Every time a website you signed up to is breached, your email address can leak along with your password or phone number. There is a free way to find out for yourself: Have I Been Pwned, a service that collects data from publicly known breaches. Its counter today lists more than 17 billion exposed accounts from 1,039 breached websites.
Step 1: check your address
- Go to haveibeenpwned.com in your browser.
- Type your email address into the search box and press Check.
- Read the result: either a message that it was not found in any breach, or a list of the sites it leaked from, with the date of each breach and the kinds of data exposed.
Step 2: sign up for alerts
- Open the Notify Me page from the menu.
- Enter your address, then click the verification link sent to your inbox.
- From then on you get an email whenever your address appears in a new breach.
According to the site’s FAQ, all it keeps for an alert subscription is the address, the date you subscribed and a random verification token.
Step 3: check the password itself
The Passwords page tells you whether a password has appeared in earlier leaks. The site says the password is never sent whole: it is turned into a SHA-1 hash on your own device, only the first five characters of that hash are sent, and the final comparison happens on your side.
If your address shows up
- A hit does not mean your mailbox itself was hacked; it means a site you used exposed its data.
- Change the password on that site straight away, and on every other account where you reused it.
- Any password that turns up in the Passwords check should never be used again, as the site advises.
- Turn on two-step verification for important accounts, so a password alone is not enough to get in.
Photo: A laptop on a desk. By Kari Shea, CC0, via Wikimedia Commons.
Source: Have I Been Pwned pages (home, Notify Me, Passwords and FAQ), checked on 6 October 2026.
Kuwait One, once a week.
The most useful stories we published this week, in your inbox.
No spam. Unsubscribe anytime.
