6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

Have I Been Pwned

SaaS

Have I Been Pwned is a breach notification service where people and organizations check whether email addresses and passwords appear in known data breaches.

haveibeenpwned.com
Have I Been Pwned homepage screenshot

About Have I Been Pwned

Have I Been Pwned, often shortened to HIBP, lets people search for their details in known data breaches and sign up for alerts. A person can enter an email address to see which known breaches exposed it, and the site displays a timeline of breaches and any appearances in public text dumps called pastes.

Beyond the public search, the service offers domain search for monitoring corporate domains, a Pwned Passwords tool for checking whether a password has been exposed, notification signups for future breaches, an API, NIST compliance guidance and an MCP server. Security teams, developers and managed service providers use it to monitor exposure at scale. Users can also opt out of having an address listed.

HIBP is a hosted service with a dashboard, a pricing page for subscriptions and a demos section. It carries sponsored recommendations for password managers and invites donations, and it publishes terms of use, a privacy policy and a data processing agreement for organizations that rely on it.

Key features

  • Email address breach lookup
  • Domain search for organizations
  • Pwned Passwords exposure check
  • Notifications for future breaches
  • API and MCP server access
  • Opt-out for listed addresses

Good fit for

  • →Individuals checking if their accounts were exposed
  • →Security teams monitoring company domains for breaches
  • →Developers blocking breached passwords at sign-up
Tags
data-breach
breach-notification
password-security
email-security
api
threat-monitoring

Open-source alternatives to Have I Been Pwned

See all

SaaS alternatives to Have I Been Pwned

See all