Data breaches
Have I Been Pwned: is it safe, legit, and what do you do next?
Have I Been Pwned tells you whether your email address has appeared in a known data breach. What it does not do is tell you what to do about it, which other accounts share that email, or how Australian rules apply to you.
The short answer
In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.
Key takeaways
- HIBP has been running since 2013 and was created by Troy Hunt, a security researcher based on the Gold Coast, Queensland.
- Checking an email address is free, and the Pwned Passwords tool uses k-anonymity so your actual password is never sent or logged.
- Being 'pwned' means your details were exposed in a breach, not that your account is currently hacked.
- HIBP is a detection tool: it will not tell you what to do next or map the other accounts tied to your email.
- The public website no longer supports phone number search, which was removed after the 2021 Facebook leak.
The short answer
Is Have I Been Pwned safe and legit?
Yes. Have I Been Pwned has been running since 2013 and is one of the most widely trusted breach-checking tools in the world. It was created by Troy Hunt, a Microsoft Regional Director and security researcher based on the Gold Coast, Queensland, so despite the “.com” address, it is genuinely Australian-built.
A few reasons security professionals and government bodies trust it:
- It is free. You have never needed to pay or hand over a credit card to check an email address.
- It does not store your searched password. If you use the Pwned Passwords tool, HIBP checks it using a privacy-preserving method (k-anonymity) so your actual password is never sent or logged.
- Government agencies use it. HIBP gives national computer emergency response teams free domain-level access, and all Australian government domains are monitored through it by the Australian Cyber Security Centre, as are all UK government domains by the National Cyber Security Centre.
- It is built into products you already trust. 1Password and other password managers integrate HIBP directly to warn users about breached credentials.
- Troy Hunt is a known, named individual who speaks publicly, writes openly about how the service works, and has testified before US Congress on data breach issues. This is not an anonymous or shady operation.
Watch for lookalike sites
Definition
What does “pwned” actually mean?
“Pwned” (pronounced “poned” or “owned”) is internet slang for being compromised or beaten, originally from gaming culture, where being “owned” meant being defeated. In a security context, being “pwned” means your account details, usually an email address, and sometimes a password, phone number or other personal data, were exposed in a data breach and are now sitting in a dataset that security researchers or criminals can access.
Being pwned does not mean your account is currently hacked. It means your information was caught up in a breach at some point, which raises your risk if you have not taken action since.
How to
How to use Have I Been Pwned (2 minutes)
- Go to haveibeenpwned.com. Type your email address into the search bar on the homepage.
- Hit “pwned?” The site checks your address against its database of loaded breaches.
- Read the result.A green “Good news” message means no breaches were found for that address. A red result lists every breach your email appeared in, with the breach name, date, and what data was exposed.
- Click into each breach to see exactly what kind of data was leaked, whether email only, or passwords, names, phone numbers and more.
- Optional: sign up for notifications. HIBP lets you register your email so it alerts you automatically if you appear in a future breach.
That is the whole process, genuinely quick, and worth doing for every email address you use regularly.
Reading it
What the results mean
If you get a “pwned” result, do not panic. A huge number of Australians show up in at least one breach, often from services they signed up to years ago and forgot about. What matters is the detail:
- Email address only: low urgency. Your email being on a list is common and mostly increases spam and phishing risk.
- Password included: higher urgency. Change that password immediately, especially if you have reused it anywhere else.
- Financial details, ID numbers or security questions included: highest urgency. This is where identity theft risk increases and Australia-specific steps (like a credit ban) become relevant.
The breach date also matters. A breach from 2016 you have already dealt with is less pressing than one from last month. You can browse notable Australian breaches to see what was exposed in the incidents most likely to affect you.
The limits
What Have I Been Pwned can't tell you
This is the important part. HIBP is an excellent detection tool, but it was never designed to be a response service. Specifically, it cannot:
- Tell you what to do next. HIBP shows you the breach; it does not walk you through changing passwords, freezing credit or reporting the incident.
- Map other accounts tied to your email. If your email is your login for banking, shopping, government and social accounts, HIBP will not show you that web of exposure, only that the address appeared in a specific breach dataset.
- Give you Australia-specific guidance.HIBP is a global tool. It will not mention IDCARE, Australian credit bans through Equifax or Experian, or your rights under the Privacy Act 1988 and the OAIC's Notifiable Data Breaches scheme.
- Search by phone number on the website anymore. HIBP briefly supported phone number searches after the 2021 Facebook leak, but that option has since been removed from the public website (it is now email-only). See the section below for how to check a phone number today.
- Monitor you continuously in one dashboard. You would need to manually re-check or wait for an email alert, and there is no ongoing view of your exposure across accounts.
Check my exposure, free
This is exactly the gap In The Event Of is built to close. We check your email against known breaches and map the accounts linked to it, so you can see your actual exposure in one place, not just a single breach list. No credit card required.
Phone numbers
Checking a phone number
If you want to check whether a phone number has been exposed, the HIBP website itself no longer supports it. That feature was pulled after the initial Facebook phone number leak. A small number of older breaches still hold phone data searchable via HIBP's API for developers, but there is no general public phone-number lookup on the site anymore.
The more useful move for a phone number is behaviour-based: watch for unexpected SMS one-time codes, unfamiliar sign-in prompts, or spam calls referencing services you use, and report suspicious activity to Scamwatch if you spot it. If your phone number turns up linked to an email address you have already found in a breach, treat it with the same urgency as a password exposure. Our guide on finding accounts linked to your phone number covers the rest.
Next steps
Your 6-step response plan after a pwned result
Once HIBP (or our free check) tells you which breach you are in, here is what actually reduces your risk:
- Change the password for that specific account (10 minutes), and any other account where you reused it.
- Turn on multi-factor authentication wherever it is offered (15 minutes), especially email, banking and superannuation logins.
- Check what data was exposed in the breach detail. Passwords and financial data need faster action than an email-only leak.
- Watch for follow-on phishing. Breached emails often trigger a wave of scam messages referencing the leaked service. Do not click links in unexpected emails.
- Consider a credit ban if identity documents, Medicare details or financial information were exposed. This is free through both Equifax Australia and Experian Australia.
- Report and get help if it is serious. Contact IDCARE on 1800 595 160 for free, Australia-specific identity support, or report the breach to the OAIC if a company mishandled your data.
For the full walkthrough, see our guide on what to do if your email is in a data breach, and how to secure your email after a data breach if the exposed account is your inbox itself.
Scope
Finding every account linked to your email
The other blind spot HIBP has is scope: a single breach check only tells you about that breach. It does not show you the dozens of other services, such as old shopping accounts, forgotten subscriptions and loyalty programs, still sitting under your email address, each one a potential weak point. Our guide on how to find accounts linked to your email covers manual ways to do this, and the digital footprint checklist gives you a running order once you know what is out there.
Using In The Event Of
How In The Event Of helps
In The Event Of picks up where a breach lookup stops. It runs a free email check against known breaches and maps the accounts linked to that email, so you see your actual exposure in one place rather than a single breach list. From there it organises what it finds into a digital footprint, highlights where the risk is concentrated, and gives you guided, Australia-specific next steps for each account. You stay in control of every change.
FAQ
Frequently asked questions
Is Have I Been Pwned actually free?
Is Have I Been Pwned owned by a company trying to sell me something?
What does it mean if I am not 'pwned'?
Can I check someone else's email on Have I Been Pwned?
Why doesn't Have I Been Pwned tell me what to do after a breach?
Does Have I Been Pwned still let you search by phone number?
Related guides
Email in a data breach
Data breaches
Best footprint tools (AU)
Tools & comparisons
Find accounts linked to your email
Digital footprint
Incogni vs DeleteMe (AU)
Tools & comparisons
MyFitnessPal breach timeline
Data breaches
Find accounts linked to your phone
Digital footprint
Delete old accounts
Digital footprint
Remove personal info (AU)
Digital footprint
Digital footprint checklist
Digital footprint
Password manager vs breach monitor
Tools & comparisons
Secure your email after a breach
Account security
What data companies store
Digital footprint
Moving house address checklist
Life admin
Disclaimer: Details about Have I Been Pwned are summarised from its official documentation and support pages and may change. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.