facebook-pixel

How to Check if Your Password Was Leaked in a Data Breach (2026 Guide)

L
Lunyb Security Team
··10 min read

Every year, billions of credentials are exposed through corporate data breaches, credential-stuffing dumps, and infostealer malware. If you reuse passwords—or even if you don't—there's a real chance one of your logins is already floating around a hacker forum. The good news: you can check if your password was leaked in a data breach in under two minutes using free, trustworthy tools. This guide walks you through exactly how to do it, what to do next, and how to make sure you never have to worry about it again.

What Does It Mean When a Password Is "Leaked"?

A leaked password is a credential that has been exposed publicly or sold privately after attackers stole it from a website, app, or user device. Once a password appears in a breach dataset, attackers feed it into automated tools that try the same email/password combination on hundreds of other sites—a technique called credential stuffing.

Password leaks typically happen in four ways:

  1. Server-side breach: A company's database is hacked and user records are stolen.
  2. Infostealer malware: Malicious software on a user's device silently exports saved browser passwords.
  3. Phishing: Users are tricked into typing credentials into a fake login page.
  4. Third-party exposure: A vendor or partner with access to accounts is compromised.

Regardless of the origin, the leaked data usually ends up in aggregated "combo lists" that circulate on the dark web, Telegram, and forums like the former RaidForums and its successors.

Why You Should Check for Leaked Passwords Right Now

If you haven't audited your credentials in the last six months, you are almost certainly overdue. Consider the scale: Have I Been Pwned currently indexes more than 13 billion compromised accounts across 800+ breaches, and that's only the publicly cataloged data. Real numbers are far higher.

Checking whether your password was leaked helps you:

  • Stop attackers before they take over your email, banking, or social accounts.
  • Identify which specific services betrayed your trust.
  • Break the habit of reusing weak or previously exposed passwords.
  • Satisfy compliance requirements if you handle customer data at work.

The 3 Best Free Tools to Check if Your Password Was Leaked

Not all breach-check tools are trustworthy. Some sketchy sites will actually log the passwords you type in. Stick with the reputable, privacy-respecting options below.

1. Have I Been Pwned (HIBP)

Created by security researcher Troy Hunt, Have I Been Pwned is the gold standard. You can search by email address to see which breaches you appeared in, or use the separate Pwned Passwords service to check a specific password.

Crucially, HIBP uses a technique called k-anonymity: your password is hashed with SHA-1 locally in your browser, and only the first 5 characters of the hash are ever sent to the server. HIBP never sees your actual password.

2. Google Password Checkup

Built into Chrome and Google accounts, Password Checkup automatically scans every password you've saved in Google Password Manager against known breach databases. Access it at passwords.google.com/checkup.

3. Mozilla Monitor (formerly Firefox Monitor)

Mozilla Monitor uses HIBP data on the backend but adds a friendlier interface, ongoing email alerts, and a paid tier that scours data-broker sites for your personal info.

Tool Free? Checks Passwords Ongoing Alerts Privacy Model
Have I Been Pwned Yes Yes (Pwned Passwords) Yes (email notify) K-anonymity, no full password sent
Google Password Checkup Yes Yes (auto-scans saved logins) Yes (in Chrome) Hashed, encrypted lookup
Mozilla Monitor Free + Paid ($8.99/mo) Indirectly (via breach) Yes Uses HIBP data, hashed
1Password Watchtower Requires subscription Yes (all vault items) Yes (in-app) K-anonymity via HIBP

How to Check if Your Password Was Leaked: Step-by-Step

Follow this exact process to audit your credentials safely.

Step 1: Check Your Email Address First

  1. Go to haveibeenpwned.com.
  2. Enter your primary email address in the search box and click "pwned?".
  3. Scroll through the list of breaches. Each entry shows the site, the date of the breach, and what data was exposed (email, password, phone number, etc.).
  4. Repeat for every email address you've used in the last decade—including old work and school accounts.

Step 2: Check Individual Passwords

  1. Navigate to haveibeenpwned.com/Passwords.
  2. Type or paste a password you're worried about.
  3. The tool will tell you how many times that exact password has appeared in known breaches. Even "1" is bad—attackers already have it on their wordlist.

Safety tip: Only use HIBP or your password manager for this. Never paste passwords into random "password checker" sites you found via ads.

Step 3: Run Your Password Manager's Audit

If you use 1Password, Bitwarden, Dashlane, Keeper, or NordPass, open the built-in security dashboard (Watchtower, Vault Health, Security Score, etc.). It will scan every stored login and flag:

  • Passwords that appear in known breaches
  • Reused passwords across multiple sites
  • Weak or short passwords
  • Accounts that support two-factor authentication but don't have it enabled

Step 4: Check Your Browser's Built-In Checker

  • Chrome: Settings → Autofill and passwords → Google Password Manager → Checkup
  • Safari: Settings → Passwords → Security Recommendations
  • Firefox: about:logins → look for red warning banners
  • Edge: Settings → Profiles → Passwords → Password Monitor

What to Do if Your Password Was Leaked

Finding out you've been exposed is stressful, but the recovery process is straightforward if you act quickly.

1. Change the Compromised Password Immediately

Start with the account that was breached. Then change the password on every account where you reused the same or a similar password. Attackers automate this—if you had "Summer2023!" on LinkedIn, they will try it on Gmail, PayPal, and your bank within hours.

3. Enable Two-Factor Authentication (2FA)

Even if attackers have your password, 2FA blocks them at the login prompt. Use an authenticator app (Aegis, Ente Auth, 1Password, Authy) or a hardware key (YubiKey, Google Titan). Avoid SMS-based 2FA when possible—SIM-swap attacks are increasingly common.

3. Check for Unauthorized Activity

Log into the affected account and review:

  • Recent login locations and devices
  • Sent email folders (attackers often delete evidence)
  • Forwarding rules, filters, and recovery options
  • Connected apps and API tokens
  • Payment methods and shipping addresses

4. Freeze Your Credit (if Financial Data Was Exposed)

If the breach included your Social Security number, driver's license, or banking info, place a free credit freeze with Experian, Equifax, and TransUnion. This blocks new accounts from being opened in your name.

5. Update Your Recovery Options

Attackers who briefly access an account often change the recovery email or phone number so they can regain access later. Verify these are still yours.

How to Prevent Future Password Leaks

Checking for leaks is reactive. The real win is making leaks harmless when they happen.

Use a Password Manager for Every Account

A password manager generates a unique, random 20+ character password for every site. When one site gets breached, only that one login is at risk. Free options like Bitwarden are excellent; paid options like 1Password add polish and family sharing.

Turn On Two-Factor Authentication Everywhere

Prioritize your email account first—it's the master key to almost everything else. Then secure banking, cloud storage, social media, and any account tied to a payment method.

Use Passkeys Where Available

Passkeys replace passwords with cryptographic keys stored on your device. They cannot be phished, reused, or leaked in a breach because the site never receives a shared secret. Apple, Google, Microsoft, GitHub, PayPal, and hundreds of other services already support them in 2026.

Practice Safe Link Habits

Many credential leaks start with a single phishing click. Before clicking shortened or unfamiliar links, preview the destination. If you share links yourself, use a reputable shortener with built-in link scanning and analytics—like Lunyb—so your audience isn't sent to a hijacked domain. For a deeper comparison of options, see our 2026 buyer's guide to URL shorteners.

Segment Your Email Addresses

Use email aliases (via iCloud Hide My Email, SimpleLogin, Addy.io, or Fastmail Masked Email) so every service gets a unique address. If one alias starts receiving spam, you know exactly which company leaked your data—and you can burn the alias without changing your real inbox.

Harden Your Network and Browser

Use encrypted DNS (DNS-over-HTTPS via Cloudflare 1.1.1.1, Quad9, or NextDNS) to prevent snoops from seeing which sites you visit. Choose a privacy-respecting browser like Firefox or Brave, and install uBlock Origin to block malicious ads that can deliver infostealers.

Common Mistakes to Avoid When Checking for Leaks

  • Typing passwords into unknown "checker" websites. Some are honeypots that collect credentials.
  • Only checking your primary email. Old aliases and forgotten accounts are frequently the leak source.
  • Changing the password but not the reused copies. One rotation is not enough if the same password is on 20 sites.
  • Ignoring "low-value" accounts. A leaked forum login can be pivoted into your email via password reset chains.
  • Skipping 2FA because "it's inconvenient." The 10 seconds it costs you costs attackers everything.

How Often Should You Check for Password Leaks?

Set up automated monitoring so you never have to remember. Subscribe to HIBP notifications for every email address you own, enable your password manager's continuous breach monitoring, and turn on Chrome or Safari's built-in password alerts. Then do a manual audit every 90 days as a backstop.

FAQ

Is it safe to type my password into Have I Been Pwned?

Yes. HIBP's Pwned Passwords service uses a technique called k-anonymity: your password is hashed locally in your browser using SHA-1, and only the first five characters of that hash are sent to the server. HIBP never receives your actual password, and the site is open-source and independently audited.

What should I do if my password appears in a breach but I don't recognize the site?

Change the password anywhere you might have used it, then use the HIBP breach details to identify the exposed service. If it's a site you don't remember signing up for, it may be an old account, a service acquired by another company, or a third-party vendor that had access to your data. Either way, treat every reused instance of that password as compromised.

Can hackers still get in if I have two-factor authentication?

2FA blocks the vast majority of credential-stuffing and phishing attacks. However, SMS-based 2FA can be defeated by SIM-swap attacks, and some phishing kits can proxy real-time 2FA codes. Use an authenticator app or hardware security key (like a YubiKey) for the strongest protection, and switch to passkeys where they're offered.

How do password managers know a password was leaked?

Reputable password managers integrate with breach databases like HIBP. They hash each stored password locally, send only a partial hash to the breach API, and compare the returned results against your full hash on your device. Your actual passwords never leave your vault.

Should I change all my passwords every 90 days?

No. Modern guidance from NIST and CISA says forced periodic rotation actually weakens security because users pick predictable variants (Password1, Password2...). Instead, use long unique passwords generated by a password manager, enable 2FA, and only rotate a password when there's evidence it was exposed. Continuous breach monitoring replaces the old calendar-based rotation habit.

Final Thoughts

Checking whether your password was leaked in a data breach is one of the highest-leverage security tasks you can do in 2026. It takes minutes, costs nothing, and can save you from account takeover, financial loss, and identity theft. Use Have I Been Pwned or your password manager's built-in monitor today, rotate any exposed credentials, and lock down the accounts that matter most with 2FA or passkeys.

For more practical privacy and security guides—plus tools like our own link shortener with built-in analytics—explore the rest of the Lunyb blog.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles