Data breaches

Is Have I Been Pwned safe?

Short answer: yes. Below is what Have I Been Pwned does with your email address and your password, who runs it, and the one thing a clean result cannot tell you.

Last updated: 4 min readIndependent guidance, Australia-first

The short answer

Yes, Have I Been Pwned is safe to use. It is run by a named Australian business, Troy Hunt's Superlative Enterprises in Queensland, and its privacy policy says it does not store the email address you search for. There are two caveats. Its web server logs, kept for up to 31 days, can include what you typed and your IP address. And a clean result does not prove you were never breached: HIBP has permanently removed some breaches, including Ticketek's 17.6 million records.

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.

Australian & independentThird-party security assessmentSources cited

Key takeaways

  • HIBP has run since 2013 and is owned by Superlative Enterprises Pty Ltd, Troy Hunt's business in Queensland.
  • Searching an email address does not store it. Ordinary server logs are kept for up to 31 days.
  • Pwned Passwords never receives your password, only the first 5 characters of its SHA-1 hash.
  • Sensitive breaches only show after you prove you own the address.
  • Retired breaches, including Ticketek, no longer show at all, so 'not pwned' is not proof.
  • The only real site is haveibeenpwned.com. Lookalike sites are the actual risk.

Who runs it

Who runs Have I Been Pwned?

Have I Been Pwned is owned and operated by Superlative Enterprises Pty Ltd, a business based in Queensland, Australia. It was created by Troy Hunt, a Microsoft Regional Director and security researcher who has run the site since 2013 and writes publicly about how it works. Charlotte Hunt manages its day-to-day operations.

It is not an anonymous site and it is not a data broker. National computer emergency response teams get free access to monitor government domains, and password managers such as 1Password build its breach data into their own products.

Your data

What Have I Been Pwned does with what you type

What Have I Been Pwned keeps when you use each feature, according to its privacy policy
What you doWhat HIBP keeps
Search an email addressNot stored. The search reads the breach data and returns it. Server logs (up to 31 days) may include the form input and your IP address.
Check a password on Pwned PasswordsNever receives it. Your browser hashes the password and sends only the first 5 characters of the hash.
Sign up for Notify meYour verified email address, so it can tell you about future breaches.
Search a domain (after proving you control it)The domain name and your IP address, as an anti-abuse measure, plus your email address if you ask to be notified.

HIBP's own FAQ is blunt about the trust question: asked how you know it is not harvesting the email addresses people search, it answers “You don't, but it's not”, and adds that if you are worried about its intent, you should not use it. The privacy policy above is the written version of that promise.

The limit

What a clean result cannot tell you

The safety question has a second half: is a “Good news - no pwnage found!” result safe to rely on? Not on its own, for three reasons.

  • It only knows about breaches it has loaded. A breach that was never made public, or not added yet, will not show.
  • Sensitive breaches are hidden from a plain search. They only appear after you sign in and verify you own the address.
  • Some breaches are retired. HIBP permanently removes a breach in rare cases, for example when the data no longer seems to be traded. Ticketek's 2024 breach of 17.6 million records is one of them, so a Ticketek customer can get a clean result for a breach that did happen.

The real risk is a lookalike site

Because HIBP is well known, scam emails and copycat domains copy it. Type haveibeenpwned.com yourself rather than following a link, and never enter a password into a site that asks for it alongside your email address.

For a second opinion from a different breach database, see our Have I Been Pwned alternatives. For what to do with a result, see the full Have I Been Pwned guide.

Go past the breach list

In The Event Of checks your email against known breaches and maps the accounts that use it, so you can see which ones to secure or close. The Free tier is A$0 and does not need a credit card.

Check my exposure free

FAQ

Frequently asked questions

Is haveibeenpwned.com legit?
Yes. Have I Been Pwned has run since 2013 and is owned and operated by Superlative Enterprises Pty Ltd, Troy Hunt's business in Queensland, Australia. Troy Hunt is a named, public security researcher, and national computer emergency response teams and password managers use HIBP's data. The only real copy lives at haveibeenpwned.com, so check the address before you type anything.
Is it safe to enter my email on Have I Been Pwned?
Yes. HIBP's privacy policy says it does not collect or store your personal information when you search: the search only reads its breach data and returns the result. The one caveat is ordinary web server logs, which it keeps for up to 31 days and which can include what was typed into a form and your IP address.
Is it safe to enter my password on Pwned Passwords?
Yes, because your password never leaves your device. The page hashes it locally with SHA-1 and sends only the first 5 characters of the hash. HIBP returns every breached hash that starts with those 5 characters, and the match is made in your browser. Even so, never type a password into a lookalike site, only haveibeenpwned.com.
Does Have I Been Pwned sell or share my email address?
No. Its privacy policy says it does not use third-party cookies or tracking pixels, does not serve ads, and passes subscriber and domain-search details to no third party except SendGrid, which sends its emails. It keeps an email address long-term only if you verify it for Notify me. A plain search is not stored as a record of you, but its web server logs, kept for up to 31 days, can include what you typed and your IP address.
If Have I Been Pwned says I'm not pwned, am I safe?
Not necessarily. HIBP only knows about breaches that were found and loaded into it, it hides sensitive breaches until you verify you own the address, and it has permanently removed some breaches. One of those retired breaches is Ticketek, with 17.6 million records, so a clean result cannot show whether you were in it.
Who owns Have I Been Pwned?
Superlative Enterprises Pty Ltd (ABN 62 085 442 020), based in Queensland, Australia. Troy Hunt created the service and runs it, and Charlotte Hunt manages its day-to-day operations.

Disclaimer: Have I Been Pwned's practices are summarised from its own privacy policy, FAQs and API, which were checked on 10 October 2026 and may change. In The Event Of is not affiliated with Have I Been Pwned. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.