Has my password been leaked? How to check without giving it away
The obvious way to find out is to type the password into a website. That is also the mistake. Here is how a safe check works, and what to do with the answer.
You can find out whether a password has appeared in a known breach without sending the password to anyone. A well-built checker scrambles it on your own computer, sends only the first five characters of the scrambled version, and does the final comparison in your browser. If the password turns up, stop using it everywhere. If it doesn't, that is good news, not a guarantee.
"Has my password been leaked?" is a sensible thing to wonder, usually right after a breach notice lands in your inbox or a login alert shows up from a city you have never visited. We hear it from business owners in Denver, Boulder and Arvada, and just as often from their staff asking about a personal account.
The trouble is the first instinct: search for a checker, pick a result, type the password in. If that site is careless or dishonest, you have just handed over the one thing you were trying to protect. This post explains how a breach check works, how to tell a safe one from a risky one, and what to do next.
Where leaked passwords come from
When a company is breached, the stolen sign-in details tend to end up in large collections that criminals trade and reuse. They then try those same email-and-password pairs on other sites. The Federal Trade Commission describes the risk plainly: a stolen username and password only opens your other accounts if you used the same pair in more than one place, which is the reason never to reuse them.
That is why one old breach at a shop you forgot about can turn into a break-in at your email or your bank years later.
Why typing your password into a random site is risky
A password checker is a box that asks for a secret. Before you fill it in, think about what could happen on the other side:
- The site could keep it. You can't see what a server stores. A password typed into a form may be logged alongside your network address.
- The site could be a fake. A page built to collect passwords looks exactly like a page built to check them.
- Even a "scrambled" password can be attacked. Some services send a hash, a scrambled fingerprint of the password, and call that safe. Cloudflare's engineers, who helped design the safer method below, point out that a complete fingerprint sent to a third party can be stored and cracked later.
Troy Hunt, who runs Have I Been Pwned, the best-known public breach database, gave the same warning when he launched its password search: don't send a password you actively use to a third-party service, his own included. The method below exists so you don't have to.
It is the method we used for the password check in Reported, our free scam checker, so that neither we nor anyone else receives what you type.
Has my password been leaked? How the safe check works
The technique is called k-anonymity. The name is technical; the idea is simple. You never ask "is this password in your list?" You ask for a pile of several hundred possibilities and look through the pile yourself. Have I Been Pwned documents it in four steps:
- Your browser scrambles the password. It runs it through a one-way function called SHA-1, which turns any password into a 40-character string of letters and numbers. This happens on your computer.
- Only the first five characters are sent. Not the password, and not the full scrambled version.
- The database sends back every match for those five characters. That is hundreds of different leaked passwords that happen to start the same way, each with a count of how many times it has been seen. The service's documentation puts a typical response at around 800 entries.
- Your browser checks the list. It looks for the rest of your scrambled password among them. The answer is worked out on your side of the connection.
The database can't tell which of those hundreds of entries you were asking about, or whether yours was there at all. In Cloudflare's words, the service never gains enough information about a password that hasn't been breached to be able to breach it later.
A good comparison: instead of reading your house number to a stranger, you ask for the list of every address on streets beginning with "W" and find yours quietly at home.
How to tell a safe checker from a risky one
- It says what is sent, before you press the button. Look for wording like "only the first five characters of the scrambled password." If the page is silent on this, don't use it.
- It names its data source. The public Pwned Passwords service is free to query and needs no account or key, so there is no reason for a checker to be vague about where the data comes from.
- It doesn't ask for your email and password together. A safe password lookup needs the password alone. A site that wants both has the full key to your account.
- You may already have one. Many password managers and browsers include a breached-password alert. Check the documentation for the one you use to see how it performs the lookup.
Checking an email address is a different lookup. It tells you which breaches that address appeared in, and it does require sending the address. That is a smaller risk than sending a password, since your address is already known to everyone who emails you, but a trustworthy tool will still say so.
What the result means
If it was found: treat the password as public. It doesn't matter whether it leaked from your account or from someone else who chose the same one; it is on the lists criminals try first. Have I Been Pwned's own advice for a password that appears in a breach is that it should never be used.
If it wasn't found: the password isn't in the breaches this database knows about. It can still be guessed, phished, or sitting in a breach nobody has published yet. A clean result is a reason to relax a little, not a certificate.
If your password has been exposed: a checklist
- Change it where it matters most first. Email comes before everything, because whoever controls your inbox can reset your other passwords. Then banking, payroll, and anything that holds a payment card.
- Change it everywhere else you used it. The FTC's advice covers near-copies too: if you reused the same password, or a similar one, on other services, change it there as well.
- Make the replacement long and used once. The FTC says to aim for at least 12 characters; CISA, the federal cybersecurity agency, recommends at least 16. A passphrase of random words is fine.
- Let a password manager do the remembering. CISA describes one as a program that generates, stores and fills in your passwords, so you only need to remember a single strong one.
- Turn on two-step sign-in. With it, a stolen password alone isn't enough to get in. The FTC notes that codes sent by text or email are the least secure kind, so choose an authenticator app or a security key where you can.
- Don't bother with a change-every-90-days rule. Current federal guidance from NIST, the standards agency, says organizations should not require periodic password changes, and should force one when there is evidence a password has been compromised. Change on evidence, not on the calendar.
For a small office
One reused password is a personal problem until it is also the password for the shared mailbox or the accounting login. If you run a small team on the Front Range, the practical version of this post is short: give everyone a password manager, switch on two-step sign-in for email first, and make it normal to say "I think my password leaked" without anyone getting in trouble. The same NIST guidance tells the services you log in to that they should screen new passwords against lists of known-compromised ones, so expect more sites to reject a leaked password outright.
At Lab 5280 we work with your team, not just for you, and our focus is on automating how a business runs. Part of that is making the safe habit the easy one, which is why the tool we built explains what it sends in one sentence, right beside the box.
Common questions
Is it safe to type my password into a leak checker?
Only if the checker never receives the password. A safe one scrambles the password on your own computer and sends just the first five characters of the scrambled version, then does the final comparison in your browser. If a site doesn't explain what it sends, don't type a password you use into it.
My password was not found. Does that mean it is safe?
No. It means the password isn't in the breach collections the database knows about. Keep it long, unique to one account, and backed by two-step sign-in.
What should I do if my password has been leaked?
Stop using it everywhere. Change it on every account that used it or something similar, starting with email and banking, and turn on two-step sign-in.
Want to check one now?
Reported's password check uses the method described here. The password is scrambled on your computer and only the first five characters of the scrambled version are sent. It's free and needs no account.
Open Reported- API documentation: Pwned Passwords range search — Have I Been Pwned
- Pwned Passwords — Have I Been Pwned
- Validating Leaked Passwords with k-Anonymity — Cloudflare
- I've Just Launched "Pwned Passwords" V2 — Troy Hunt
- Creating Strong Passwords and Other Ways To Protect Your Accounts — Federal Trade Commission
- Use Strong Passwords — Cybersecurity and Infrastructure Security Agency
- SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management — NIST