Security

Password Leak Checker

A password leak checker tells you whether a password appears in known data breaches. This one uses k-anonymity: your password is hashed locally with SHA-1, only the first five characters of that hash are sent to Have I Been Pwned, and the match is resolved in your browser.

Last updated · Free, no signup

Loading interactive Password Leak Checker…

How can a password be checked against breaches safely?

A password leak checker compares a password's hash with hashes found in known breach datasets. This implementation uses the Have I Been Pwned range protocol so the service can return candidate suffixes without receiving the password or its complete SHA-1 hash.

The browser hashes the value locally, sends only the first five hexadecimal characters, and resolves the full match on the device. That k-anonymity design limits disclosure but does not make a reused password safe when no match appears; unpublished breaches, targeted theft, and weak guessable patterns remain possible.