Data breaches

Have I Been Pwned: is it safe, legit, and what do you do next?

Have I Been Pwned tells you whether your email address has appeared in a known data breach. What it does not do is tell you what to do about it, which other accounts share that email, or how Australian rules apply to you.

Last updated: 31 May 2026Independent guidance, Australia-first

The short answer

Have I Been Pwned (HIBP) is safe and legitimate. It is a free tool built by Australian security researcher Troy Hunt that checks whether your email address has appeared in a known data breach. Government agencies and companies like 1Password rely on it. “Pwned” simply means your details showed up in a breach that has been made public. What HIBP will not do is tell you what to do next, which other accounts share that email, or how Australian rules like the Privacy Act apply to you, and that is the gap this guide fills.

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.

Australian & independentThird-party security assessmentSources cited

Key takeaways

  • HIBP has been running since 2013 and was created by Troy Hunt, a security researcher based on the Gold Coast, Queensland.
  • Checking an email address is free, and the Pwned Passwords tool uses k-anonymity so your actual password is never sent or logged.
  • Being 'pwned' means your details were exposed in a breach, not that your account is currently hacked.
  • HIBP is a detection tool: it will not tell you what to do next or map the other accounts tied to your email.
  • The public website no longer supports phone number search, which was removed after the 2021 Facebook leak.

The short answer

Is Have I Been Pwned safe and legit?

Yes. Have I Been Pwned has been running since 2013 and is one of the most widely trusted breach-checking tools in the world. It was created by Troy Hunt, a Microsoft Regional Director and security researcher based on the Gold Coast, Queensland, so despite the “.com” address, it is genuinely Australian-built.

A few reasons security professionals and government bodies trust it:

  • It is free. You have never needed to pay or hand over a credit card to check an email address.
  • It does not store your searched password. If you use the Pwned Passwords tool, HIBP checks it using a privacy-preserving method (k-anonymity) so your actual password is never sent or logged.
  • Government agencies use it. HIBP gives national computer emergency response teams free domain-level access, and all Australian government domains are monitored through it by the Australian Cyber Security Centre, as are all UK government domains by the National Cyber Security Centre.
  • It is built into products you already trust. 1Password and other password managers integrate HIBP directly to warn users about breached credentials.
  • Troy Hunt is a known, named individual who speaks publicly, writes openly about how the service works, and has testified before US Congress on data breach issues. This is not an anonymous or shady operation.

Watch for lookalike sites

Because it is well known, there are copycat sites and scam emails that impersonate HIBP to phish people. The real service only lives at haveibeenpwned.com. Be wary of lookalike domains, and never enter your password anywhere other than a site you navigated to directly.

Definition

What does “pwned” actually mean?

“Pwned” (pronounced “poned” or “owned”) is internet slang for being compromised or beaten, originally from gaming culture, where being “owned” meant being defeated. In a security context, being “pwned” means your account details, usually an email address, and sometimes a password, phone number or other personal data, were exposed in a data breach and are now sitting in a dataset that security researchers or criminals can access.

Being pwned does not mean your account is currently hacked. It means your information was caught up in a breach at some point, which raises your risk if you have not taken action since.

How to

How to use Have I Been Pwned (2 minutes)

  1. Go to haveibeenpwned.com. Type your email address into the search bar on the homepage.
  2. Hit “pwned?” The site checks your address against its database of loaded breaches.
  3. Read the result.A green “Good news” message means no breaches were found for that address. A red result lists every breach your email appeared in, with the breach name, date, and what data was exposed.
  4. Click into each breach to see exactly what kind of data was leaked, whether email only, or passwords, names, phone numbers and more.
  5. Optional: sign up for notifications. HIBP lets you register your email so it alerts you automatically if you appear in a future breach.

That is the whole process, genuinely quick, and worth doing for every email address you use regularly.

Reading it

What the results mean

If you get a “pwned” result, do not panic. A huge number of Australians show up in at least one breach, often from services they signed up to years ago and forgot about. What matters is the detail:

  • Email address only: low urgency. Your email being on a list is common and mostly increases spam and phishing risk.
  • Password included: higher urgency. Change that password immediately, especially if you have reused it anywhere else.
  • Financial details, ID numbers or security questions included: highest urgency. This is where identity theft risk increases and Australia-specific steps (like a credit ban) become relevant.

The breach date also matters. A breach from 2016 you have already dealt with is less pressing than one from last month. You can browse notable Australian breaches to see what was exposed in the incidents most likely to affect you.

The limits

What Have I Been Pwned can't tell you

This is the important part. HIBP is an excellent detection tool, but it was never designed to be a response service. Specifically, it cannot:

  • Tell you what to do next. HIBP shows you the breach; it does not walk you through changing passwords, freezing credit or reporting the incident.
  • Map other accounts tied to your email. If your email is your login for banking, shopping, government and social accounts, HIBP will not show you that web of exposure, only that the address appeared in a specific breach dataset.
  • Give you Australia-specific guidance.HIBP is a global tool. It will not mention IDCARE, Australian credit bans through Equifax or Experian, or your rights under the Privacy Act 1988 and the OAIC's Notifiable Data Breaches scheme.
  • Search by phone number on the website anymore. HIBP briefly supported phone number searches after the 2021 Facebook leak, but that option has since been removed from the public website (it is now email-only). See the section below for how to check a phone number today.
  • Monitor you continuously in one dashboard. You would need to manually re-check or wait for an email alert, and there is no ongoing view of your exposure across accounts.

Check my exposure, free

This is exactly the gap In The Event Of is built to close. We check your email against known breaches and map the accounts linked to it, so you can see your actual exposure in one place, not just a single breach list. No credit card required.

Check my exposure free

Phone numbers

Checking a phone number

If you want to check whether a phone number has been exposed, the HIBP website itself no longer supports it. That feature was pulled after the initial Facebook phone number leak. A small number of older breaches still hold phone data searchable via HIBP's API for developers, but there is no general public phone-number lookup on the site anymore.

The more useful move for a phone number is behaviour-based: watch for unexpected SMS one-time codes, unfamiliar sign-in prompts, or spam calls referencing services you use, and report suspicious activity to Scamwatch if you spot it. If your phone number turns up linked to an email address you have already found in a breach, treat it with the same urgency as a password exposure. Our guide on finding accounts linked to your phone number covers the rest.

Next steps

Your 6-step response plan after a pwned result

Once HIBP (or our free check) tells you which breach you are in, here is what actually reduces your risk:

  1. Change the password for that specific account (10 minutes), and any other account where you reused it.
  2. Turn on multi-factor authentication wherever it is offered (15 minutes), especially email, banking and superannuation logins.
  3. Check what data was exposed in the breach detail. Passwords and financial data need faster action than an email-only leak.
  4. Watch for follow-on phishing. Breached emails often trigger a wave of scam messages referencing the leaked service. Do not click links in unexpected emails.
  5. Consider a credit ban if identity documents, Medicare details or financial information were exposed. This is free through both Equifax Australia and Experian Australia.
  6. Report and get help if it is serious. Contact IDCARE on 1800 595 160 for free, Australia-specific identity support, or report the breach to the OAIC if a company mishandled your data.

For the full walkthrough, see our guide on what to do if your email is in a data breach, and how to secure your email after a data breach if the exposed account is your inbox itself.

Scope

Finding every account linked to your email

The other blind spot HIBP has is scope: a single breach check only tells you about that breach. It does not show you the dozens of other services, such as old shopping accounts, forgotten subscriptions and loyalty programs, still sitting under your email address, each one a potential weak point. Our guide on how to find accounts linked to your email covers manual ways to do this, and the digital footprint checklist gives you a running order once you know what is out there.

Using In The Event Of

How In The Event Of helps

In The Event Of picks up where a breach lookup stops. It runs a free email check against known breaches and maps the accounts linked to that email, so you see your actual exposure in one place rather than a single breach list. From there it organises what it finds into a digital footprint, highlights where the risk is concentrated, and gives you guided, Australia-specific next steps for each account. You stay in control of every change.

FAQ

Frequently asked questions

Is Have I Been Pwned actually free?
Yes. Checking an email address on haveibeenpwned.com has always been free, with no credit card or account required. Troy Hunt built it as a public resource. Some related developer features (like bulk API access for businesses) are paid, but the standard email check anyone would use to check themselves stays free.
Is Have I Been Pwned owned by a company trying to sell me something?
No. It is an independent project run by Troy Hunt, an Australian security researcher. It is not owned by a data broker or security vendor, though vendors like 1Password integrate its data into their own paid products.
What does it mean if I am not 'pwned'?
It means your email did not turn up in any of the breaches currently loaded into HIBP's database. It does not guarantee your data has never been exposed, because some breaches are never publicly discovered or loaded, so it is worth rechecking periodically.
Can I check someone else's email on Have I Been Pwned?
Technically yes, since it only requires typing in an address, but you should only check emails you own or have permission to check. HIBP does not verify ownership of the address you search.
Why doesn't Have I Been Pwned tell me what to do after a breach?
HIBP was built purely as a detection and awareness tool, not a response service. It intentionally stays narrow in scope. Acting on a breach, including changing passwords, freezing credit and reporting to IDCARE, is a separate step you need to take yourself, which is where a guided AU-specific process helps.
Does Have I Been Pwned still let you search by phone number?
Not on the public website. Phone number search was added briefly after the 2021 Facebook data leak, then removed from the standard site search, which now only accepts email addresses. A limited historical phone-number lookup remains available through HIBP's developer API only.

Disclaimer: Details about Have I Been Pwned are summarised from its official documentation and support pages and may change. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.