All tests and tools Self-check

Is your password on the attackers' lists?

Hundreds of millions of passwords from real data breaches circulate online. Attackers automatically try them on every service. Here you can see whether yours is among them. Your password never leaves this browser.

How your password stays secret

  1. Your browser calculates a fingerprint of the password, the SHA-1 hash.
  2. Only the first five of 40 characters are sent to the server. Hundreds of passwords share this beginning.
  3. The list of all these passwords comes back. Only your browser checks whether yours is among them.

The method is called k-anonymity. The data comes from "Pwned Passwords" by Have I Been Pwned. Nothing is stored.

A password alone is no longer enough

Most break-ins into company accounts start with a stolen or guessed password. In my training, your team learns to spot password phishing and sets up password managers and two-factor authentication.

Training for your team → More tools

This check is also available as an open API and as an MCP tool. There, only the SHA-1 hash is accepted, never the password.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first