🔒 Local processing · No sign-up
passly.
Have I Been Pwned

Check if your password has been leaked

Find out if your password or email appeared in known data breaches, and see a detailed password strength analysis. The process is anonymous – your data never leaves the browser in plain form.

Passwords are checked against Have I Been Pwned, while email addresses are checked against the independent XposedOrNot database — two separate breach data sources.

🧠 This tool uses Have I Been Pwned. Your password is hashed locally (SHA-1), and only a prefix is sent to the API – your password is never revealed.

Why use Passly?

Security and anonymity

Your password is processed locally. No data ever leaves your device.

Up-to-date leak data

The Have I Been Pwned database contains billions of passwords from confirmed breaches.

Check and protect yourself

If your password is compromised – change it immediately and create a new strong one.

Wall of shame

The world’s worst passwords

These passwords have topped the annual "most common" (read: worst) password lists for years. If one of them looks familiar — it’s time for a change.

#1 123456
#2 123456789
#3 qwerty
#4 password
#5 12345
#6 111111
#7 1234567
#8 iloveyou
#9 admin
#10 abc123

Based on annual most-common-password reports (e.g. NCSC, NordPass) — the same entries reappear almost every year.

History

The biggest password breaches in history

A few moments that show how badly password reuse and weak protections can backfire at scale.

2009

RockYou

A SQL injection exposed 32 million accounts — passwords were stored in plain text, with no encryption at all. The dump became the basis for the infamous "rockyou.txt" wordlist, still used for password cracking today.

2012

LinkedIn

Data from 165 million accounts was stolen (the full scale was only revealed in 2016) — passwords were protected with weak, unsalted SHA-1 hashing, making them much easier to crack.

2013

Adobe

153 million accounts, including poorly encrypted passwords and password hints stored in plain text.

2013–2014

Yahoo

The largest single breach in history — affecting all roughly 3 billion Yahoo accounts.

2019

Collection #1

A bulk compilation of older leaks (not a fresh hack of one company) — 773 million email addresses and 21 million unique passwords packaged into one file circulating online.

2024

RockYou2024

Another massive compilation (not a new hack) — about 9.9 billion passwords gathered from earlier leaks and databases into a single file.

Figures are estimates based on widely reported industry sources. "Compilation" means a collection of data from earlier, separate breaches — not a fresh hack of a single company.

Why should you check your passwords?

Knowledge is the first step to safety. Learn how data breaches work and how to protect yourself.

How do password leaks happen?

During a breach, user data can be exposed – if you reuse passwords, other accounts are also at risk.

Why is reusing passwords dangerous?

Reusing passwords makes it easier for attackers to access multiple accounts after one breach.

How to protect yourself?

  • Use unique passwords for every account.
  • Create passwords at least 12 characters long with varied symbols.
  • Use a password manager.
  • Enable two-factor authentication (2FA).
  • Regularly check your passwords on Passly.pl.

What is k-anonymity?

K-anonymity technology allows checking a password without revealing its full hash.

Take care of your online safety – generate strong passwords and check them regularly.

Generate a new password

Frequently Asked Questions

No. Your password is processed locally – only the first 5 characters of its hash are sent.
Change it immediately and use Passly.pl to create a strong new password.
Regularly – every few months or after a major data breach.
Passwords are checked against Have I Been Pwned using k-anonymity (only the first 5 characters of the SHA-1 hash are sent). Email addresses are checked against the independent, free XposedOrNot database — two separate breach data sources.