Free tool

Has your password leaked? Let’s check.

Put your password in the box below.

Password checker

Your password Type your password to check it Stop there

Good instinct, wrong move.

You were about to type your password into a website because a page asked you to. That is how phishing works: a page that looks helpful, a box that looks official, and a password that ends up somewhere you cannot see.

This box was never a box. Nothing could be typed into it and nothing was sent anywhere. But you had no way of knowing that, and neither does anybody else who asks you for a password.

The rule: only ever type a password into the one site it belongs to.

How to check a password safely

  • Your password manager. Most have a breach check built in. NordPass, the password manager we supply to our clients, checks your saved passwords against known breaches without them ever leaving your device.
  • Your browser. Google Chrome and Microsoft Edge warn you when a password you have saved in them turns up in a breach. On an iPhone or a Mac, the Passwords app does the same.
  • Check your email address, not your password. Have I Been Pwned tells you which breaches your address has turned up in, which tells you which passwords to change. NordPass, which we supply, also does this for you, and lets you know when a work email address turns up in a new breach.

If it has leaked

Change it on that site. Change it everywhere else you used the same one, because the first thing an attacker does with a leaked password is try it on your email. Then turn on multi factor authentication, which stops a leaked password being enough on its own.

Questions

The things people ask next

Is it ever safe to type a password into a checker website?

Not your real one, and not somewhere you cannot verify. Some checkers only send a scrambled fragment of the password rather than the password itself, which is safe in principle, but from the outside you cannot tell a careful site from a harvesting one. The breach checks built into password managers and browsers do the same job without the question coming up.

Why is a reused password such a problem?

Because a breach at one site becomes a key to every site where you used the same password. Attackers take leaked lists and try each email and password pair against email, banking and Microsoft 365 logins automatically. A password manager fixes this by making a different password for every site, so one leak stays one leak.

How do we stop staff reusing passwords at work?

Give them a password manager and turn on multi factor authentication everywhere. Asking people to remember dozens of unique passwords does not work, so they reuse them. A business password manager is included in our Secure level, and switching on multi factor authentication is free.

Next step

Worried about passwords at work?

Tell us how many people you have and how they log in now. We will tell you where the reused passwords are likely to be and what it takes to fix them.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.