Data breaches
Is Have I Been Pwned safe?
Short answer: yes. Below is what Have I Been Pwned does with your email address and your password, who runs it, and the one thing a clean result cannot tell you.
The short answer
In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.
Key takeaways
- HIBP has run since 2013 and is owned by Superlative Enterprises Pty Ltd, Troy Hunt's business in Queensland.
- Searching an email address does not store it. Ordinary server logs are kept for up to 31 days.
- Pwned Passwords never receives your password, only the first 5 characters of its SHA-1 hash.
- Sensitive breaches only show after you prove you own the address.
- Retired breaches, including Ticketek, no longer show at all, so 'not pwned' is not proof.
- The only real site is haveibeenpwned.com. Lookalike sites are the actual risk.
Who runs it
Who runs Have I Been Pwned?
Have I Been Pwned is owned and operated by Superlative Enterprises Pty Ltd, a business based in Queensland, Australia. It was created by Troy Hunt, a Microsoft Regional Director and security researcher who has run the site since 2013 and writes publicly about how it works. Charlotte Hunt manages its day-to-day operations.
It is not an anonymous site and it is not a data broker. National computer emergency response teams get free access to monitor government domains, and password managers such as 1Password build its breach data into their own products.
Your data
What Have I Been Pwned does with what you type
| What you do | What HIBP keeps |
|---|---|
| Search an email address | Not stored. The search reads the breach data and returns it. Server logs (up to 31 days) may include the form input and your IP address. |
| Check a password on Pwned Passwords | Never receives it. Your browser hashes the password and sends only the first 5 characters of the hash. |
| Sign up for Notify me | Your verified email address, so it can tell you about future breaches. |
| Search a domain (after proving you control it) | The domain name and your IP address, as an anti-abuse measure, plus your email address if you ask to be notified. |
HIBP's own FAQ is blunt about the trust question: asked how you know it is not harvesting the email addresses people search, it answers “You don't, but it's not”, and adds that if you are worried about its intent, you should not use it. The privacy policy above is the written version of that promise.
The limit
What a clean result cannot tell you
The safety question has a second half: is a “Good news - no pwnage found!” result safe to rely on? Not on its own, for three reasons.
- It only knows about breaches it has loaded. A breach that was never made public, or not added yet, will not show.
- Sensitive breaches are hidden from a plain search. They only appear after you sign in and verify you own the address.
- Some breaches are retired. HIBP permanently removes a breach in rare cases, for example when the data no longer seems to be traded. Ticketek's 2024 breach of 17.6 million records is one of them, so a Ticketek customer can get a clean result for a breach that did happen.
The real risk is a lookalike site
For a second opinion from a different breach database, see our Have I Been Pwned alternatives. For what to do with a result, see the full Have I Been Pwned guide.
Go past the breach list
In The Event Of checks your email against known breaches and maps the accounts that use it, so you can see which ones to secure or close. The Free tier is A$0 and does not need a credit card.
FAQ
Frequently asked questions
Is haveibeenpwned.com legit?
Is it safe to enter my email on Have I Been Pwned?
Is it safe to enter my password on Pwned Passwords?
Does Have I Been Pwned sell or share my email address?
If Have I Been Pwned says I'm not pwned, am I safe?
Who owns Have I Been Pwned?
Sources
Where this information comes from
Related guides
Email in a data breach
Data breaches
Best footprint tools (AU)
Tools & comparisons
Find accounts linked to your email
Digital footprint
HIBP alternatives
Tools & comparisons
Sites like Have I Been Pwned
Tools & comparisons
Digital footprint check
Digital footprint
Data breach check
Data breaches
Incogni vs DeleteMe (AU)
Tools & comparisons
MyFitnessPal breach timeline
Data breaches
Find accounts linked to your phone
Digital footprint
Have I Been Pwned explained
Data breaches
Delete old accounts
Digital footprint
Remove personal info (AU)
Digital footprint
Digital footprint checklist
Digital footprint
Password manager vs breach monitor
Tools & comparisons
Secure your email after a breach
Account security
What data companies store
Digital footprint
Moving house address checklist
Life admin
Disclaimer: Have I Been Pwned's practices are summarised from its own privacy policy, FAQs and API, which were checked on 10 October 2026 and may change. In The Event Of is not affiliated with Have I Been Pwned. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.