In June 2026 alone, security researchers added more than 124 million newly stolen passwords to the world’s largest breach-tracking database, and one of them could be yours without you ever knowing it.
Most leaks trace back to one of two sources:
- A company gets hacked, and its user database ends up online.
- Malware (Infostealer) quietly copies passwords saved in your browser and sends them to cybercriminals.
Either way, you won’t feel it happen. Checking is the only way to know.
Check Your Email at Have I Been Pwned
This is the quickest option, and you don’t need to create an account.
- Open a browser and go to haveibeenpwned.com
- Type the email address you want to check into the search box.
- Click “Check”.
If the site says your email wasn’t found (0 Data Breaches), that’s good news, but it only means your address hasn’t shown up in a breach the site already knows about. New breaches get added often, so it’s worth checking again every few months.
If the site lists one or more breaches, it will name the companies involved and what kind of data was exposed, such as passwords, phone numbers, or physical addresses. Scroll through the list and note every breach that mentions passwords specifically.
Tip: On the same page, you can sign up for free alerts. Have I Been Pwned will then email you automatically the next time your address turns up in a new breach, so you don’t have to keep checking by hand.
Check One Password Without Sharing Your Email
Have I Been Pwned also lets you check an individual password on its own, separate from any email address.
- Go to haveibeenpwned.com/Passwords
- Type the password you want to check into the box.
You don’t need to worry about typing a real password in. The site never sees or stores it. Your device scrambles the password first and sends only a small fragment of that scrambled version to check for a match. This method is called K-Anonymity, and it’s the same technique many password managers use behind the scenes.
If the result says the password has been seen before, stop using it anywhere, even on accounts that seem unrelated.
Safety note: Only run this check on the official haveibeenpwned.com domain. Copycat sites sometimes show up in search results and ask for your real password with no privacy protection in place.
Let Your Browser or Phone Check Automatically
If you already save passwords in Chrome, Safari, Edge, or Firefox, that browser can scan its own saved passwords and flag any that have leaked. Each tool only checks passwords saved inside it, so if you use more than one browser, check each one separately.
Chrome or Android (Google Password Manager)
On a computer:
- Open Chrome.
- Click the three-dot menu in the top right corner.
- Select “Passwords and autofill.”
- Select “Google Password Manager.”
- Click “Checkup” in the left sidebar.
Chrome sorts any problems into three groups: Compromised (found in a breach), Reused (the same password on more than one site), and Weak (easy to guess). Fix compromised passwords first.
On an Android phone:
- Open the Settings app.
- Tap “Google.”
- Tap “Password Manager.”
- Tap “Check passwords.”
iPhone or Mac (Apple Passwords App)
On an iPhone or iPad:
- Open Settings.
- Tap “Apps.”
- Tap “Passwords.”
- Tap “Security.”
- Turn on “Detect Compromised Passwords” if it isn’t already on.
- Review any accounts listed as compromised, reused, or weak.
On a Mac, open the Passwords app directly and select Security to see the same list.
Microsoft Edge (Password Monitor)
- Open Edge.
- Click the three dots in the top right corner.
- Select “Settings.”
- Select “Passwords and autofill.”
- Select “Microsoft Password Manager.”
- Select “Password security check.”
- Click “Check now.”
Firefox (Mozilla Monitor)
Firefox’s password manager warns you automatically if a saved login matches a known breach, but you can also check directly.
- Go to monitor.mozilla.org
- Enter your email address.
- Follow the prompts to see your breach report.
What to Do If a Password Has Leaked
- Change that password immediately on the affected site.
- Change it everywhere else too, if you’ve ever reused it. This step matters most, since criminals test leaked passwords across many popular sites at once in what’s called a credential stuffing attack.
- Turn on Two-Factor Authentication for that account if it’s offered. This adds a second step, usually a code sent to your phone or generated by an app, so a stolen password alone isn’t enough to get in.
- Use a password manager to generate a new, unique password instead of typing one from memory.
Changing a leaked password often fixes the immediate problem, but it doesn’t undo the leak itself. If the breach also exposed things like security question answers or your date of birth, keep an eye on that account for unusual activity for a while afterward.
When to Get Extra Help
If a breach exposed more than a password, such as a Social Security number, bank account details, or a copy of a government ID, changing a password isn’t enough on its own. Contact your bank about a fraud alert, consider freezing your credit with the major credit bureaus, and look into an identity theft protection service if you want ongoing monitoring.
Quick Recap
Check haveibeenpwned.com first since it’s free and takes seconds. Then run the built-in checkup on whichever browser or phone you use to catch anything saved locally. If something turns up, change that password everywhere you used it, turn on two-factor authentication, and switch to a password manager so it matters less next time.































