Free online tools to generate, calculate,
convert, format, encode, and play.
 

Data Breach Checker

Check if your password has appeared in known data breaches. Uses the Have I Been Pwned API with k-anonymity — your full password is never sent over the network.


Check Details
SHA-1 Hash
Prefix Sent
Suffix Matched Locally
Hashes Returned by API
Privacy

Your password is hashed locally using SHA-1. Only the first 5 characters of the hash are sent to the API. The full password and hash never leave your browser.

K-Anonymity Model
  1. Password is SHA-1 hashed in your browser
  2. First 5 hex characters are sent to the API
  3. API returns all hashes matching that prefix
  4. Your browser checks for a match locally

How It Works

This tool uses the Have I Been Pwned Pwned Passwords API to check if a password has appeared in any known data breach. The database contains over 900 million compromised passwords collected from real-world breaches.

K-Anonymity: Your Password Stays Private

The check uses a technique called k-anonymity to protect your privacy. Instead of sending your password to the server, the process works like this:

  1. Hash locally: Your password is hashed with SHA-1 entirely in your browser. For example, password becomes 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8.
  2. Send prefix only: Only the first 5 characters of the hash (5BAA6) are sent to the Have I Been Pwned API.
  3. Receive candidates: The API returns all hash suffixes in its database that match that prefix (typically 500-800 results).
  4. Match locally: Your browser compares the remaining characters of your hash against the returned list. The match happens entirely on your device.

This means the API server never sees your password or its full hash. Even if someone intercepted the request, they would only know the 5-character prefix, which matches hundreds of different passwords.

What Should I Do If My Password Was Found?

  • Change it immediately on any account where you use that password.
  • Never reuse passwords across multiple sites or services.
  • Use a password manager to generate and store strong, unique passwords.
  • Enable two-factor authentication (2FA) wherever possible for an extra layer of security.

About the Data Source

The Have I Been Pwned project, created by security researcher Troy Hunt, aggregates data from publicly disclosed breaches. The Pwned Passwords list is updated regularly and is used by organizations worldwide, including government agencies and major technology companies, to prevent users from choosing compromised passwords.

Note: This tool checks passwords only. To check if your email address has appeared in a breach, visit haveibeenpwned.com directly.

Embed This Util

You can embed this util on your own site as a widget. Adding ?embed=1 to the URL loads a compact version with just the tool itself; no header, menu, or documentation. Paste this snippet into your HTML:


    

Copy snippet Adjust the height to taste.



Feedback

Help us improve this page by providing feedback, and include your name/email if you want us to reach back. Thank you in advance.


Share with