PII Scanners
Dark Web Data Scanners Reviewed
Back to comparison
Service Review, No. 14 Ranked #14 of 20

Have I Been Pwned

The free, gold-standard breach checker maintained by security researcher Troy Hunt since 2013. Used by browsers, password managers, and governments worldwide. Indexes 859 breaches and 14.8 billion compromised accounts.

haveibeenpwned.com Troy Hunt · independent · 2013 Global
Composite Score
3.70/5
#14 of 20 ranked services, top free option
Service Type
Free ToolNo paid tier for consumers
Pricing
FreeDonations and API keys fund the project
Insurance Cap
NoneNo insurance, no restoration, no support
Best For
Email breach checkingIndustry-standard free tool
Visit HIBP Subscribe to alerts
§ 01

What it is

Have I Been Pwned (HIBP) was launched in 2013 by Australian security researcher Troy Hunt as a side project, originally just a way to centralize information about a few major breaches in one searchable database. Twelve years later it has become the most-trusted free tool in the category, indexing 859 breaches covering 14.8 billion accounts. Mozilla Monitor, 1Password, BitWarden, the FBI, the UK government, and dozens of password managers and browsers all rely on HIBP's underlying data through its API. The service is operated by one person with help from a small group of trusted contributors and verifiers.

For consumers, HIBP is the simplest possible interaction: type your email, see which breaches it appeared in, and (separately) check whether specific passwords have appeared in any breach. The "Notify Me" feature emails you when your address shows up in a new breach. There is no paid tier, no upsell, no insurance, no restoration support. HIBP's usefulness is intentionally bounded: it tells you exactly what happened and stops there. For a full picture of what to do next, you need to combine HIBP with other resources.

§ 02

What it monitors

Email breach lookup
Check any email address against 859 indexed breaches covering 14.8 billion accounts.
Pwned passwords
Check specific passwords against billions of known-compromised passwords (k-anonymity protected).
Domain monitoring
Free domain-wide monitoring for organizations to track all employee email exposure.
Real-time API
Public API powers password managers, browsers, and many other security tools.
Notify Me alerts
Email notifications when your address appears in a newly indexed breach.
Manual verification
Troy personally verifies major breaches before adding them, reducing false data.
Breach details
Each breach page shows what data was exposed (passwords, hashes, addresses, etc.).
Sensitive flagging
Breaches involving sensitive data (e.g., adult sites, medical) are flagged and verification-gated.
Public good ethos
Operated as a public service with full transparency and no commercial agenda.
§ 03

Pricing breakdown

There is no consumer paid tier. HIBP is entirely free for personal email lookups, password checks, and notify-me subscriptions. The only paid offerings are API access for developers (rate-limited tiers starting at $3.95/mo) and enterprise domain monitoring for companies.

Developer
API Access
$3.95/mo and up
  • For developers building security tools
  • Rate-limited API access
  • Multiple pricing tiers based on volume
  • Used by 1Password, BitWarden, Mozilla, etc.
  • Not aimed at consumers
§ 04

Pros and cons

What works

  • Completely free for personal use, no upsell, no ads, no tracking
  • Most-trusted free tool in the category, used by browsers, password managers, and governments
  • 14.8 billion compromised accounts indexed across 859 breaches
  • Troy Hunt personally verifies major breaches, reducing false-positive data
  • API is the back end for many other security products (Mozilla Monitor, etc.)
  • k-anonymity protocol means passwords are checked without ever being transmitted

What doesn't

  • No mobile app on iOS or Android, browser-only experience
  • No insurance, restoration, credit monitoring, or any premium features
  • Tells you what happened but does not help you remediate beyond information
  • No continuous monitoring beyond email-address-based notifications
  • Sensitive breaches (adult sites, etc.) require email verification to access
  • Trustpilot rating sits at 3.7 from a small 59-review sample
§ 05

What users actually say

Apple App Store
- - - - -
N/A
No iOS app
Google Play
- - - - -
N/A
No Android app
Trustpilot
★★★★☆
3.7
59 reviews

Positive sentiment. Security professionals overwhelmingly recommend HIBP as the first stop for any breach concern. The transparency, public-good ethos, and personal involvement of Troy Hunt build trust that paid services have to manufacture. Users praise the absence of upsell, the simplicity of the interface, and the seriousness with which Troy treats breach verification. Many reviews specifically thank Troy by name and characterize the service as essential public infrastructure.

Negative sentiment. The negative reviews are unusual: they often come from people who misunderstood what HIBP is for. Complaints about "no help when my identity was stolen" reflect a service-expectation mismatch, HIBP never claimed to provide that help. Some users want a mobile app that does not exist. The 3.7 Trustpilot rating from 59 reviews reflects a small and somewhat self-selected sample, security-aware users tend not to leave reviews on free tools.

§ 06

Who should buy this, and who shouldn't

Buy HIBP if

You want to check if your email or specific passwords have been exposed in known breaches, this is the fastest, most trusted way to find out. You want a one-time check or periodic notify-me alerts without paying anything. You are a security-aware user who would distrust commercial ID protection brands.

§ 07

Top alternatives

Bottom line

HIBP is the most important free tool in this category and arguably the most important free security service for individuals on the entire internet. The fact that it is run by one person as essentially a public service, with no paywall and no ulterior motive, is remarkable.

Use it. Whatever else you decide about long-term identity protection, run your email and your most-important passwords through HIBP today. If you find exposure, take action (rotate passwords, lock credit). HIBP is the first step.

Treat it as one tool among many. HIBP tells you what happened, not what to do about it. Pair it with a password manager, credit monitoring, and (optionally) a paid ID protection service if you want active monitoring and insurance.