More than 17 billion accounts have already leaked online. One free website tells you whether yours has turned up in a known leak. No signup, no cost, nothing to install.
Most people reuse the same password across sites, so a single leak can quietly hand crooks the keys to your email, your bank, and your shopping accounts. Checking takes a minute. Cleaning up takes longer.
Start with your email
The tool to use is Have I Been Pwned, basically a search engine for stolen data. Built by security researcher Troy Hunt, it holds more than 17.5 billion leaked accounts from around 1,000 known breaches as of June 2026. Type in your email, hit enter, and it lists the breaches yours showed up in, with the breach name, the date, and the kinds of data exposed.
Have I Been Pwned breach search
For alerts instead of a one-time check, use Mozilla Monitor, formerly Firefox Monitor. It runs a free scan, then watches up to 20 of your email addresses and pings you when a new breach hits one. Its paid data-removal add-on shut down in December 2025, but the free breach alerts stay.
Check your passwords too
Your saved passwords can rat themselves out. Google's Password Checkup, built into your Google account and Chrome, flags any saved password caught in a leak or reused across sites. Apple's Passwords app does the same on iPhone and Mac, flagging weak, reused, and leaked logins. Both are free.
Google Password Checkup, Apple password recommendations
To check one specific password, Have I Been Pwned can do it without ever seeing the password, because your browser only sends the first few characters of a scrambled version. If that password has shown up millions of times, retire it everywhere right away.
Have I Been Pwned password search
What to do if you're in one
If you turn up in a leak, do not panic, but move fast, in this order:
- Change that password right away, plus anywhere else you reused it.
- Turn on two-factor login, or a passkey, for that account.
- Stop reusing passwords, and let a password manager invent a fresh one for every site.
- If a card number leaked, call your bank, cancel the card, and ask for a replacement.
- If a Social Security number or government ID leaked, freeze your credit for free and head to IdentityTheft.gov.
The second step matters most. The UK's National Cyber Security Centre calls turning on two-step login the single most important step, because it protects you even when your password is already out there. It also says to make passkeys your first choice where offered.
A password manager covers the third step, and the US agency CISA calls it one of the easiest ways to keep strangers out. On the credit freeze, the FTC says it is free and matters most when a Social Security number or similar ID leaks, because it blocks new credit accounts in your name.
CISA strong passwords, FTC credit freezes
What a checker can't tell you
A clean "you're safe" result is not a clean bill of health. These tools only know about breaches that went public, so a fresh or quiet leak simply will not appear. Treat good news as good news, not a guarantee.
Stick to names you trust, like the ones here. Some random site promising to "scan the dark web" might just be farming addresses for spam, or worse. Handing your email to a sketchy checker is its own little disaster.






