Password Breach Check: Safe Query Guide
A previously leaked password puts accounts at risk. This tool uses k-anonymity: only the first 5 hash characters leave the device, never the full password. On a match, change it everywhere immediately.
Step by step
- Type your password (max 128 characters).
- Press check; the hash is computed on-device.
- Await the verdict with match counts.
- Replace leaked passwords on all accounts.
- Store the new one in a manager.
Example scenario
A user tests a long-used password. The hash prefix goes to the server; 50,000 records match. The password is replaced everywhere, the new one stored in a manager.
Check your result
Confirm the valid-or-leaked verdict. On a leak, rotate everywhere it was used. Do not re-test the new password here.
Frequently asked questions
Is my password sent?
No, only the first 5 hash characters leave.
What does a match mean?
The password sits in known breach lists.
Over 128 characters?
Not accepted; try a shorter one.
Is the new password safe?
If unique and manager-stored, yes.
How often?
Yearly for important accounts suffices.
Open the tool: Password Breach Check →
Keep an original copy before processing your file. Examples are illustrative; results depend on your document.