Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Pwned Password Checker

See if a password has leaked in a data breach — without sending the password.

Security Uses live data Free, no sign-up

Check a password

Checked only when you press Check — never while you type. Nothing is stored.

Your password is hashed with SHA-1 on this device. Only the first 5 of its 40 hex characters are sent to Have I Been Pwned; the match is found here.

Next steps

About the Pwned Password Checker

Find out whether a password has been exposed in a data breach. Have I Been Pwned (HIBP) collects hundreds of millions of real passwords from breaches, and attackers try exactly those passwords first. NIST's Digital Identity Guidelines (SP 800-63B-4) require services to check every new password against a blocklist of commonly used, expected or compromised passwords — such as those from previous breaches.

The check never sends your password. Your browser hashes it with SHA-1, sends only the first 5 of the 40 hex characters to HIBP's free Pwned Passwords API, and receives every breached hash that starts with them — hundreds to thousands of them, padded with random decoys so that even the size of the reply reveals nothing. The tool then looks for the rest of your hash on your device and tells you how often the password was seen. You can also check a SHA-1 or NTLM hash directly, for example when auditing Windows or Active Directory hashes.

How to use it

  1. Choose Password, SHA-1 hash or NTLM hash.
  2. Type or paste the password (or hash), then press Check. The check only runs when you press it, never while you type.
  3. Read the result: how many times the password appeared in breaches, or that it was not found.
  4. Open What was sent to see the exact request: the 5-character prefix, the number of hashes returned and how many were padding.

Examples

A very common password
Input
password
Result
Found in data breaches — seen 5,23,72,427 times (about 52.4 million)

Result on 2026-10-03; counts grow as HIBP adds breaches. Its SHA-1 is 5BAA61E4…; only "5BAA6" was sent.

Checking an NTLM hash
Input
8846F7EAEE8FB117AD06BDD830B7586C (NTLM hash)
Result
Found in data breaches — seen 5,23,72,427 times

The NTLM hash of "password". In NTLM mode the request is /range/8846F?mode=ntlm.

A random password
Input
A 20-character password from a password manager
Result
Not found in Pwned Passwords

Not found only means it is not in the breach list — it says nothing about how guessable it is.

Common uses

  • Checking your own passwords, or a family member's, after hearing about a breach.
  • Deciding which old passwords to change first.
  • Checking a password before you start using it as a master password or Wi-Fi key.
  • Auditing SHA-1 or NTLM password hashes, such as those exported from Active Directory, without revealing them.

How the password stays private (k-anonymity)

The method was designed by Cloudflare and HIBP (Junade Ali, "Validating Leaked Passwords with k-Anonymity"):

  • Your browser computes the SHA-1 hash of the password, for example 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8 for "password".
  • Only the first 5 characters, 5BAA6, are sent. There are 1,048,576 possible prefixes, and each one is shared by hundreds to thousands of breached passwords, so the prefix does not identify yours.
  • The reply lists the remaining 35 characters of every breached hash with that prefix and how often each was seen. The request asks for padding: HIBP adds random fake entries with a count of 0, so the size of the reply does not give the prefix away.
  • Your browser looks for the rest of your hash in that list. HIBP never learns the full hash, and MySmartCoPilot's servers are not involved at all.

HIBP recommends checking only once a password is complete — checking every keystroke would send the prefixes of partial passwords — which is why this tool waits for Check.

What the result means

Found means the exact password appeared in at least one breach; the number is how many times it was seen across all of them. Even a count of 1 means it is on attackers' lists, so stop using it everywhere and change it wherever you used it.

Not found means it is not in HIBP's collection — not that it is strong. A short or predictable password that never leaked can still be guessed quickly, so check it with the Password Strength Checker too, and use a different password for every account.

SHA-1 and NTLM hashes

HIBP stores every password, encoded as UTF-8, as both a SHA-1 and an NTLM hash. SHA-1 hash mode takes a 40-character hex hash (SHA-1 of the UTF-8 bytes); NTLM hash mode takes the 32-character hashes Windows and Active Directory use — MD4 of the password's UTF-16LE text, so "password" is 8846F7EAEE8FB117AD06BDD830B7586C — and asks the API with ?mode=ntlm. Salted hashes such as bcrypt or Argon2 cannot be checked — every account's salt is different — so check the password itself.

Limitations

  • Needs an internet connection; privacy extensions or company networks that block api.pwnedpasswords.com stop the check.
  • The breach data is HIBP's and changes over time. MySmartCoPilot does not run or store it.
  • Email addresses cannot be checked here: HIBP's breached-account search needs an API key. Use haveibeenpwned.com for that.

Privacy

Your password never leaves your device. It is hashed with SHA-1 in your browser, and only the first 5 characters of that hash are sent to Have I Been Pwned’s Pwned Passwords API (api.pwnedpasswords.com), which returns every breached hash starting with them; the match is looked for on your device.

Frequently asked questions

Is it safe to type my real password here?

The password itself is never sent — only the first 5 characters of its SHA-1 hash, which hundreds of breached passwords share. You can see exactly what was sent under What was sent. Nothing is stored, and nothing goes to MySmartCoPilot's servers.

What does the number mean?

How many times that exact password appears in the breaches HIBP has collected. Popular passwords have millions; a count of 1 still means the password is in attackers' lists.

My password was not found. Is it safe?

It has not been seen in a known breach, which is good. It can still be weak: check its strength, keep it unique to one account and turn on two-factor authentication.

Why SHA-1? Isn't it broken?

SHA-1 is only used here to look up the password in HIBP's list, which is indexed by SHA-1 (and NTLM). Collision attacks on SHA-1 do not matter for that. It must never be used to store passwords — use bcrypt or Argon2 for that.

Why do I have to press Check?

So that nothing is sent while you are still typing. HIBP advises against checking on every keystroke, because the hash prefixes of partial passwords could help someone who watches the traffic.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.