GeneratePass
CHECK PASSWORDS AGAINST KNOWN BREACHES

Password Breach Checker

Scan your credentials safely. Uses secure k-anonymity protocol to avoid transmitting your password.

✓ Client Safe Your password never leaves your browser.
✓ Anonymized Prefix Only anonymous hash prefixes are checked.
✓ Zero Logs Nothing is stored on any server.
Decision Guide

When Should I Check for Breaches?

After hearing about a data breach

When a company announces a breach, immediately check if your password was exposed. This is the #1 reason to use this tool.

Before creating a new account

If you are reusing an old password, check it first. If it appears in a breach, generate a fresh one with the Password Generator.

Periodic security audit

Check your most important passwords (email, banking, password manager) every few months against the latest breach data.

After installing a password manager

When migrating to a password manager, check your old passwords first. Replace any breached ones before importing them.

Important Warning

When Should I NOT Rely on This?

To check if a password is strong

A password that has never been breached can still be weak. "password123" might not appear in breaches yet is trivially guessable. Use the Strength Checker for that.

To generate new passwords

This tool checks existing passwords only. Use the Password Generator to create new ones.

To assume a clean result is permanent

Breach databases are updated continuously. A password safe today may be compromised tomorrow. Check regularly.

Next Steps

What to Do After the Scan?

1
If found in a breach — Change this password immediately on every account where you used it.
2
Generate a new password — Use the Password Generator to create a unique 16+ character replacement.
3
Check password strength — Verify your new password rates "Strong" or better with the Strength Checker.
4
Enable 2FA — Add two-factor authentication on all important accounts for layered protection.
Real-World Scenario

LinkedIn just announced a data breach

1. Enter your LinkedIn password above

2. If found — change it immediately on LinkedIn and every other site where you used it

3. Generate a new unique password with the Password Generator

4. Check the new password with the Strength Checker

5. Enable 2FA on LinkedIn and all email accounts

Understanding Your Results

What the Breach Check Tells You

Found in a breach

Your password has appeared in a known data breach. Change it immediately on every account where you used it. Generate a new password with our Password Generator.

Not found in any breach

Your password was not found in the queried dataset. This is good news, but it does not guarantee the password is strong. A short, simple password might not appear in breaches yet could still be easily cracked. Always combine breach checking with our Strength Checker.

How privacy is protected

This tool uses the k-anonymity model: your password is hashed locally, only the first 5 characters of the hash are sent to the API, and the full password never leaves your browser. See the technical details below.

Protocol Explanation

What is k-Anonymity?

We use the Have I Been Pwned range API. When you scan a password, we hash it locally using SHA-1. We send only the first 5 characters of that hash (e.g. 21BD1) to the server. The server responds with a list of all leaked hashes starting with those 5 characters. We then search that list locally on your computer for the remaining suffix. Your plain text password never leaves your browser.

Privacy Model

How k-Anonymity Protects Your Password

1. Your password is hashed locally

When you enter a password, your browser computes a SHA-1 hash entirely on your device using the Web Crypto API. Your plain text password never leaves your browser — not even for a millisecond.

2. Only the first 5 characters of the hash are sent

The 40-character SHA-1 hash is split. Only the first 5 characters (the prefix) are sent to the Have I Been Pwned API. This prefix represents a small group — not your specific password.

3. The API returns all matching hash suffixes

The server responds with a list of all 35-character hash suffixes that share that same 5-character prefix, along with their breach counts. This list may contain hundreds of entries — your request is hidden among all of them.

4. Your browser compares locally

Your browser searches the returned list on your own device, comparing your full hash suffix against every entry. If a match is found, the breach count is displayed. The server never sees your full hash or your password.

5. Why this is safe even against a remote service

The k-anonymity model works because many users query the same 5-character prefixes. Your individual request is statistically indistinguishable from thousands of others. Even the API operator cannot determine which specific password you are checking — only that someone, somewhere, is checking passwords that share the same hash prefix.

Action Plan

What to Do After a Breach

1
Change the password immediately on every service where you used it. Do not wait — compromised credentials are often automated within hours.
2
Check other services where you used the same or similar passwords. Password reuse is the #1 way attackers pivot from one breach to dozens of accounts.
3
Enable 2FA/MFA on affected accounts. Even if your password is compromised, two-factor authentication adds a critical second layer that blocks most unauthorized access attempts.
4
Generate a new, unique password using the Password Generator. Avoid reusing old passwords or making minor variations of the breached one.
5
Monitor for unusual activity on your accounts — unfamiliar logins, password reset emails, or transactions you did not authorize. Report anything suspicious to the service provider immediately.
Important Context

Limitations to Understand

Only checks passwords in known breaches

This tool queries the Have I Been Pwned database, which contains passwords from publicly disclosed breaches. A password that does not appear here may still have been compromised in a private or undisclosed incident.

Does NOT detect weak passwords

A password like "password123" may not appear in breach databases yet is trivially guessable. This tool only checks if a password has been seen before — not if it is strong. Use the Strength Checker to evaluate password quality.

Breach databases update periodically, not in real-time

New breaches take days or weeks to appear in the database after discovery. A password compromised in a very recent breach may not show up yet. Check again periodically for the most current results.

"Not found" does not mean "safe"

A clean result means the password was not found in known breaches — but it does not guarantee the password is secure. It could still be weak, predictable, or compromised in an incident not yet added to the database. Always combine breach checking with strength analysis.

Introduction

Your password could be sitting in a leaked database right now, circulating on dark web forums, and you'd never know it. The Breach Checker lets you test your credentials against the Have I Been Pwned API — the same database security professionals use to detect compromised accounts. In seconds, you'll know if your password has appeared in any of the billions of records exposed in known data breaches. This is the tool that turns 'I think I'm safe' into 'I know I'm safe' — or 'I need to change this immediately.'

What This Tool Does

Why It Matters

Every major breach exposes millions of credentials that attackers immediately feed into credential stuffing bots — automated tools that test leaked username-password pairs across hundreds of services. The 2024 Verizon DBIR found that 49% of breaches involved stolen credentials, and Credential stuffing attacks succeeded 1-3% of the time across billions of attempts. A single compromised password can cascade into email takeover, financial fraud, and identity theft. Checking your password against known breaches isn't paranoia — it's basic digital hygiene that takes three seconds and could save you from a catastrophic account compromise.

How It Works

Step-by-Step Examples

Example 1: Check if a password has appeared in known breaches
1

Enter a password in the input field (the password is hashed locally using k-anonymity — only the first 5 characters of the SHA-1 hash are sent to the API)

2

The tool sends the partial hash to Have I Been Pwned's breached password API

3

The API returns all known hash suffixes matching that prefix

4

If your password's full hash matches any returned suffix, it has been found in a breach

ResultPassword found in 2,347 breaches — must be changed immediately on every account where it was used
Example 2: Verify a new password is not previously compromised
1

Generate a new password using the Password Generator tool

2

Copy the generated password and paste it into the Breach Checker

3

Wait for the k-anonymity API response (typically under 200ms)

4

A clean result means the password has not appeared in any indexed breach database

ResultPassword not found in any known breaches — safe to use (but always unique per service)

Code Examples

javascriptk-Anonymity Breach Check with the HIBP API
async function checkPasswordBreach(password) {
  // Step 1: SHA-1 hash the password locally
  const encoder = new TextEncoder();
  const data = encoder.encode(password);
  const hashBuffer = await crypto.subtle.digest('SHA-1', data);
  const hashArray = Array.from(new Uint8Array(hashBuffer));
  const hashHex = hashArray.map(b => b.toString(16).padStart(2, '0')).join('').toUpperCase();

  // Step 2: Extract first 5 characters (k-anonymity prefix)
  const prefix = hashHex.slice(0, 5);
  const suffix = hashHex.slice(5);

  // Step 3: Query HIBP API with only the prefix
  const response = await fetch(
    'https://api.pwnedpasswords.com/range/' + prefix,
    { headers: { 'Add-Padding': 'true' } }
  );
  const text = await response.text();

  // Step 4: Check if our suffix appears in the results
  const lines = text.split('\n');
  for (const line of lines) {
    const [hashSuffix, count] = line.split(':');
    if (hashSuffix.trim() === suffix) {
      return {
        breached: true,
        count: parseInt(count.trim(), 10),
        message: 'Found in ' + count.trim() + ' breaches'
      };
    }
  }

  return { breached: false, count: 0, message: 'Not found in any known breaches' };
}

// Usage
const result = await checkPasswordBreach('MyP@ssw0rd123');
console.log(result);
// { breached: true, count: 2347, message: "Found in 2,347 breaches" }
javascriptBulk Breach Check for Multiple Passwords
async function checkMultiplePasswords(passwords) {
  const results = [];
  
  for (const password of passwords) {
    const encoder = new TextEncoder();
    const data = encoder.encode(password);
    const hashBuffer = await crypto.subtle.digest('SHA-1', data);
    const hashArray = Array.from(new Uint8Array(hashBuffer));
    const hashHex = hashArray.map(b => b.toString(16).padStart(2, '0')).join('').toUpperCase();
    
    const prefix = hashHex.slice(0, 5);
    const suffix = hashHex.slice(5);
    
    const response = await fetch(
      'https://api.pwnedpasswords.com/range/' + prefix,
      { headers: { 'Add-Padding': 'true' } }
    );
    const text = await response.text();
    
    let breachCount = 0;
    for (const line of text.split('\n')) {
      const [hashSuffix, count] = line.split(':');
      if (hashSuffix.trim() === suffix) {
        breachCount = parseInt(count.trim(), 10);
        break;
      }
    }
    
    results.push({
      password: password.slice(0, 3) + '*'.repeat(password.length - 3),
      breached: breachCount > 0,
      count: breachCount
    });
    
    // Rate limit: wait 1.5 seconds between requests
    await new Promise(r => setTimeout(r, 1500));
  }
  
  return results;
}

How the k-Anonymity Model Protects Your Password

StepWhat HappensPrivacy Guarantee
1. Local HashingYour password is SHA-1 hashed entirely in your browserRaw password never leaves your device
2. Prefix ExtractionOnly the first 5 hex characters of the hash are extractedAPI server never sees your full hash
3. API QueryThe 5-character prefix is sent to HIBPNo password, no full hash, no identifying data transmitted
4. Suffix MatchingHIBP returns all hash suffixes matching that prefix (typically 200-800 results)Your specific hash is indistinguishable from the other hundreds returned
5. Local ComparisonYour browser compares your full hash against returned suffixesThe match check happens entirely on your machine

Breach Severity by Credential Type

Credential TypeRisk if CompromisedAction Required
Email + PasswordHigh — enables account takeover, email access, password resetsChange immediately, enable 2FA
Password onlyMedium — dangerous if reused across multiple servicesChange on all accounts using this password
Email addressLow — enables targeted phishing, but no direct accessMonitor for suspicious activity
Password hash (bcrypt)Very Low — computationally expensive to crackNo immediate action, but consider rotation

Benefits

  • Uses k-anonymity so your full password hash is never transmitted — only a 5-character prefix leaves your browser.
  • Checks against billions of real breach records from the Have I Been Pwned database, updated continuously.
  • Instant results in under 200 milliseconds with zero account creation or personal data required.
  • Detects passwords exposed in breaches you may not even know happened — old accounts, third-party leaks, and dark web dumps.

Use Cases

01

Verifying that a newly generated password has not appeared in any known data breach before deploying it to production systems.

02

Auditing existing passwords across personal and work accounts to identify credentials compromised in recent breaches.

03

Checking legacy or reused passwords during a security audit to determine which accounts need immediate credential rotation.

04

Validating employee passwords against breach databases as part of organizational security policies and compliance checks.

Common Mistakes to Avoid

✗

Assuming a password is safe because 'I've never been breached' — your password could appear in breaches of services you've never used if it was reused.

✗

Checking passwords through untrusted third-party services that may log your input — always use tools with client-side hashing and k-anonymity.

✗

Changing a breached password only on the compromised service instead of everywhere it was reused.

✗

Continuing to use a password after it appears in a breach, assuming the count is 'too low to matter' — even one breach means it's in attacker wordlists.

Security Implications

A password that has appeared in a known breach is no longer secret — it exists in attacker-controlled databases, rainbow tables, and credential stuffing lists. Attackers run automated tools that test leaked credentials across millions of services simultaneously. Even if the breach was from an obscure forum you used once, that password is now in the global attack surface. The k-anonymity model used by this tool ensures you can check your password without exposing it, solving the fundamental paradox of breach checking: you need to verify a secret without revealing it.

Security Information

Frequently Asked Questions

Fundamentals

What is a Password Breach Checker?

GeneratePass checks passwords against the Have I Been Pwned (HIBP) range API using the k-anonymity model. Your password is hashed locally with SHA-1 via crypto.subtle.digest('SHA-1', buffer). The resulting hex digest is split: only the first 5 characters of the hash prefix are sent to api.pwnedpasswords.com/range/{prefix}. The server returns all matching hash suffixes. Your browser then searches that list locally for the remaining suffix. The full password and full hash never leave your browser.

A 3-second cooldown is enforced between scans to respect the HIBP API rate limits. Passwords shorter than 8 characters or longer than 128 characters are rejected before hashing. If the returned count is 0, the password was not found in any known breach database — but this does not guarantee it is strong.

Technical Deep Dive

How k-Anonymity Protects Your Password

When you click "Scan Database," GeneratePass first hashes your password using SHA-1 via the Web Crypto API (crypto.subtle.digest('SHA-1', buffer)). The hex digest (40 characters) is split: the first 5 characters become the prefix, and the remaining 35 characters become the suffix. Only the 5-character prefix is sent as a GET request to https://api.pwnedpasswords.com/range/{prefix}.

The HIBP server responds with a text list of all hash suffixes (35 characters each) along with their breach counts, formatted as SUFFIX:COUNT lines. GeneratePass then iterates through this list on your device, comparing each line's suffix against your suffix. If a match is found, the count tells you how many times that password appeared in known breaches.

The k-anonymity model ensures that even the API operator cannot determine which specific password you are checking. With thousands of users querying the same 5-character prefix, your request is hidden among many others, providing strong privacy guarantees. A 10-second timeout aborts the request if the API is unresponsive.

Practical Applications

Real-World Use Cases

Account Auditing: Check all your existing passwords after a major breach is reported. When a company announces a data breach, immediately check if your credentials were affected. This is especially important for email and banking accounts.

Password Reuse Detection: If you have been reusing passwords across multiple sites, a breach checker reveals the full scope of your exposure. One compromised password could give attackers access to dozens of your accounts.

Security Compliance: Organizations can use breach checking as part of their security audit process to ensure employee passwords have not been compromised in known incidents. This is a critical step in maintaining SOC 2 and ISO 27001 compliance.

Incident Response: Security teams can quickly assess the impact of a reported breach by checking organizational credentials against the newly leaked database. This helps prioritize which accounts need immediate password resets.

Security Pitfalls

Common Mistakes to Avoid

Assuming a Clean Result is Permanent: A password that is safe today may be compromised tomorrow. Breach databases are constantly updated as new incidents are discovered. Make it a habit to check your passwords regularly, especially after hearing about major data breaches.

Using Untrusted Breach Checkers: Many online breach checkers actually send your password to their servers. If the tool is not privacy-focused, you risk exposing your password to yet another service. Always verify the tool uses client-side hashing and k-anonymity.

Ignoring the Result: Finding out your password is breached is only useful if you take action. Immediately change the compromised password on all affected accounts and enable two-factor authentication wherever possible.

Not Checking Reused Passwords: If your password appears in a breach, check every account where you used that same password. Password reuse is the most common way attackers gain access to multiple accounts from a single breach.

Enhance Your Security

Related Tools

After checking your passwords for breaches, strengthen your security with these complementary tools:

Honest Limitations

What This Tool Cannot Guarantee

No breach database is complete

This tool checks against Have I Been Pwned, which is the largest public breach database. But not all breaches are reported or included. "Not found" does not mean "never breached."

It does not check password strength

A password that has never appeared in a breach can still be weak. "password123" might not be in every breach database yet is trivially guessable. Use our Strength Checker for that.

Private breaches are invisible

Some breaches are never made public. If a company is hacked but does not disclose it, those passwords will not appear in any database.

Try It Yourself

k-Anonymity Visualizer

See the step-by-step flow of how k-anonymity protects your password. The server never sees your actual password or even the full hash.

Type a password above to see the k-anonymity flow...

Frequently Asked Questions

Is my password sent to any server when I use this tool?
No. Your password is hashed locally in your browser using SHA-1. Only the first 5 characters of the hash are sent to the HIBP API. The server never sees your actual password or the full hash. This is called k-anonymity.
What happens if my password is found in a breach?
If your password appears in the breach database, you should immediately change it on all accounts where it is used. Enable two-factor authentication (2FA) on important accounts and consider using a password manager to generate unique passwords for each service.
How often are breach databases updated?
The Have I Been Pwned database is continuously updated as new breaches are discovered and verified. Major breaches typically appear within days to weeks of discovery. We recommend checking your passwords regularly, especially after hearing about new data breaches.
Can I check if my email address has been in a breach?
Yes. Visit haveibeenpwned.com directly to check email addresses against known breaches. Our tool focuses specifically on password checking using the k-anonymity model for maximum privacy.
Is a password not found in any breach automatically safe?
Not necessarily. A clean breach check is a good sign, but it does not guarantee your password is strong. A short or simple password like "password123" might not appear in breaches yet could still be easily cracked. Always combine breach checking with strength analysis tools like our Password Strength Checker.