What to do if your Password leaks - Check Have I Been Pwned(HIBP)

Have I Been Pwned is a free website created by security researcher Troy Hunt. It's a database of every email address and password that's ever been leaked in a data breach. You type your email and that tells you which breaches you're in. If you get results, this is what you need to do..

Step 1: Check the breach HIBP


Once you type your email in the site, you may see a list of breaches where your email appeared. Each entry includes:


Some breaches only exposed email addresses. Others exposed passwords, phone numbers, physical addresses, and even credit card data.

Step 2: Check Your Passwords


HIBP also has a password checker. Type in a password you use. It tells you how many times that password has appeared in leaked databases. If your password has been seen thousands of times, it's useless. Attackers add these to their wordlists.

Step 3: Change the Important Passwords First


Don't try to change every password in one sitting. Prioritize:

  1. Email — your email is the master key. If someone gets into your email, they can reset every other password.
  2. Banking and financial — obvious reasons.
  3. Cloud storage — Dropbox, Google Drive, iCloud. Private documents live there.
  4. Social media — attackers use compromised accounts to scam your friends.

Step 4: Enable Multi-Factor Authentication


MFA means you need a second code — usually from your phone — in addition to your password. Even if someone has your password, they can't log in without the second factor.

Most services support it:

Enable it on your email first. Then your bank. Then everything else. This single step does more to protect you than any password change.