1. Home
  2. NIST Online Resources
  3. Managing NIST Accounts
  4. haveibeenpwned? (Use this to check for breaches of your credentials)

haveibeenpwned? (Use this to check for breaches of your credentials)

  • NIST recommends that you register your email(s) at the site called haveibeenpwned? to be notified if your credentials are ever released during any known breaches. This site is a database of all known credential and personal information breaches.
  • What does pwned mean? The word “pwned” has origins in video game culture and is a leetspeak derivation of the word “owned”, due to the proximity of the “o” and “p” keys. It’s typically used to imply that someone has been controlled or compromised, for example “I was pwned in the Adobe data breach”.
  • For example, if Canva had a breach and it exposed your name, email address, and/or password, this site would tell you if your email was a part of that breach as well as the date of the breach and the type of personal data that was exposed.

Instructions to Register and Interpret Results (Or Video Below)

  1. Go to the haveibeenpwned? site.
  2. Click on Notify Me
  3. Type in your email address, and tick Not a robot. Click notify me of pwnage.
  4. Check email, click on the Verification link.
  5. “Verification is complete” message will show. Get your results displayed and be informed of any new pwnage in the future.
  6. Be wary of suspicious emails based on which elements of your personal information has been breached. Make changes to passwords based on when your password was last compromised. You can decide whether you need to take action based on the date of your last password change and how many other systems you use this password in (which is not recommended).
  7. Repeat for any other email addresses you use.

More Information

Updated on September 20, 2020

Was this article helpful?