Have I Been Pwned

Breach exposure lookup for emails and domains

Best for Checking known breach, paste, password, domain, and supported stealer-log exposure in defensive account-security, credential-hygiene, and incident-response workflows.
Workflow Verification
Pricing / access Free · Browser-Based
Source checked 2026-05-27

Claims and corrections are reviewed before public profile changes.

Signal summary

  • VendorHIBP
  • PlatformPlatform coverage varies by tool.
  • Reviewed2026-05-27

Trust / disclosure

How to read this profile

Tested

Editorial line

Editorial judgment and commercial context are kept separate on OSINT4ALL.

Review status

This profile is marked as editor-tested; workflow notes and caveats are shown where available.

Claims / submissions

Corrections and claim requests are reviewed before any public change is made.

Commercial context

No commercial relationship is disclosed on this profile.

Editorial verdict

Use case and fit

This is editorial guidance, not vendor copy.

Best for

Checking known breach, paste, password, domain, and supported stealer-log exposure in defensive account-security, credential-hygiene, and incident-response workflows.

Editorial read

Strong defensive awareness tool, but public wording should avoid shaming people or implying that HIBP is a complete breach database.

Overview

Best when an email, domain, password, or stealer-log question needs breach-exposure context without treating exposure as blame.

Operational snapshot

Workflow, access, and coverage

WorkflowVerification
PricingFree
AccessBrowser-Based
RegionsGlobal
LanguagesEnglish
StatusStatus under review
Tool function
Core jobs

Email exposure lookup in known breach records

Works from

Email, Verified Domain

Produces

Breach Reference, Exposed Data Category, Exposure Notification

Workflow roles

Exposure Triage, Monitoring

Interpretation limits

No match does not rule out exposure. Email results do not reveal passwords or prove a current compromise. Domain-wide and sensitive-breach access require the relevant ownership verification.

Recommended workflow

Check the scoped email, domain, or password workflow, note breach names and dates, separate subscription-gated stealer-log context from public results, prioritize password reset and MFA, then verify any active incident through internal or direct evidence.

Language notes

English-first service; breach names, stealer-log terminology, and remediation language may need explanation for non-technical or multilingual audiences.

Limits

Strengths, caveats, and risk

Strengths

Widely used breach-notification service with domain monitoring, paid authenticated APIs, and privacy-aware Pwned Passwords range search.

Limitations

Email/domain APIs require keys and access tiers, stealer-log features are more restricted, and non-technical audiences can overread what a hit means.

Does not prove current compromise, account control, user fault, password reuse, or absence of breach exposure elsewhere; data only reflects what HIBP has loaded and exposes under each access model.

Risk note

Breach and stealer-log hits can expose sensitive personal history and may be misread as proof of current compromise, negligence, or wrongdoing.

Use breach data for defense, notification, and risk reduction; avoid republishing personal exposure details, leaked passwords, or victim-level stealer-log context.

Trust note

Treat HIBP as breach-exposure context, then verify active risk through password reset status, MFA, internal logs, account-owner contact, or incident-response evidence.

Maintenance

Source status & suggest an update

Help keep this profile accurate. Update requests are reviewed and logged before publication.

Source checked: 2026-05-27

If something is outdated, please submit a correction or ownership update request. Claim requests are reviewed and do not grant editorial control.

Commercial or sponsorship requests use the separate partner workflow.

Claim / Correct Listing