Data breach check

Is your password already in circulation?

Check it in 10 seconds, without signing up and without your password leaving your device. Below you can see which breaches went public most recently.

No login, no storage, no newsletter

Check a password against known breaches

Your password is hashed inside your own browser. Only the first five characters of that hash are queried, and they match hundreds of thousands of other passwords. Neither we nor the data service learns which password you checked.

How it works: the hash is computed locally in your browser and only its first five characters are sent. The remaining characters are compared on your device. We run no server for this, log nothing and store nothing. Data source for the password check: Pwned Passwords.

And then?

A hit is not a result. A plan is.

  • Replace the password everywhere you used it, not just at the affected service.
  • Turn on multi-factor authentication, starting with email, banking and company accounts.
  • End active sessions and signed-in devices, because stolen sessions bypass multi-factor authentication.
  • Introduce a password manager so every account gets its own password.
  • In the company: check which company accounts are affected and document the case.
Live

The most recently disclosed breaches

This overview updates automatically from the public Have I Been Pwned corpus. It shows how routinely credentials leak from services your people use privately.

12.7 B

accounts recorded across all known breaches combined.

884

documented breaches in the public corpus.

119

of them were added in the last twelve months alone.

66 %

of the breaches also exposed passwords.

Oz Hair and Beauty

Oz Hair and Beauty

ozhairandbeauty.com

Accounts affected
2 M
Date of breach
15 August 2026

Data exposed

Email addressesGeographic locationsNamesPhone numbersPurchases
Fanlore

Fanlore

fanlore.org

Accounts affected
144,520
Date of breach
6 August 2026

Data exposed

Email addressesNamesPasswordsUsernames
RingCentral

RingCentral

ringcentral.com

Accounts affected
1.6 M
Date of breach
27 July 2026

Data exposed

Email addressesNamesPhone numbersPhysical addresses
Alcon

Alcon

alcon.com

Accounts affected
218,395
Date of breach
1 August 2026

Data exposed

Email addressesNamesPhone numbersPhysical addresses
Brinks Home

Brinks Home

brinkshome.com

Accounts affected
732,162
Date of breach
13 July 2026

Data exposed

Dates of birthEmail addressesNamesPartial credit card dataPhone numbersPhysical addresses
Inter-Con Security

Inter-Con Security

icsecurity.com

Accounts affected
276,114
Date of breach
18 June 2026

Data exposed

Email addressesEmployersJob titlesNamesPhone numbersPhysical addresses

Data source: Have I Been Pwned, licensed under CC BY 4.0. Presentation and assessment by CAVRIX.

For companies

One password is a start. Your domain is the real question.

How many addresses on your company domain sit in breach corpora and infostealer logs, how old are the findings and which of them are still dangerous today? We check that for you and deliver the measures with it.

We deliberately do not offer domain checks as self-service on the web. Querying other people's addresses unasked would not be clean under data protection law. We confirm up front that the domain is yours.

FAQ

Questions about the breach check

  • Is it safe to type my password here?

    Yes, because the password never leaves the field. Your browser computes a hash locally and queries only its first five characters. What comes back is a block of hundreds of thousands of possible matches, compared on your device. Neither CAVRIX nor the data service can derive your password from that.

  • Why can I not check an email address here?

    Because we would then be processing personal data, often somebody else's. An open input field for email addresses invites exactly that. For company domains we run the check once it is confirmed that the domain belongs to you.

  • What exactly does “no hit” mean?

    That this password does not appear in the recorded breaches. It can still be weak, guessable or from a breach nobody knows about yet. The check does not replace good password hygiene, it only covers the known part.

  • Do you store my input?

    No. There is no form posting to our server, no logging and no handover to analytics tools. The query goes directly from your browser to the password service, deliberately without a detour through us.

  • Where does the data come from?

    From Have I Been Pwned, the internationally established breach corpus run since 2013. The breach data is published under CC BY 4.0, which is why we credit the source visibly.

  • I got a hit. What is actually urgent now?

    The email account first, because every other password can be reset through it. Then company accounts and banking. A new unique password and multi-factor authentication everywhere, and end active sessions.

Do not check one password. Check your company.

Free exposure analysis for your domains, clear result, no commitment.