Is your password
already stolen?
Billions of passwords have leaked in data breaches, and attackers try those lists first. Check one against the whole corpus — without ever sending it to anyone.
- Length
- Character set
- Offline guessing time (estimate)
-
Hashed here, in your browser
-
Only these five characters were sent
-
Breached hashes received back, then compared on your device
Five hex characters match hundreds of millions of possible passwords, so the server cannot tell which one you typed — or whether it matched. This is called k-anonymity, and the breach data comes from Have I Been Pwned. This site has no analytics, so nothing here is logged either.
A found password is not a small problem.
If a password of yours is on those lists, every account using it is effectively unlocked. Three things fix that permanently.
Stop reusing
One breached site hands attackers the key to every other account sharing that password. A password manager makes every login different without you memorising anything.
Turn on two-factor
Even a stolen password fails without the second step. Email first, then banking, then everything else — it takes about ten minutes per account.
Check what leaked
Knowing which breach exposed you tells you which accounts to fix first. We do this with clients as part of an account security checkup.
We’ll lock it down with you.
Password managers, two-factor, recovering a compromised account, and checking what has actually leaked — done with you, in plain language, usually in a single session.