Have I Been Pwned searches an email address against breaches loaded into its database and explains which services exposed what kinds of information. It turns vague concern into a list of accounts you can secure, while keeping password checks in a separate tool.
Read the result precisely
A match means the address appeared in one or more breaches known to the service. Open each record and note the exposed data classes, because an email-only leak calls for a different response from one containing passwords or security answers.
Turn the list into action
Change reused passwords, enable multi-factor authentication and review recovery details on affected accounts. Start with email, finance and other services that can unlock access elsewhere rather than changing low-risk accounts in random order.
Understand what no match means
A clean result is reassuring but not proof that an address has never leaked. Unknown, private or not-yet-loaded incidents will not appear, so unique passwords and multi-factor authentication still matter even when the search returns nothing.
Things to know
- Results cover known breaches loaded into the service, not every incident.
- A match does not prove that an account is currently being accessed.
- The homepage contains sponsorship and promotes additional products.
