Have I Been Pwned? How to Check If Your Email Was Leaked
What pwned means, how Have I Been Pwned and Pwned Passwords work, how to read your results, and exactly what to do if your email or password was leaked.
Have I Been Pwned is a free website that tells you whether your email address has appeared in a known data breach. You type in an address, and it lists every breach it knows of that included that address, along with what kind of data leaked: passwords, names, phone numbers, home addresses, IP addresses, and more. If you have used the internet for more than a few years, the answer is almost certainly yes.
This guide explains what "pwned" means, how Have I Been Pwned works and whether it is safe to use, how to read your results, and, most importantly, exactly what to do if your email or password shows up. It also covers the scams that use breach data, and what it means when a breach exposed your IP address. IP Trackers is not affiliated with Have I Been Pwned. We explain it because it is the most useful first check after any breach.

What Does "Pwned" Mean?
"Pwned" (usually pronounced "powned" or "poned") is internet slang for "owned": beaten, dominated, or taken control of. It started in online gaming, where a mistyped "owned" (the P key sits next to the O key) became a joke that stuck. In security, it means compromised. An account that has been pwned has had its details exposed or taken over.
So when someone says "I got pwned", it means one of two things depending on context: they lost badly in a game, or their account or data was compromised. If you found this page because a breach notice or a check told you that you were pwned, it is the second meaning, and the steps below are for you.
What Is Have I Been Pwned?
Have I Been Pwned (HIBP) was created by Australian security researcher Troy Hunt and launched in December 2013, shortly after a huge breach at Adobe exposed data on well over a hundred million accounts. The idea was simple: when a breach becomes public, load the leaked data into a searchable index so ordinary people can find out whether they were affected, without having to download stolen data themselves.
Since then, HIBP has indexed data from hundreds of breaches covering billions of accounts, from big platforms to small forums and online shops. It has become a standard tool: password managers and browsers use its data, and many national governments use it to monitor their own email domains. Searching is free for individuals.
How to check your email
- Go to haveibeenpwned.com. Type the address yourself rather than following a link from an email or ad, because scammers imitate security tools.
- Enter your email address and search. No account or password is needed.
- Read the results. A green message means the address was not found in any breach HIBP knows about. A red result lists each breach, with its date, a description, and the types of data involved.
- Repeat for every email address you use or have used, including old ones. Old addresses often appear in the most breaches.
Notifications and domain search
A single search only tells you about breaches that are already known. HIBP's notification service emails you when your address appears in a new breach, which is the more useful long-term protection. You verify the address once and are told about future breaches automatically. Some breaches are marked as sensitive, for example leaks from adult sites, and only show up after you verify that you own the address, so nobody can look up your email to see them.
If you run a domain, such as a company or a family domain, the domain search feature lets you verify ownership and then see every address on that domain that has appeared in a breach.
Pwned Passwords: Checking a Password Safely
HIBP also runs Pwned Passwords, a separate list of hundreds of millions of real passwords that have appeared in breaches. Typing a password into a website sounds like exactly what you should never do, so the design is worth understanding.
It uses a technique called k-anonymity. Your browser turns the password into a SHA-1 hash, a fixed-length fingerprint, and sends only the first five characters of that hash. The service returns every leaked hash that starts with those five characters, often hundreds of them, and your browser checks locally whether yours is among them. The full password, and even its full hash, never leaves your device.
Many password managers and services check passwords against this list automatically. If a password manager warns that a password is "compromised" or "found in a breach", this is usually the source. A password on the list should never be used again anywhere, even if it looks strong, because attackers try every password on these lists first.
How to Read Your Results
- The breach date matters. A breach from ten years ago mainly matters if you still use the same password or security questions. A breach from last month needs action now.
- The data types matter most. Email addresses alone mean more spam and phishing. Passwords, even hashed ones, mean you must change them. Phone numbers raise the risk of scam calls, texts and SIM-swap attempts. Dates of birth, physical addresses and government ID numbers raise the risk of identity fraud.
- Hashed is not the same as safe. Many breaches store passwords as hashes. Weak hashing methods, or weak passwords, can be cracked quickly, so treat any leaked password as exposed.
- Being listed does not mean you are hacked right now.It means the service you used was breached. What happens next depends on whether you reused that password and what else leaked.
- Not being listed does not mean you are safe. HIBP only knows about breaches that have been made public and loaded into it. Many breaches are never disclosed.
What to Do If You Have Been Pwned
Work through these steps in order. The first three matter most.
- Change the password on the breached service. If the service still exists, change your password there. If you no longer use the account, consider deleting it so it cannot leak again.
- Change it everywhere you reused it. This is the step that actually prevents damage. Attackers take leaked email and password pairs and try them automatically on email, banking, shopping and social media sites, a technique called credential stuffing. A password reused on ten sites turns one breach into ten. A password manager makes unique passwords for every site practical.
- Turn on two-factor authentication. Start with your email account, because whoever controls your email can reset every other password. Prefer an authenticator app, a security key or passkeys over SMS codes, which can be intercepted through SIM swaps.
- Check your email account for tampering. Look at recent sign-in activity and active sessions, sign out of devices you do not recognize, and check for forwarding rules or filters you did not create. Attackers often add a rule that quietly forwards your mail to them.
- Review recovery options. Make sure the recovery phone number and backup email on important accounts are yours and current. Update security questions if their answers leaked. Better still, answer them with random text stored in your password manager.
- Protect your finances if identity data leaked. If the breach included government ID numbers, dates of birth or financial details, watch your bank and card statements closely. In the US you can freeze your credit for free with Equifax, Experian and TransUnion, which stops anyone opening new credit in your name.
- Expect targeted phishing. Breach data makes scam emails more convincing because they can include your name, your address or a real password. Be suspicious of any message that uses leaked details to create urgency. You can check where a suspicious email really came from with the email header analyzer.
If a Breach Exposed Your IP Address
Many breaches, especially of forums, games and online shops, include IP addresses, because services log the address you signed up or logged in from. HIBP lists "IP addresses" as a data type when that happened. It sounds alarming, but it is usually one of the less dangerous items in a breach.
An IP address reveals your internet provider and an approximate location, often the city or region, and sometimes not even that. It does not reveal your name or your home address. You can see exactly what your current IP reveals with the IP lookup. Most home connections also get dynamic addresses that change over time, so an IP from an old breach may belong to someone else today. The guides on what someone can do with your IP and whether someone can find you from your IP explain the real limits.
Where a leaked IP does matter is in combination with other data. An IP plus your name, email and the time you were online builds a more complete picture of you. If that concerns you, a VPN hides your real IP from the services you use in future. Read how to hide your IP for the options.
If You Appear in Infostealer Logs
Not all leaked credentials come from a company being breached. Some come from infostealer malware running on a person's own computer. It collects saved browser passwords, cookies and form data and sends them to criminals, who sell or share the logs. HIBP has loaded data from such logs in recent years.
If your credentials came from a stealer log, the problem is a device, not a website. Changing passwords on an infected computer does not help, because the malware captures the new ones too. Scan the device with a reputable security tool, or reinstall the operating system if you are unsure. Then change your passwords from a clean device and sign out of all sessions, because stolen cookies can let attackers skip the password entirely. The guide to avoiding computer viruses covers how this kind of malware usually gets in.
Scams That Use Breach Data
- "I know your password" extortion emails: a message quotes a real old password from a breach and claims the sender has hacked your webcam or device and will leak videos unless you pay in cryptocurrency. It is a bluff built entirely on leaked data. Do not pay or reply. If the quoted password is still in use anywhere, change it.
- Fake breach notices:scammers send "your account was compromised" emails that link to fake login pages. Go to the service directly instead of clicking links.
- Support-call scams:callers use your name, address or account details from a breach to sound like your bank or internet provider. Hang up and call the number on the company's own website.
- SIM swaps: with a leaked phone number and personal details, a criminal tries to move your number to their SIM card to receive your SMS codes. Ask your carrier for a port-out PIN or account lock, and move important accounts off SMS verification.
How Breaches Happen
Most of the data in HIBP comes from a handful of patterns: databases left exposed on the internet without a password, attackers exploiting unpatched web applications, stolen employee credentials, and insiders or third-party vendors with too much access. Once data is out, it spreads through criminal forums and marketplaces, many of them on the dark web, and gets combined into huge lists of email and password pairs used for credential stuffing. The guide to how hackers steal data covers these methods in detail.
The important point is that a breach is usually not your fault. You cannot stop a company from being breached. What you control is how much damage one breach can do, and that comes down to unique passwords, strong second factors and sharing less data in the first place.
How to Limit Damage From Future Breaches
- Use a password manager and a unique, generated password for every account. This single habit defeats credential stuffing.
- Use passkeys where offered. A passkey cannot be phished or leaked in a password breach, because the site never stores a secret that works anywhere else.
- Use email aliases. Services such as Apple Hide My Email, Firefox Relay or SimpleLogin give each site its own forwarding address. A breached alias can be switched off, and it shows you exactly which company leaked it.
- Share less. Skip optional profile fields, do not store cards on sites you rarely use, and delete accounts you no longer need.
- Sign up for breach notifications so you hear about new breaches without having to remember to check.
- Keep devices clean and updated to stay out of infostealer logs. Our internet security tips cover the basics.
Frequently Asked Questions
Is Have I Been Pwned safe and legitimate?
Yes. It is run by security researcher Troy Hunt, has operated since 2013, and its data is used by password managers, browsers and government agencies. Searching an email address is free and needs no account. Always type the address haveibeenpwned.com yourself rather than following links, because scammers imitate it.
What does it mean if my email has been pwned?
It means your email address was included in data leaked from at least one service you used. It does not mean your email account itself was hacked. Check which data leaked in each breach, change any passwords that were exposed or reused, and turn on two-factor authentication.
What does "I got pwned" mean?
It is slang for being beaten or compromised. In gaming it means losing badly. In security it means your account or data was exposed or taken over, for example in a data breach.
Should I be worried if I am on Have I Been Pwned?
Being listed is very common and not a reason to panic, but it is a reason to act. The real risk comes from reused passwords and from breaches that leaked identity or financial data. Unique passwords and two-factor authentication remove most of the danger.
Does Have I Been Pwned show my password?
No. An email search shows which breaches included your address and what types of data leaked, but never the leaked passwords themselves. The separate Pwned Passwords check tells you whether a password has leaked without the password ever leaving your device.
Can I remove my email from Have I Been Pwned?
You can opt out so that your address no longer appears in public searches. That does not remove your data from the original breach, which is already circulating. Opting out only hides the result on HIBP.
What should I do first after a data breach?
Change the password for the breached service and every other account where you used the same password, starting with your email. Then turn on two-factor authentication and check your email account for unfamiliar sessions or forwarding rules.
