Have I Been Pwned (HIBP) is a data breach lookup service: type an email address or username into its homepage and it tells you whether that account has shown up in publicly circulating breaches, which sites were involved, and what kinds of data were exposed. It was created in 2013 by Australian security researcher Troy Hunt, who still runs it today, and it is the best-known service of its kind — Firefox's breach monitor and 1Password's password check were both built on its data. Core searches are free and anonymous; domain monitoring and high-volume API access are sold as subscriptions.

At a Glance

  • URL: https://haveibeenpwned.com/
  • Type: Data breach lookup and security information service
  • Cost: Email search, password checks, and breach notifications are free; API access and domain monitoring are subscription-based, with the Core tier from US$4.39/month billed annually (pricing, as of 2026-08-30)
  • Sign-up: Public searches need no account; sensitive breach searches, domain search, and subscription management use a passwordless dashboard unlocked via an emailed verification link
  • Interface language: English only
  • Operator: Superlative Enterprises Pty Ltd, Queensland, Australia (privacy policy)

The Have I Been Pwned homepage: a search box with live corpus statistics below

The homepage is the search box, with live corpus figures underneath: 1,032 breaches and 17,795,083,974 pwned addresses (haveibeenpwned.com, as of 2026-08-30).

Background

HIBP grew out of the October 2013 Adobe breach, which exposed roughly 152 million accounts. While comparing breach dumps, Troy Hunt kept finding the same accounts compromised over and over — usually without the victims knowing — so on 4 December 2013 he launched HIBP with five incidents (Adobe, Stratfor, Gawker, Yahoo! and Sony) totaling about 154 million records (launch announcement). The name comes from gaming slang "pwned," meaning compromised; the ';-- in the logo is a classic SQL injection string (Wikipedia).

The service is operated by Hunt's Australian company, Superlative Enterprises Pty Ltd, which holds the "Have I Been Pwned" registered trademark. The core team is just three people: Hunt himself; Charlotte Hunt, who has run operations since 2021; and Stefán Jökull Sigurðsson, a part-time engineer since 2023 (About). In 2019 Hunt publicly explored selling HIBP ("Project Svalbard") but called the process off in March 2020, and the service has remained independent.

On reach, the subscription page claims more than 200,000 organisations monitoring over 400,000 domains, including over half of the Fortune 500, and says the FBI, the UK's NCA and Europol use HIBP data for victim notification. The FAQ also notes that the FBI and Dutch police supplied Emotet malware data to HIBP in April 2021 so victims could be notified.

What It Does

Email breach search

The public search is the main entry point: enter an email address or username and get back the list of breaches it appears in, each with a name, date, and the classes of data exposed (password hashes, phone numbers, addresses, and so on), plus "paste" records from public pasting sites. Breaches carry flags that describe their nature: sensitive (e.g. adult sites — excluded from public search and visible only after you verify ownership of the address; 87 such breaches at present), unverified, fabricated, and retired (removed from the system; 2 at present) (FAQ, as of 2026-08-30). The full catalogue is browsable on the Who's Been Pwned page.

The Who's Been Pwned page lists every breach loaded into HIBP

Who's Been Pwned: all 1,032 breaches sortable by name, affected accounts, and date added — the rows shown here were added in August 2026.

Pwned Passwords

A separate check for whether a password has appeared in breach data, and how many times. It uses a k-anonymity model: the browser hashes the password locally with SHA-1, sends only the first five characters of the hash, and completes the comparison against the returned suffixes on your side — the server never sees the password or its full hash (Pwned Passwords).

The Pwned Passwords page offers a privacy-preserving password check

The Pwned Passwords page: the check runs entirely under k-anonymity, and you can watch the range request in your browser's dev tools. The API is free and keyless, served by Cloudflare at a claimed 18+ billion requests per month with a cache hit ratio above 99.9%; the full corpus can also be mirrored offline with the open-source Pwned Passwords downloader.

Breach notifications (Notify Me)

A free subscription: enter an address, click the link in the verification email (double opt-in), and HIBP emails you if that address turns up in a newly loaded breach. Per the FAQ, the service stores only the address, the subscription date, and a random verification token.

Dashboard and domain search

The dashboard is passwordless: enter your address and follow the emailed link. Signed-in users can see their own sensitive-breach exposure, view the website domains captured alongside their address in stealer logs, and manage domains and subscriptions (sign-in page). Domain search is for domain owners: you prove control via a WHOIS contact address, a standard administrative mailbox (security@, postmaster@, etc.), a meta tag, an uploaded file, or a DNS TXT record, and can then list every breached address on that domain. Larger domains and ongoing monitoring require a paid subscription (privacy policy, FAQ).

API, Plans, and Open Data

HIBP exposes a REST API (v3): breach, paste, domain, and stealer-log endpoints require a paid hibp-api-key header, while Pwned Passwords queries are free and keyless. Every request must carry a user-agent header, and exceeding your plan's rate limit returns HTTP 429. HIBP also publishes an MCP server for AI agents, and free test keys exist for integration testing. Breach and paste data is licensed under CC BY 4.0.

Plan tiers (pricing, as of 2026-08-30; monthly equivalents of annual billing):

  • Core: US$4.39–319/month, 10–1,000 RPM, direct email search and monitoring for your own domains, five sizes based on how many breached addresses a domain has;
  • Pro: US$379–4,599/month, 1,000–16,000 RPM, adding k-anonymity email search, customer-domain monitoring, stealer-log data, and bulk domain verification, with 2- and 3-year discounts;
  • High RPM: US$1,150–5,833/month, 4,000–24,000 RPM for high-throughput email searching;
  • Enterprise: white-label deployment, real-time breach callbacks, no rate limits, custom terms.

HIBP also open-sources peripheral components on GitHub, including the Pwned Passwords Azure Functions implementation and the offline downloader (BSD-3-Clause; the downloader has about 1,291 stars as of 2026-08-30).

Privacy and Data Policy

For a site whose business is breach data, its own privacy stance is a key trust signal. Highlights from the published policies (Privacy; the Terms of Use were last updated in March 2026):

  • Searches are not stored: a query reads from storage and returns a result, nothing more. The site uses no third-party tracking cookies or pixels and runs no targeted advertising;
  • Loaded breaches store only the email address or username and the list of incidents it appeared in — passwords are never stored alongside personally identifying data. Data sits in a Microsoft Azure data centre in the western United States;
  • Notification and domain-search details are never shared with third parties beyond SendGrid for email delivery; payments are processed by Stripe;
  • A three-level opt-out lets you hide an address from public search, block current and future breach associations, or delete the address entirely;
  • The terms prohibit using HIBP data to solicit or disadvantage breach victims, and forbid building a substantially similar breach-search service on top of it.

Beyond subscriptions, the site accepts donations and shows a clearly labelled "Sponsored" slot for 1Password on the homepage.

When It's Useful

  • Personal check-ups: after breach news breaks or before rotating passwords, quickly see whether your addresses are involved;
  • Password hygiene: screen new passwords against Pwned Passwords before adopting them (a practice NIST guidelines recommend for services);
  • Security teams and developers: wire breach checks into signup, login, or risk flows via the API, and monitor corporate domains continuously;
  • Researchers and journalists: cite its public breach catalogue and timelines as a verifiable primary source.

Limitations

  • Coverage is inherently partial: HIBP itself stresses that it holds only a fraction of all historical breaches, so "not found" does not mean "not breached" (absence of evidence is not evidence of absence). Opt-outs and retired breaches also shrink visible results;
  • Sensitive breaches are invisible to public search — confirming them requires receiving a verification email at the address;
  • Results tell you which incident and which data classes were exposed, never the exposed content itself; the service cannot recover your actual passwords;
  • Username searches can misfire: common handles get registered by strangers, and you may appear in breaches of sites you never joined (data resold, services rebranded, or accounts created by someone else);
  • The interface is English-only;
  • The free public search handles one address at a time; all bulk capability sits behind paid tiers whose upper prices clearly target enterprise budgets.

Alternatives and Ecosystem

Many similar services are effectively wrappers around HIBP data: Mozilla's Firefox Monitor (later Mozilla Monitor) built its breach checks on HIBP starting in 2018, and 1Password integrated Pwned Passwords the same year and remains an official partner (Wikipedia, partners note). For most readers, going straight to HIBP is more direct than any downstream repackaging.

References

All sources checked on 2026-08-30: