Password Breach Checker Is this password already in attackers' lists?
Hashed in your browser: only the first 5 characters of its SHA-1 are sent. Nothing is stored.
Type a password, or paste its SHA-1 or NTLM hash. It is hashed in your browser and only the first 5 characters of the hash leave it; the match against over 2 billion breached passwords is made on your side.
curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant500 free requests/month · instant API key · no signup form
2B+
Breached passwords
5
Hash characters sent
SHA-1 · NTLM
Hash types
30 d
Corpus refresh
Key features. Everything you need to protect your infrastructure and users.
k-anonymity by design
The password is hashed where you type it. Only a 5-character prefix of its SHA-1 is sent; around 2,000 hashes share it, and the match is made on your side.
Over 2 billion breached passwords
Have I Been Pwned's Pwned Passwords corpus, held on our servers and refreshed monthly, so a check does not depend on a third party.
SHA-1 and NTLM
Paste an NTLM hash from an Active Directory audit or a credential dump and see whether the password behind it is known to attackers.
How often, not just whether
Each match carries the number of times the password was seen in breaches, from once to tens of millions.
REST API and SDK
POST /check/password with a hash, or the range endpoint for k-anonymity. The JavaScript SDK hashes locally for you.
For AI agents
The MCP tool check_password_exposure lets an agent check a password before it accepts, generates or stores one.
Use cases. How security teams use this tool.
Signup and password change
Refuse a breached password when a user sets it, as NIST SP 800-63B recommends. We do it on our own signup form.
Active Directory audits
Check the NTLM hashes extracted from a domain controller against breach data to find accounts whose password is already circulating.
Incident response
After a credential dump or an infostealer infection, see which recovered passwords attackers already have in their lists.
Agents that handle credentials
Give an AI agent a way to refuse a leaked password without ever sending the password itself.
Why breached passwords matter
Credential stuffing works because people reuse passwords. Attackers do not guess: they replay the billions of passwords already published in breach dumps against every login page they can reach. A password that appears in those lists is compromised whatever its length or complexity, which is why NIST SP 800-63B asks services to reject passwords found in breach corpuses.
Checking a password without revealing it
The check uses k-anonymity. Your browser hashes the password with SHA-1 and sends only the first five characters of the hash. Around 2,000 breached hashes share any given prefix; we return all of them with their counts, and the comparison with the rest of your hash happens in your browser. Neither the password nor its full hash is ever transmitted.
Auditing Active Directory with NTLM hashes
Windows stores passwords as NTLM hashes. An auditor who extracts them from a domain controller can check each hash against breach data without cracking anything: a match means the account's password is already in attackers' lists and must be changed first.
Password checks in your own code
POST /check/password takes a SHA-1 or NTLM hash and returns whether the password is exposed, how many times, and a prevalence level. For k-anonymity, GET /pwned-passwords/range/{prefix} returns the hashes under a prefix. The JavaScript SDK's checkPassword hashes locally, and the MCP tool check_password_exposure gives the same check to AI agents.
Frequently asked questions.
How does the password check work?
Do you see or store my password?
My password was not found. Is it safe?
Can I check NTLM hashes from Active Directory?
Is there an API?
Related articles. Learn more from our security research blog.
Ready to get started?
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key

