Yes, Have I Been Pwned is an established, trustworthy service for checking whether an email address appears in known breaches. Its results remain partial: an address that does not appear is not necessarily protected, and phone-number searches are more limited.
When a breach affects you, change the affected account's password and any reused passwords, enable 2FA and watch for phishing. To check breaches, the public web and data brokers together, run a free scan, then remove what you choose.
Here is what HIBP does, how to use it without overestimating its coverage, and a practical action plan. For a shorter guide, see how to check for leaked data in three minutes.
Is Have I Been Pwned trustworthy?
Have I Been Pwned was created by security expert Troy Hunt. It brings together documented breach datasets and lets you check whether your email appears in them. Its list of recorded compromised services explains the coverage.
The service is reliable within that scope: it confirms that an identifier appears in a breach known to its database. It does not prove that someone currently controls your account and does not cover every breach. Basic email checking is free. Paid options exist for notifications and certain professional uses.
HIBP does not hack services or retrieve passwords from websites. It matches your email against data already exposed elsewhere. It is an awareness and after-the-event detection tool, not an absolute guarantee.
What does “pwned” mean?
“Pwned” comes from gaming and computer-security jargon. In HIBP, it means that your email or another identifier appears in a recorded breach. It does not necessarily mean that someone still controls your account. You should nevertheless check the affected service and replace reused passwords.
Is Have I Been Pwned available in French?
The official Have I Been Pwned website is mainly in English. The search is straightforward: enter your email to see associated breaches and exposed data categories. This guide explains the terms and the steps relevant to users in France.
How to check whether your email has been pwned
Enter your email on the official haveibeenpwned.com website. The service tells you:
- Whether the address appears in one or more known breaches in its database.
- Usually, the service or breach name, such as a compromised forum, social network or online game.
For passwords, the site uses mechanisms such as hash-based k-anonymity to check whether a password has appeared in breaches without sending the plain-text password to the server. The purpose is to tell you that a password has been exposed somewhere and should not be reused. For an individual, the free email check is often a useful starting point; paid options mainly concern alerts.
Can you check a phone number?
The homepage primarily presents email search. Some recorded breaches also contain phone numbers, and the HIBP privacy policy explains how number searches are handled without associating them with an email address. Coverage depends on the data in each breach. A negative result therefore does not prove that your number has never circulated.
What Have I Been Pwned cannot tell you
Avoid false reassurance or unnecessary alarm:
- Not every breach is listed. Some are never published, some arrive later and others circulate privately. No result does not mean zero risk.
- An old breach can still be dangerous if you reused the same password elsewhere. Attackers automate checks across other websites, a technique called credential stuffing.
- Phone numbers can leak through resellers, scams or telecom breaches, which are not always visible in the same datasets as email addresses.
A broader digital footprint scan combines breach checks with visibility on the web and with brokers. Our free scan includes a breach layer to help prioritise actions alongside public databases.
What should you do after a data breach?
Follow this sequence when you learn that an account or breach affects you, whether through HIBP, an official email, the press or your employer.
1. Confirm the source
Scammers exploit breach announcements. Before clicking:
- Use the service's official website, typed manually or opened from a bookmark, rather than a suspicious email link.
- Check whether it has published a statement or incident page.
2. Change the affected password
- Choose a long, unique password generated by your password manager. See our five-minute password guide.
- If you used the same password elsewhere, change it everywhere, prioritising sensitive accounts such as email, banking, health, cloud and administration.
3. Enable two-factor authentication
2FA, using an authenticator app or security key, greatly reduces risk even if a password leaks. Prioritise:
- Your email inbox, which is central to account recovery.
- Your Apple or Google account.
- Social networks and storage services.
Our seven-day response plan covers passwords, 2FA and habits in more detail.
4. Revoke unfamiliar sessions and devices
Where the service allows it, sign out active sessions, check sign-in history and report unfamiliar activity.
5. Watch for misuse
- Phishing: emails or texts urgently asking you to sign in again.
- Fraud: attempted account openings, transfers or changes to bank details. Report these to your bank and, where appropriate in France, the police, gendarmerie or cybermalveillance.gouv.fr.
6. Reduce exposure beyond the account
A breach can expose more than a login and password. Your email and phone number may also be held by data brokers or appear on public people search sites. You may be able to request removal or object under the GDPR and Article 17.
Follow the seven-day plan, and stay alert for spam and text scams after a breach. Our removal process, digital footprint guide and explanation of the scan's three sources cover this wider exposure.
Phishing after a breach: useful habits
Attackers know people change passwords after a breach announcement. They send fake emails impersonating services such as Netflix, La Poste or your bank.
- Never give your password by email or to unsolicited callers claiming to be support.
- Reset passwords through the official website or app.
- Treat pressure such as “your account will be suspended in one hour” as a warning sign.
Breach notifications and your rights in Europe
When an organisation processes personal data under the GDPR and a breach poses a risk to your rights, it may have to inform you and notify the authority. In France, the relevant authority is the CNIL. This legal framework complements the practical security steps above.
Quick checklist
- Check the source, using the official website.
- Set unique passwords for the affected account and any account reusing the old one.
- Enable 2FA on email, cloud, banking and social accounts.
- Check sessions and sign-in alerts.
- Watch for phishing and scams over the following weeks.
- Check your wider footprint: run a free scan.
See also: Check for leaked data · Leaked password: five-minute response · Seven-day breach response plan · Spam and scams after a breach



