Skip to content
Mounteyes
All guides

How to check if your password has been compromised

6 min readUpdated: Passwords

Billions of username and password pairs from old breaches are traded openly. If one of yours is in there, attackers are already trying it on your other accounts — and they do not need to guess.

The short version

  • Check by email address first — that tells you which services leaked.
  • A legitimate checker never needs your full password.
  • Change email and banking passwords first, then anything reused.
  • Being in a breach is not your fault; leaving the password in place is the risk.

What a breach actually leaks

When a company is breached, the stolen data usually includes email addresses and password hashes. Weak or old hashing means many of those passwords get recovered, and the resulting lists are traded, combined and replayed against other services for years afterwards.

That replay is the danger. Attackers do not need to guess your password on your bank if it already appeared in a breach from a shopping site where you used the same one. This is automated, cheap, and runs constantly.

Checking safely

Start with your email address at haveibeenpwned.com, a long-standing free service run by a security researcher. It tells you which breaches your address appears in, which is the useful part — it names the accounts to fix.

For a specific password, only use a checker that works on a partial hash of it, which is how Have I Been Pwned's password search is built: your password never leaves your device in full. Your browser's own password manager and most password managers run this check for you automatically.

Never type a real password into a random website that offers to check it. A form asking for your full password to "see if it is safe" is either careless or harvesting. Our own strength checker deliberately does not compare against breach lists for this reason — it analyses the password's structure locally instead, with no request leaving your browser.

What to do when something turns up

Change the password on the breached service, then on every other account where you reused it. Reuse is what turns one old breach into a current problem.

Prioritise: email first, because it resets everything else, then banking and payment accounts, then anything holding personal data. Use a new unique password each time rather than a variation of the old one — attackers try variations.

Turn on two-factor authentication on those accounts while you are there. It means the leaked password alone is no longer enough, which is the outcome you actually want.

Then sign out other sessions where the platform offers it, so anyone already logged in with the old password is removed.

If the breach included more than a password

Some breaches expose phone numbers, addresses, dates of birth or identity-document numbers, and none of those can be changed like a password. Expect targeted phishing that quotes real details back to you in order to sound legitimate — knowing your address proves nothing about who is calling. Treat unsolicited contact with more suspicion afterwards, not less, and never act on a phone call about money without independently calling the official number.

Staying ahead of the next one

There will be another breach, and it will not be your fault. What is in your control is that each password is unique, so a leak stays contained to one service, and that your important accounts have a second factor. A password manager plus 2FA turns a breach notification from an emergency into a five-minute task.

Nothing on this site will ever ask for your password, OTP or recovery codes.

Related guides

Want this handled for you?

Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.

Talk to Our Security Team