Data breach check

Is your password already in circulation?

Check it in 10 seconds, without signing up and without your password leaving your device. Below you can see which breaches went public most recently.

No login, no storage, no newsletter

Check a password against known breaches

Your password is hashed inside your own browser. Only the first five characters of that hash are queried, and they match hundreds of thousands of other passwords. Neither we nor the data service learns which password you checked.

How it works: the hash is computed locally in your browser and only its first five characters are sent. The remaining characters are compared on your device. We run no server for this, log nothing and store nothing. Data source for the password check: Pwned Passwords.

And then?

A hit is not a result. A plan is.

  • Replace the password everywhere you used it, not just at the affected service.
  • Turn on multi-factor authentication, starting with email, banking and company accounts.
  • End active sessions and signed-in devices, because stolen sessions bypass multi-factor authentication.
  • Introduce a password manager so every account gets its own password.
  • In the company: check which company accounts are affected and document the case.
Live

The most recently disclosed breaches

This overview updates automatically from the public Have I Been Pwned corpus. It shows how routinely credentials leak from services your people use privately.

12.8 B

accounts recorded across all known breaches combined.

891

documented breaches in the public corpus.

117

of them were added in the last twelve months alone.

66 %

of the breaches also exposed passwords.

LimeLeads

LimeLeads

limeleads.com

Accounts affected
17.8 M
Date of breach
1 August 2019

Data exposed

Email addressesEmployersGeographic locationsJob titlesPhone numbers
Burger King Russia

Burger King Russia

burgerkingrus.ru

Accounts affected
3.2 M
Date of breach
25 August 2024

Data exposed

Dates of birthEmail addressesGendersGeographic locationsNamesPhone numbers
Chess.com (2026)

Chess.com (2026)

chess.com

Accounts affected
4.7 M
Date of breach
3 August 2026

Data exposed

Email addressesGeographic locationsNamesUsernames
Manchester Airports Group

Manchester Airports Group

magairports.com

Accounts affected
8.8 M
Date of breach
27 August 2026

Data exposed

Browser user agent detailsEmail addressesGeographic locationsIP addressesNamesPhone numbers
Questel

Questel

questel.com

Accounts affected
1.2 M
Date of breach
1 August 2026

Data exposed

Email addressesEmployersJob titlesNamesPhone numbersPhysical addresses
Carhartt

Carhartt

carhartt.com

Accounts affected
12.9 M
Date of breach
13 August 2026

Data exposed

Email addressesNamesPhone numbersPhysical addresses

Data source: Have I Been Pwned, licensed under CC BY 4.0. Presentation and assessment by CAVRIX.

For companies

One password is a start. Your domain is the real question.

How many addresses on your company domain sit in breach corpora and infostealer logs, how old are the findings and which of them are still dangerous today? We check that for you and deliver the measures with it.

We deliberately do not offer domain checks as self-service on the web. Querying other people's addresses unasked would not be clean under data protection law. We confirm up front that the domain is yours.

FAQ

Questions about the breach check

  • Is it safe to type my password here?

    Yes, because the password never leaves the field. Your browser computes a hash locally and queries only its first five characters. What comes back is a block of hundreds of thousands of possible matches, compared on your device. Neither CAVRIX nor the data service can derive your password from that.

  • Why can I not check an email address here?

    Because we would then be processing personal data, often somebody else's. An open input field for email addresses invites exactly that. For company domains we run the check once it is confirmed that the domain belongs to you.

  • What exactly does “no hit” mean?

    That this password does not appear in the recorded breaches. It can still be weak, guessable or from a breach nobody knows about yet. The check does not replace good password hygiene, it only covers the known part.

  • Do you store my input?

    No. There is no form posting to our server, no logging and no handover to analytics tools. The query goes directly from your browser to the password service, deliberately without a detour through us.

  • Where does the data come from?

    From Have I Been Pwned, the internationally established breach corpus run since 2013. The breach data is published under CC BY 4.0, which is why we credit the source visibly.

  • I got a hit. What is actually urgent now?

    The email account first, because every other password can be reset through it. Then company accounts and banking. A new unique password and multi-factor authentication everywhere, and end active sessions.

Do not check one password. Check your company.

Free exposure analysis for your domains, clear result, no commitment.