Toolkit
Password Breach Check
Find out whether a password appears in known data breaches, without ever sending it to us. If it does, it is already in the wordlists attackers try first.
Your password is not sent anywhere. It is hashed in your browser and only the first five characters of that hash are transmitted. We receive around two thousand possible matches and compare them here, so neither we nor the breach index can tell which one was yours, or reconstruct it.
Why we built it this way
Asking someone to type a password into a website is normally terrible advice, and we would not ask you to do it if the password had to be transmitted. It does not. Your browser hashes it, sends five characters of that hash, and compares the results locally.
The same reasoning is why we do not offer a tool where you type in anyone's email address and see their breaches. That is not a security check, it is a targeting tool: it tells a stranger which of your staff to phish. Breach exposure for a domain is available, but only after you prove you control that domain's DNS.
If you found a password here
Changing it is the first step, but the more useful question is where else it was used. Credential-stuffing works because people reuse passwords, and the breach that exposed it was often somewhere unrelated to the account that gets taken over.
Check whether your domain can also be impersonated by email