All tools

Password Breach Checker

Check if a password was leaked: find out if it is on the lists attackers use, while the password itself stays on your device.

  • Runs on your device
  • No watermark
  • Free, no signup needed
  • Available offline

Has this password appeared in a data breach?

Optional, and only when you press the button. Your password never leaves this device: it is turned into a SHA-1 fingerprint here and only the first 5 of its 40 characters are sent to Have I Been Pwned. The list of matching fingerprints comes back and is compared on your device.

Strength

How to use it

  1. Type the password you want to check.
  2. Press Check breaches. Only 5 characters of its SHA-1 fingerprint are sent.
  3. If it was found, change it everywhere you use it.

Questions

Does my password get sent to Have I Been Pwned?

No. Your browser turns the password into a SHA-1 fingerprint on your device and sends only the first 5 of its 40 characters to the Pwned Passwords service. Hundreds of unrelated fingerprints share those 5 characters; the list comes back with extra padding entries, and the match is checked on your device. This is the k-anonymity method published by Have I Been Pwned. Nothing is sent until you press the button.

What should I do if my password was found?

Stop using it everywhere, starting with email, banking and any account that shares it. Use a different random password for each site (a password manager makes this easy) and turn on two-step sign-in. Being found does not mean your own account was hacked, only that someone, somewhere, used the same password and it leaked.

Why check against breached passwords at all?

Attackers try leaked passwords first. NIST guidance on passwords (SP 800-63B, section 5.1.1.2) asks services to reject passwords that appear in breach lists, because length and symbols do not help once a password is on those lists.

Does it also show how strong the password is?

Yes. The strength estimate (zxcvbn, created at Dropbox) runs on your device as you type and never sends anything.

Why does it say it could not check?

The check needs a connection to api.pwnedpasswords.com. If you are offline, or a network filter blocks that address, nothing is checked and nothing is sent. Try again on another connection.

Keep exploring In-Right

Independent reviews and buying guides for the gear behind the task.

More free tools

All tools

move open closeAll tools