Password Breach Checker
Scan your credentials safely. Uses secure k-anonymity protocol to avoid transmitting your password.
When Should I Check for Breaches?
After hearing about a data breach
When a company announces a breach, immediately check if your password was exposed. This is the #1 reason to use this tool.
Before creating a new account
If you are reusing an old password, check it first. If it appears in a breach, generate a fresh one with the Password Generator.
Periodic security audit
Check your most important passwords (email, banking, password manager) every few months against the latest breach data.
After installing a password manager
When migrating to a password manager, check your old passwords first. Replace any breached ones before importing them.
When Should I NOT Rely on This?
To check if a password is strong
A password that has never been breached can still be weak. "password123" might not appear in breaches yet is trivially guessable. Use the Strength Checker for that.
To generate new passwords
This tool checks existing passwords only. Use the Password Generator to create new ones.
To assume a clean result is permanent
Breach databases are updated continuously. A password safe today may be compromised tomorrow. Check regularly.
What to Do After the Scan?
LinkedIn just announced a data breach
1. Enter your LinkedIn password above
2. If found — change it immediately on LinkedIn and every other site where you used it
3. Generate a new unique password with the Password Generator
4. Check the new password with the Strength Checker
5. Enable 2FA on LinkedIn and all email accounts
What the Breach Check Tells You
Found in a breach
Your password has appeared in a known data breach. Change it immediately on every account where you used it. Generate a new password with our Password Generator.
Not found in any breach
Your password was not found in the queried dataset. This is good news, but it does not guarantee the password is strong. A short, simple password might not appear in breaches yet could still be easily cracked. Always combine breach checking with our Strength Checker.
How privacy is protected
This tool uses the k-anonymity model: your password is hashed locally, only the first 5 characters of the hash are sent to the API, and the full password never leaves your browser. See the technical details below.
What is k-Anonymity?
We use the Have I Been Pwned range API. When you scan a password, we hash it locally using SHA-1. We send only the first 5 characters of that hash (e.g. 21BD1) to the server. The server responds with a list of all leaked hashes starting with those 5 characters. We then search that list locally on your computer for the remaining suffix. Your plain text password never leaves your browser.
How k-Anonymity Protects Your Password
1. Your password is hashed locally
When you enter a password, your browser computes a SHA-1 hash entirely on your device using the Web Crypto API. Your plain text password never leaves your browser — not even for a millisecond.
2. Only the first 5 characters of the hash are sent
The 40-character SHA-1 hash is split. Only the first 5 characters (the prefix) are sent to the Have I Been Pwned API. This prefix represents a small group — not your specific password.
3. The API returns all matching hash suffixes
The server responds with a list of all 35-character hash suffixes that share that same 5-character prefix, along with their breach counts. This list may contain hundreds of entries — your request is hidden among all of them.
4. Your browser compares locally
Your browser searches the returned list on your own device, comparing your full hash suffix against every entry. If a match is found, the breach count is displayed. The server never sees your full hash or your password.
5. Why this is safe even against a remote service
The k-anonymity model works because many users query the same 5-character prefixes. Your individual request is statistically indistinguishable from thousands of others. Even the API operator cannot determine which specific password you are checking — only that someone, somewhere, is checking passwords that share the same hash prefix.
What to Do After a Breach
Limitations to Understand
Only checks passwords in known breaches
This tool queries the Have I Been Pwned database, which contains passwords from publicly disclosed breaches. A password that does not appear here may still have been compromised in a private or undisclosed incident.
Does NOT detect weak passwords
A password like "password123" may not appear in breach databases yet is trivially guessable. This tool only checks if a password has been seen before — not if it is strong. Use the Strength Checker to evaluate password quality.
Breach databases update periodically, not in real-time
New breaches take days or weeks to appear in the database after discovery. A password compromised in a very recent breach may not show up yet. Check again periodically for the most current results.
"Not found" does not mean "safe"
A clean result means the password was not found in known breaches — but it does not guarantee the password is secure. It could still be weak, predictable, or compromised in an incident not yet added to the database. Always combine breach checking with strength analysis.
Introduction
Your password could be sitting in a leaked database right now, circulating on dark web forums, and you'd never know it. The Breach Checker lets you test your credentials against the Have I Been Pwned API — the same database security professionals use to detect compromised accounts. In seconds, you'll know if your password has appeared in any of the billions of records exposed in known data breaches. This is the tool that turns 'I think I'm safe' into 'I know I'm safe' — or 'I need to change this immediately.'
What This Tool Does
Why It Matters
Every major breach exposes millions of credentials that attackers immediately feed into credential stuffing bots — automated tools that test leaked username-password pairs across hundreds of services. The 2024 Verizon DBIR found that 49% of breaches involved stolen credentials, and Credential stuffing attacks succeeded 1-3% of the time across billions of attempts. A single compromised password can cascade into email takeover, financial fraud, and identity theft. Checking your password against known breaches isn't paranoia — it's basic digital hygiene that takes three seconds and could save you from a catastrophic account compromise.
How It Works
Step-by-Step Examples
Enter a password in the input field (the password is hashed locally using k-anonymity — only the first 5 characters of the SHA-1 hash are sent to the API)
The tool sends the partial hash to Have I Been Pwned's breached password API
The API returns all known hash suffixes matching that prefix
If your password's full hash matches any returned suffix, it has been found in a breach
Password found in 2,347 breaches — must be changed immediately on every account where it was usedGenerate a new password using the Password Generator tool
Copy the generated password and paste it into the Breach Checker
Wait for the k-anonymity API response (typically under 200ms)
A clean result means the password has not appeared in any indexed breach database
Password not found in any known breaches — safe to use (but always unique per service)Code Examples
async function checkPasswordBreach(password) {
// Step 1: SHA-1 hash the password locally
const encoder = new TextEncoder();
const data = encoder.encode(password);
const hashBuffer = await crypto.subtle.digest('SHA-1', data);
const hashArray = Array.from(new Uint8Array(hashBuffer));
const hashHex = hashArray.map(b => b.toString(16).padStart(2, '0')).join('').toUpperCase();
// Step 2: Extract first 5 characters (k-anonymity prefix)
const prefix = hashHex.slice(0, 5);
const suffix = hashHex.slice(5);
// Step 3: Query HIBP API with only the prefix
const response = await fetch(
'https://api.pwnedpasswords.com/range/' + prefix,
{ headers: { 'Add-Padding': 'true' } }
);
const text = await response.text();
// Step 4: Check if our suffix appears in the results
const lines = text.split('\n');
for (const line of lines) {
const [hashSuffix, count] = line.split(':');
if (hashSuffix.trim() === suffix) {
return {
breached: true,
count: parseInt(count.trim(), 10),
message: 'Found in ' + count.trim() + ' breaches'
};
}
}
return { breached: false, count: 0, message: 'Not found in any known breaches' };
}
// Usage
const result = await checkPasswordBreach('MyP@ssw0rd123');
console.log(result);
// { breached: true, count: 2347, message: "Found in 2,347 breaches" }async function checkMultiplePasswords(passwords) {
const results = [];
for (const password of passwords) {
const encoder = new TextEncoder();
const data = encoder.encode(password);
const hashBuffer = await crypto.subtle.digest('SHA-1', data);
const hashArray = Array.from(new Uint8Array(hashBuffer));
const hashHex = hashArray.map(b => b.toString(16).padStart(2, '0')).join('').toUpperCase();
const prefix = hashHex.slice(0, 5);
const suffix = hashHex.slice(5);
const response = await fetch(
'https://api.pwnedpasswords.com/range/' + prefix,
{ headers: { 'Add-Padding': 'true' } }
);
const text = await response.text();
let breachCount = 0;
for (const line of text.split('\n')) {
const [hashSuffix, count] = line.split(':');
if (hashSuffix.trim() === suffix) {
breachCount = parseInt(count.trim(), 10);
break;
}
}
results.push({
password: password.slice(0, 3) + '*'.repeat(password.length - 3),
breached: breachCount > 0,
count: breachCount
});
// Rate limit: wait 1.5 seconds between requests
await new Promise(r => setTimeout(r, 1500));
}
return results;
}How the k-Anonymity Model Protects Your Password
| Step | What Happens | Privacy Guarantee |
|---|---|---|
| 1. Local Hashing | Your password is SHA-1 hashed entirely in your browser | Raw password never leaves your device |
| 2. Prefix Extraction | Only the first 5 hex characters of the hash are extracted | API server never sees your full hash |
| 3. API Query | The 5-character prefix is sent to HIBP | No password, no full hash, no identifying data transmitted |
| 4. Suffix Matching | HIBP returns all hash suffixes matching that prefix (typically 200-800 results) | Your specific hash is indistinguishable from the other hundreds returned |
| 5. Local Comparison | Your browser compares your full hash against returned suffixes | The match check happens entirely on your machine |
Breach Severity by Credential Type
| Credential Type | Risk if Compromised | Action Required |
|---|---|---|
| Email + Password | High — enables account takeover, email access, password resets | Change immediately, enable 2FA |
| Password only | Medium — dangerous if reused across multiple services | Change on all accounts using this password |
| Email address | Low — enables targeted phishing, but no direct access | Monitor for suspicious activity |
| Password hash (bcrypt) | Very Low — computationally expensive to crack | No immediate action, but consider rotation |
Benefits
- Uses k-anonymity so your full password hash is never transmitted — only a 5-character prefix leaves your browser.
- Checks against billions of real breach records from the Have I Been Pwned database, updated continuously.
- Instant results in under 200 milliseconds with zero account creation or personal data required.
- Detects passwords exposed in breaches you may not even know happened — old accounts, third-party leaks, and dark web dumps.
Use Cases
Verifying that a newly generated password has not appeared in any known data breach before deploying it to production systems.
Auditing existing passwords across personal and work accounts to identify credentials compromised in recent breaches.
Checking legacy or reused passwords during a security audit to determine which accounts need immediate credential rotation.
Validating employee passwords against breach databases as part of organizational security policies and compliance checks.
Common Mistakes to Avoid
Assuming a password is safe because 'I've never been breached' — your password could appear in breaches of services you've never used if it was reused.
Checking passwords through untrusted third-party services that may log your input — always use tools with client-side hashing and k-anonymity.
Changing a breached password only on the compromised service instead of everywhere it was reused.
Continuing to use a password after it appears in a breach, assuming the count is 'too low to matter' — even one breach means it's in attacker wordlists.
Security Implications
A password that has appeared in a known breach is no longer secret — it exists in attacker-controlled databases, rainbow tables, and credential stuffing lists. Attackers run automated tools that test leaked credentials across millions of services simultaneously. Even if the breach was from an obscure forum you used once, that password is now in the global attack surface. The k-anonymity model used by this tool ensures you can check your password without exposing it, solving the fundamental paradox of breach checking: you need to verify a secret without revealing it.
Security Information
Frequently Asked Questions
What is a Password Breach Checker?
GeneratePass checks passwords against the Have I Been Pwned (HIBP) range API using the k-anonymity model. Your password is hashed locally with SHA-1 via crypto.subtle.digest('SHA-1', buffer). The resulting hex digest is split: only the first 5 characters of the hash prefix are sent to api.pwnedpasswords.com/range/{prefix}. The server returns all matching hash suffixes. Your browser then searches that list locally for the remaining suffix. The full password and full hash never leave your browser.
A 3-second cooldown is enforced between scans to respect the HIBP API rate limits. Passwords shorter than 8 characters or longer than 128 characters are rejected before hashing. If the returned count is 0, the password was not found in any known breach database — but this does not guarantee it is strong.
How k-Anonymity Protects Your Password
When you click "Scan Database," GeneratePass first hashes your password using SHA-1 via the Web Crypto API (crypto.subtle.digest('SHA-1', buffer)). The hex digest (40 characters) is split: the first 5 characters become the prefix, and the remaining 35 characters become the suffix. Only the 5-character prefix is sent as a GET request to https://api.pwnedpasswords.com/range/{prefix}.
The HIBP server responds with a text list of all hash suffixes (35 characters each) along with their breach counts, formatted as SUFFIX:COUNT lines. GeneratePass then iterates through this list on your device, comparing each line's suffix against your suffix. If a match is found, the count tells you how many times that password appeared in known breaches.
The k-anonymity model ensures that even the API operator cannot determine which specific password you are checking. With thousands of users querying the same 5-character prefix, your request is hidden among many others, providing strong privacy guarantees. A 10-second timeout aborts the request if the API is unresponsive.
Real-World Use Cases
Account Auditing: Check all your existing passwords after a major breach is reported. When a company announces a data breach, immediately check if your credentials were affected. This is especially important for email and banking accounts.
Password Reuse Detection: If you have been reusing passwords across multiple sites, a breach checker reveals the full scope of your exposure. One compromised password could give attackers access to dozens of your accounts.
Security Compliance: Organizations can use breach checking as part of their security audit process to ensure employee passwords have not been compromised in known incidents. This is a critical step in maintaining SOC 2 and ISO 27001 compliance.
Incident Response: Security teams can quickly assess the impact of a reported breach by checking organizational credentials against the newly leaked database. This helps prioritize which accounts need immediate password resets.
Common Mistakes to Avoid
Assuming a Clean Result is Permanent: A password that is safe today may be compromised tomorrow. Breach databases are constantly updated as new incidents are discovered. Make it a habit to check your passwords regularly, especially after hearing about major data breaches.
Using Untrusted Breach Checkers: Many online breach checkers actually send your password to their servers. If the tool is not privacy-focused, you risk exposing your password to yet another service. Always verify the tool uses client-side hashing and k-anonymity.
Ignoring the Result: Finding out your password is breached is only useful if you take action. Immediately change the compromised password on all affected accounts and enable two-factor authentication wherever possible.
Not Checking Reused Passwords: If your password appears in a breach, check every account where you used that same password. Password reuse is the most common way attackers gain access to multiple accounts from a single breach.
Related Tools
After checking your passwords for breaches, strengthen your security with these complementary tools:
- Password Strength Checker — Test the overall strength of your passwords against dictionary attacks and pattern analysis.
- Password Entropy Calculator — Measure the randomness and security bits of your passwords.
- Passphrase Generator — Generate strong, memorable passphrases that are resistant to brute-force attacks.
- Password Crack Time Estimator — Estimate how long it would take an attacker to crack your password.
- Password Policy Checker — Validate passwords against custom organizational security policies.
What This Tool Cannot Guarantee
No breach database is complete
This tool checks against Have I Been Pwned, which is the largest public breach database. But not all breaches are reported or included. "Not found" does not mean "never breached."
It does not check password strength
A password that has never appeared in a breach can still be weak. "password123" might not be in every breach database yet is trivially guessable. Use our Strength Checker for that.
Private breaches are invisible
Some breaches are never made public. If a company is hacked but does not disclose it, those passwords will not appear in any database.
k-Anonymity Visualizer
See the step-by-step flow of how k-anonymity protects your password. The server never sees your actual password or even the full hash.
Type a password above to see the k-anonymity flow...