Free tool
Breached password checker
Find out whether a password has appeared in known data breaches, without the password ever leaving your browser.
This tool runs in your browser and needs JavaScript. Turn JavaScript on to use it.
How your password stays private
- Your browser turns the password into a SHA-1 hash, a 40-character fingerprint of it.
- Only the first 5 characters of the hash are sent to the Pwned Passwords service, with padding so the size of the answer reveals nothing.
- The service returns every hash it knows that starts with those 5 characters, often hundreds of them.
- Your browser looks for the rest of your hash in that list, and tells you how often it was seen.
This method is called k-anonymity: the service never learns which password, or even which hash, you checked. KeyCare Pass's exposed passwords report uses the same method for every password in your vault.
If your password was found
Stop using it everywhere, starting with your most important accounts, and turn on two-step login where you can.
Never make up a password again
KeyCare Pass makes strong passwords, remembers them and fills them in for you.
Frequently asked questions
Who runs Pwned Passwords?
Pwned Passwords is part of Have I Been Pwned, a free service that collects passwords exposed in data breaches. It is not run by GovPAM.
Not found means it is safe?
Not quite. It means the password is not in the breaches the service knows about. A short or reused password can still be guessed.