Is your password already in circulation?
Check it in 10 seconds, without signing up and without your password leaving your device. Below you can see which breaches went public most recently.
No login, no storage, no newsletter
Check a password against known breaches
Your password is hashed inside your own browser. Only the first five characters of that hash are queried, and they match hundreds of thousands of other passwords. Neither we nor the data service learns which password you checked.
How it works: the hash is computed locally in your browser and only its first five characters are sent. The remaining characters are compared on your device. We run no server for this, log nothing and store nothing. Data source for the password check: Pwned Passwords.
A hit is not a result. A plan is.
- Replace the password everywhere you used it, not just at the affected service.
- Turn on multi-factor authentication, starting with email, banking and company accounts.
- End active sessions and signed-in devices, because stolen sessions bypass multi-factor authentication.
- Introduce a password manager so every account gets its own password.
- In the company: check which company accounts are affected and document the case.
The most recently disclosed breaches
This overview updates automatically from the public Have I Been Pwned corpus. It shows how routinely credentials leak from services your people use privately.
accounts recorded across all known breaches combined.
documented breaches in the public corpus.
of them were added in the last twelve months alone.
of the breaches also exposed passwords.
Oz Hair and Beauty
ozhairandbeauty.com
- Accounts affected
- 2 M
- Date of breach
- 15 August 2026
Data exposed
Fanlore
fanlore.org
- Accounts affected
- 144,520
- Date of breach
- 6 August 2026
Data exposed
RingCentral
ringcentral.com
- Accounts affected
- 1.6 M
- Date of breach
- 27 July 2026
Data exposed
Alcon
alcon.com
- Accounts affected
- 218,395
- Date of breach
- 1 August 2026
Data exposed
Brinks Home
brinkshome.com
- Accounts affected
- 732,162
- Date of breach
- 13 July 2026
Data exposed
Inter-Con Security
icsecurity.com
- Accounts affected
- 276,114
- Date of breach
- 18 June 2026
Data exposed
Data source: Have I Been Pwned, licensed under CC BY 4.0. Presentation and assessment by CAVRIX.
One password is a start. Your domain is the real question.
How many addresses on your company domain sit in breach corpora and infostealer logs, how old are the findings and which of them are still dangerous today? We check that for you and deliver the measures with it.
We deliberately do not offer domain checks as self-service on the web. Querying other people's addresses unasked would not be clean under data protection law. We confirm up front that the domain is yours.
Questions about the breach check
Is it safe to type my password here?
Yes, because the password never leaves the field. Your browser computes a hash locally and queries only its first five characters. What comes back is a block of hundreds of thousands of possible matches, compared on your device. Neither CAVRIX nor the data service can derive your password from that.
Why can I not check an email address here?
Because we would then be processing personal data, often somebody else's. An open input field for email addresses invites exactly that. For company domains we run the check once it is confirmed that the domain belongs to you.
What exactly does “no hit” mean?
That this password does not appear in the recorded breaches. It can still be weak, guessable or from a breach nobody knows about yet. The check does not replace good password hygiene, it only covers the known part.
Do you store my input?
No. There is no form posting to our server, no logging and no handover to analytics tools. The query goes directly from your browser to the password service, deliberately without a detour through us.
Where does the data come from?
From Have I Been Pwned, the internationally established breach corpus run since 2013. The breach data is published under CC BY 4.0, which is why we credit the source visibly.
I got a hit. What is actually urgent now?
The email account first, because every other password can be reset through it. Then company accounts and banking. A new unique password and multi-factor authentication everywhere, and end active sessions.
Do not check one password. Check your company.
Free exposure analysis for your domains, clear result, no commitment.