Pwned Password Check 한국어

Has My Password Been Leaked?

Type a password to see how many times it appears in known data breaches. It is hashed with SHA-1 on your device and only the first 5 characters of the hash are sent, so your password itself never leaves your browser.

Password breach count

Your password is hashed with SHA-1 on this device and only the first 5 characters of the hash are sent. The server never receives your password or its full hash (k-anonymity).

Was a service I use breached?

If your password was pwned

  1. Change it on every site where you use it.
  2. Use a unique password per site and let a password manager remember them.
  3. Turn on two-factor authentication (a code from an app or text when you sign in).
  4. Check your email address at haveibeenpwned.com to see which breaches included your account.

How this check works

  1. Your browser turns the password into a 40-character SHA-1 hash.
  2. Only the first 5 characters go to Have I Been Pwned, which returns every breached hash starting with them.
  3. Your browser looks for the remaining 35 characters in that list and shows the count.

Data: Have I Been Pwned (CC BY 4.0)

FAQ

Is it safe to type my password here?

Yes. Your password is turned into a SHA-1 hash on your device, and only the first 5 characters of that hash are sent to Have I Been Pwned. The server returns hundreds of hashes starting with those characters and your browser checks for a match locally (k-anonymity). Neither the server nor we can tell which password you checked.

If it says 0 times, is my password strong?

Only that it isn’t in known breach lists. Short passwords or ones with names and birthdays can still be guessed easily. Use 12+ characters and a different password for every site.

What does the number mean?

It is how many times that password appeared across breached password collections. Even once means it is on attackers’ first-try lists — change it now.

Can I check whether my email was in a breach?

This page doesn’t ask for your email. You can search breached services by name below, or check your email directly at haveibeenpwned.com.

Where does the data come from?

From Have I Been Pwned, run by security researcher Troy Hunt (CC BY 4.0). It covers billions of breached passwords and every publicly known breach it has loaded.