facebook-pixel

How to Check if Your Password Was Leaked in a Data Breach (2026 Guide)

L
Lunyb Security Team
··9 min read

Every year, billions of credentials leak from hacked companies, misconfigured servers, and phishing kits. If you reuse passwords—or even just use them for a long time—there is a real chance one of yours is already floating around a criminal forum. The good news: you can check if your password was leaked in a data breach in under a minute using free, privacy-respecting tools. This guide shows you exactly how to do it, what to do next, and how to prevent future exposure.

What Does It Mean When a Password Is "Leaked"?

A leaked password is one that has appeared in a public or semi-public data breach—usually because a company was hacked and its user database was dumped online. Once a password appears in a breach corpus, attackers add it to credential stuffing lists and try it against thousands of other sites (banking, email, social media) hoping you reused it.

Even strong-looking passwords like Summer2024! become worthless the moment they appear in a leak, because attackers automate testing at scale. This is why breach-checking should be part of your regular digital hygiene, not a one-time task.

How Passwords End Up in Breaches

  • Company hacks: Attackers steal user databases from services you signed up for.
  • Phishing: You typed your password into a fake login page.
  • Malware: Info-stealers on your device harvest browser-saved credentials.
  • Third-party leaks: A vendor or contractor of a service you use gets compromised.
  • Insider leaks: Employees exfiltrate data intentionally or by accident.

How to Check if Your Password Was Leaked in a Data Breach

The safest way to check is with tools that use k-anonymity—meaning you never send your full password or email to a third party. Here is the step-by-step process.

Step 1: Check Your Email Address First

  1. Go to haveibeenpwned.com (HIBP), the industry-standard free breach database created by security researcher Troy Hunt.
  2. Enter your email address in the search box.
  3. Review the list of breaches your address appears in. Each entry shows the company, date, and what data was exposed (passwords, addresses, phone numbers, etc.).
  4. Repeat for every email address you use—including old ones.

If your email appears in even one breach that included passwords, assume that password is compromised on every site where you reused it.

Step 2: Check Specific Passwords Safely

HIBP also offers a Pwned Passwords service that lets you check a specific password without ever transmitting it in full.

  1. Visit haveibeenpwned.com/Passwords.
  2. Type the password you want to check. Your browser hashes it locally with SHA-1, sends only the first 5 characters of the hash to the server, and compares locally—your actual password never leaves your device.
  3. The tool tells you how many times that password appears in known breaches. Anything above zero = stop using it immediately.

Step 3: Use Your Password Manager's Built-In Scanner

Modern password managers scan your entire vault against breach databases automatically. Enable this feature in:

  • 1Password: Watchtower
  • Bitwarden: Reports → Exposed Passwords Report
  • Dashlane: Password Health
  • Proton Pass: Pass Monitor
  • Apple Passwords / iCloud Keychain: Security Recommendations
  • Google Password Manager: Password Checkup (passwords.google.com/checkup)

These tools flag reused, weak, and leaked passwords in one dashboard—far faster than checking one by one.

Step 4: Check Browser-Saved Passwords

If you save passwords in Chrome, Edge, Firefox, or Safari, all four browsers now include built-in breach alerts:

  • Chrome/Edge: Settings → Autofill → Password Manager → Checkup
  • Firefox: about:logins → look for the yellow warning banner
  • Safari: Settings → Passwords → Security Recommendations

Best Free Tools to Check for Leaked Passwords

Below is a comparison of the most trustworthy breach-checking services in 2026.

Tool Checks Privacy Method Free? Best For
Have I Been Pwned Email + Password k-Anonymity (SHA-1 prefix) Yes Everyone—the gold standard
Google Password Checkup Saved passwords Hashed + encrypted lookup Yes Chrome/Android users
Mozilla Monitor Email Uses HIBP data Yes (Plus tier paid) Ongoing monitoring
Apple Security Recommendations Keychain passwords On-device comparison Yes iOS/macOS users
1Password Watchtower Vault passwords k-Anonymity Included with subscription Power users
Bitwarden Data Breach Report Vault passwords k-Anonymity via HIBP Free tier available Open-source fans

Pros and Cons of Free Breach Checkers

Pros:

  • Instant results, no signup required for most
  • Uses privacy-preserving hashing so your data stays safe
  • Covers billions of leaked records across thousands of breaches
  • Integrated directly into browsers and password managers

Cons:

  • Cannot detect breaches that have not been publicly disclosed yet
  • Some "dark web scanners" from commercial vendors are marketing gimmicks reselling the same HIBP data
  • Email-only checks do not tell you which password leaked

What to Do if Your Password Was Leaked

Finding a leak is only useful if you act on it. Follow this response checklist within the next hour.

Immediate Actions (Do These Now)

  1. Change the compromised password on the breached site first. Use a unique, 16+ character password.
  2. Change it everywhere you reused it. This is where a password manager saves your life—search your vault for the old password.
  3. Enable two-factor authentication (2FA) on the affected account, preferably using an authenticator app or hardware key rather than SMS.
  4. Log out all active sessions from the account settings. This kicks out any attacker who is already logged in.
  5. Check for suspicious activity: unfamiliar logins, forwarding rules in email, unknown connected apps, changed recovery info.

Follow-Up Actions (Within the Week)

  1. Rotate passwords for high-value accounts (email, bank, cloud storage) even if they were not in the leak.
  2. Set up ongoing monitoring at Have I Been Pwned or Mozilla Monitor so you are alerted to future breaches.
  3. Freeze your credit if the breach exposed personal info like SSN, date of birth, or ID numbers.
  4. Review connected third-party apps in your Google, Microsoft, and Apple accounts.
  5. Update security questions—old answers may also be in the leak.

How to Prevent Future Password Leaks

You cannot stop companies from being hacked, but you can make sure a single breach never cascades into total account takeover.

1. Use a Password Manager for Every Account

A password manager generates and stores a unique, random password for every site. When one site leaks, only that single credential is compromised—everything else stays safe. Popular options include Bitwarden (free, open source), 1Password, Proton Pass, and Dashlane.

2. Turn On Two-Factor Authentication Everywhere

Even if your password leaks, 2FA blocks the attacker. Prioritize hardware keys (YubiKey, Google Titan) for critical accounts, and use TOTP apps (Aegis, Ente Auth, 2FAS) for the rest. Avoid SMS 2FA where possible—SIM-swap attacks are still common.

3. Use Passkeys Where Available

Passkeys replace passwords with cryptographic keys stored on your device. They cannot be phished or leaked in a breach because the server never stores anything reusable. Major sites like Google, Apple, Microsoft, Amazon, and PayPal now support them.

4. Use Email Aliases

Services like SimpleLogin, Firefox Relay, Apple Hide My Email, and DuckDuckGo Email Protection let you sign up for sites with unique aliases. If one leaks, you know exactly which company was breached, and you can burn that alias without touching your real inbox.

5. Be Careful What You Click and Share

Phishing links remain the number-one delivery method for credential theft. Before clicking any shortened link, hover to preview the destination. If you send shortened links yourself, use a reputable service that publishes transparent privacy practices—Lunyb is one option that focuses on clean, privacy-friendly link handling without the tracking bloat found in many free shorteners. For a broader comparison of shortener options and their security practices, see our 2026 buyer's guide to URL shorteners.

6. Harden Your Network and Device

Use encrypted DNS (like NextDNS, Cloudflare 1.1.1.1, or Quad9) to block known phishing and malware domains at the network level. Keep your OS, browser, and password manager patched—info-stealer malware often exploits outdated software to harvest stored credentials.

Common Signs Your Credentials Have Been Compromised

Even before a breach becomes public, you may see warning signs:

  • Password reset emails you did not request
  • Login notifications from unfamiliar locations or devices
  • Friends receiving spam or phishing messages from your account
  • New forwarding rules or filters in your email you did not create
  • Unexplained charges or subscription changes
  • Being suddenly locked out of an account

Any one of these should trigger the immediate-response checklist above.

How Often Should You Check for Leaks?

For a proactive routine:

  • Weekly: Glance at your password manager's health report.
  • Monthly: Run a full breach scan on all your email addresses.
  • Immediately: Any time you hear news of a major breach involving a service you use.
  • Continuously: Subscribe to Have I Been Pwned notifications so alerts come to you automatically.

Frequently Asked Questions

Is it safe to type my real password into Have I Been Pwned?

Yes. HIBP's Pwned Passwords tool uses k-anonymity: your browser hashes the password locally with SHA-1 and sends only the first five characters of the hash. The server returns all matching hash suffixes, and your browser checks locally. Your actual password never leaves your device. If you are still uncomfortable, use a password manager's built-in scanner instead—it works the same way behind the scenes.

My email shows up in a breach but I do not remember signing up. What now?

This usually means either (1) the site was acquired by or shared data with another service you did use, (2) someone signed you up without permission, or (3) the breach data was aggregated from multiple sources. Regardless of cause, check whether you reused any passwords tied to that email and rotate anything similar. Then enable 2FA on your email account itself, since your email is the recovery path for everything else.

Do "dark web monitoring" services from banks and antivirus companies actually help?

They typically use the same public breach data available through free tools like Have I Been Pwned, wrapped in a nicer dashboard. They can be convenient if you want a single alert stream, but they rarely provide unique intelligence. Do not pay premium prices just for basic breach alerts—use the free options and put your money toward a good password manager and hardware security keys instead.

Can attackers still get in if I change my password after a leak?

Changing the password blocks credential-stuffing attacks going forward, but if an attacker has already logged in, they may have created session tokens, app passwords, forwarding rules, or backup codes that survive the password change. That is why the response checklist includes logging out all sessions, revoking third-party app access, and reviewing account activity—not just changing the password.

Are passkeys really safer than long, random passwords?

Yes, for two reasons. First, the site never stores anything an attacker can steal and reuse—only a public key that is useless without your device. Second, passkeys are bound to the legitimate site's domain, so they cannot be phished onto a lookalike page. A 20-character random password in a manager is very strong, but a passkey removes entire categories of risk (breaches, phishing, credential stuffing) at once.

Final Thoughts

Checking whether your password was leaked in a data breach takes less than a minute and could save you from account takeover, identity theft, or financial fraud. Make it a habit: check your emails at Have I Been Pwned, enable the health scanner in your password manager, turn on 2FA everywhere, and start migrating to passkeys as sites support them. Breaches will keep happening—but with unique passwords, strong second factors, and regular checks, no single leak can unravel your digital life.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles