Passwords · Windows 10 and 11
Has this password been leaked?
Type a password and Octoolo tells you whether it appears in Have I Been Pwned's list of passwords exposed in data breaches, and how many times. It can be any password: one from your vault, a sticky note or your router's settings page. The password itself never leaves your computer: only a short piece of its fingerprint does.
How to check if a password was leaked
- 1
Open the leak check
Pick Password leak check, the last item under Passwords and accounts in Octoolo's Passwords app. It works without unlocking the vault.
- 2
Type or paste the password
Put it in Password to check. A strength meter rates it as you type, on your PC.
- 3
Press Check it
Octoolo sends the first five characters of the password's SHA-1 fingerprint to Have I Been Pwned and compares the answer itself. This step needs an internet connection.
- 4
Read the answer
Leaked N times means it is in the list: stop using it everywhere, and follow the steps further down this page. Not found in any known leak is good news, though a weak password is still weak.
How it checks without sending your password
Have I Been Pwned keeps a list of hundreds of millions of passwords that turned up in data breaches. Sending your password there to look it up would defeat the purpose, so Octoolo uses a method called k-anonymity:
- It turns the password into its SHA-1 fingerprint, 40 characters long. The fingerprint of “password” is 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8.
- It sends only the first five characters, 5BAA6 in that example, to api.pwnedpasswords.com.
- The service answers with every leaked fingerprint that starts the same way, usually hundreds of them, padded with dummy lines so even the size of the answer gives nothing away.
- Octoolo looks for the rest of your fingerprint in that answer, on your PC.
The service never learns the password, nor even its full fingerprint. Nothing you type is stored.
If your password was leaked
A count above zero means the password sits in the lists criminals try first, when they test leaked passwords against other sites. It does not mean your account was broken into, and it does not say which site leaked it. Still, treat it as burned:
- Change it everywhere you used it, starting with your email, since email resets everything else.
- Give each site its own password. The password generator or the vault's dice make one in a click.
- Turn on two-step sign-in where you can, with an authenticator app or the site's own method.
- Look over the account for changes you did not make, such as a new recovery email or phone number.
Do not read too much into the size of the number. A password seen once is as burned as one seen a million times: either way it sits on lists that are shared and tried.
What the result does not tell you
Not found in any known leak means just that. A short or predictable password can be guessed without ever having leaked, which is why the strength meter, built on the zxcvbn estimator, runs beside the check. The opposite happens too: a long, strong password can still leak if a site stored it carelessly. Aim for both: not found, and rated Strong.
The check is about passwords, not email addresses. To see which breaches your email address appeared in, search it on Have I Been Pwned's own website.
To check every password you keep instead of one at a time, open the password manager's Health tab and press Check for leaks. It marks each leaked entry with the number of times it was seen, and lists weak, reused and year-old passwords too.
Other ways to check, and how they differ
Have I Been Pwned's own website has a password search, and browsers check the passwords they save: Chrome's Password Checkup and Edge's Password Monitor warn you about leaked ones. Those are good habits, with limits. A browser checks only what it stores, and typing a password into a web page means trusting that page.
Octoolo's check works for any password you type, wherever you keep it, from a program on your own PC that follows the method described above. The password manager then covers everything in your vault in one go. Use whichever you will actually run: what matters is that leaked passwords get replaced.
Whichever you use, check again from time to time. New breaches are added to the list as they come to light, so a password that was clean last year can turn up today.
Questions, answered
Is it safe to type my real password here?
Yes, that is what the method is for: only five characters of its SHA-1 fingerprint leave your PC. The password is not saved anywhere, not even in a list of past checks.
What does Leaked 3,000 times mean?
The password turned up that many times across breached data. Common passwords show up millions of times; even once is reason enough to stop using it.
Does it say which site leaked my password?
No. The list holds passwords without the accounts or sites they came from.
Can it check my email address?
No, only passwords. Have I Been Pwned's website searches email addresses in known breaches.
Does it need the internet?
The check itself does, because the list lives at Have I Been Pwned. The strength meter works offline.
Why SHA-1, if SHA-1 is considered weak?
Here it only names the password in the list's own format; nothing depends on it being hard to break. The five characters sent are shared by hundreds of leaked passwords, which is what keeps yours anonymous.
Password leak check, and 16 more apps.
Download for Windows7 days free, then from $3.99 a month for all 17 apps. Windows 10 and 11.