Have I Been Pwned
Checks whether an email address or phone number appears in known data breaches and lists which breaches exposed it.

- Categories
- Breach DataEmail OSINT
- Price
- Freemium
- Setup
- Easy to use
Have I Been Pwned is Troy Hunt’s public breach directory. You enter an email address or a phone number and it tells you which loaded breaches and pastes contain that value. The homepage currently lists about a thousand pwned websites and more than 17 billion pwned addresses. Those counts move.
Anyone can run a single check in the browser. You can subscribe to notifications for an address you control. Organizations that need to search other people’s addresses, or to do it in bulk, use the paid API. Pwned Passwords is a separate service for checking whether a password has appeared in a dump, without sending the password itself.
Why it is in the directory
It is the citation people already understand. When I need to write “this address appeared in the 2021 LinkedIn scrape” and have the reader believe me, HIBP is the source I point at. The breach pages name the incident, the date, and the kinds of data involved. That is a different product from a raw combo search.
It is also honest about scope. A clean HIBP result does not mean the address is safe. It means it is not in the breaches Hunt has loaded. Stealer logs, closed marketplaces, and fresh dumps show up in HackCheck or IntelBase first.
How I use it
I run it early, because it is free and fast, and I do not stop there if the case is serious. For password exposure on an account I am authorized to test, I use Pwned Passwords rather than pasting a password into a random search box. For monitoring a client’s domain, the paid API is the grown-up path.
Everyone should know it. The Gems are the tools I pay for when HIBP is not enough.



