share those 5 characters; the list comes back with extra padding entries, and the match is checked on your device. This is the k-anonymity method published by Have I Been Pwned. Nothing is sent until you press the button.
What should I do if my password was found?
Stop using it everywhere, starting with email, banking and any account that shares it. Use a different random password for each site (a password manager makes this easy) and turn on two-step sign-in. Being found does not mean your own account was hacked, only that someone, somewhere, used the same password and it leaked.
Why check against breached passwords at all?
Attackers try leaked passwords first. NIST guidance on passwords (SP 800-63B, section 5.1.1.2) asks services to reject passwords that appear in breach lists, because length and symbols do not help once a password is on those lists.
Does it also show how strong the password is?
Yes. The strength estimate (zxcvbn, created at Dropbox) runs on your device as you type and never sends anything.
Why does it say it could not check?
The check needs a connection to api.pwnedpasswords.com. If you are offline, or a network filter blocks that address, nothing is checked and nothing is sent. Try again on another connection.
Keep exploring In-Right
Independent reviews and buying guides for the gear behind the task.



