All tools

Breached Password Checker

Checks a password against Have I Been Pwned's corpus of billions of passwords exposed in breaches. Only the first five characters of its hash are ever sent.

Breached Password Checker

This is one of the two tools here that sends anything at all, and it is worth reading before you use it. Your password is hashed here, in your browser. Only the FIRST FIVE characters of that hash are sent to Have I Been Pwned. They reply with every hash suffix they hold beginning with those five characters - around a thousand of them - and the comparison happens here. They learn a bucket holding roughly one password in a million and cannot tell which one you checked. Your password never leaves this page, no email address is involved, and nothing is stored or logged.

Elsewhere on this page we argue against strength checkers, because they teach people to type real passwords into web pages. This one is the defensible exception: the k-anonymity design means the password genuinely cannot be recovered from what is sent. It also answers a question a strength meter cannot - a password can look strong and still be in every attacker's wordlist.

Input

Checked only when you press the button, never as you type.

Ready to secure your organization?

Let’s discuss how we can strengthen your cybersecurity posture

CYBRS is a cybersecurity practice powered by Smart Plan for Information Technology (SPIT.sa).

Phone: 920014958Email: [email protected]

© 2026 All rights reserved.