Have I Been Pwned
Have I Been Pwned is a free breach-notification service operated by Superlative Enterprises Pty Ltd that aggregates 1,014+ breached websites and 17.67 billion+ pwned accounts, letting individuals and organizations check exposed credentials via paid API subscriptions.
- Company typePrivate
- Founded2013
- HeadquartersSurfers Paradise, Australia
- Headcount1–10
- GTM typeB2B and B2C
- OfferingSoftware
What Have I Been Pwned does
Have I Been Pwned (HIBP) is a free, consumer-facing breach notification service founded by Troy Hunt in 2013 and operated by Superlative Enterprises Pty Ltd, an Australian private company headquartered in Queensland. HIBP aggregates data from 1,014+ breached websites containing 17.67 billion+ pwned accounts and lets any user check whether an email address or password has appeared in a known breach, with optional free email alerts via the Notify Me service. The underlying platform runs on Microsoft Azure (Azure Table Storage) for the breach corpus and on Cloudflare's 335-edge-location CDN for the Pwned Passwords API, which serves 18 billion+ monthly requests at a >99.9% cache hit ratio using a SHA-1 / NTLM k-anonymity model that never exposes full hashes or email addresses to the server.
The paid product surface is API-first, offered in tiered subscriptions (Core from $4.39/month to $319/month, Pro from $379/month to $4,599/month, High RPM from $1,150/month to $5,833/month, plus custom Enterprise with white-label and callbacks). Paid tiers unlock domain monitoring, bulk enrollment for MSPs, k-anonymity email search, and stealer-log access. Breach data is sourced from direct submissions, open-source scraping, and law-enforcement feeds including the FBI and the Dutch National High Tech Crime Unit, giving HIBP visibility into credential exposure that competitors cannot easily reproduce.
Distribution is predominantly product-led: the free email and password search drives top-of-funnel awareness, the API and developer documentation (including a 2025-launched Model Context Protocol server) carry mid-funnel conversion, and partner integrations with 1Password and Aura provide post-breach upsells for US users. Headcount is small (1-10, with founder Troy Hunt, his wife Charlotte Hunt on operations, and Microsoft MVP Stefán Jökull Sigurðsson part-time on engineering), and the company is bootstrapped with no disclosed external funding.
Have I Been Pwned firmographics
Firmographics- Name
- Have I Been Pwned
- Legal name
- Superlative Enterprises Pty Ltd
- Website
- https://haveibeenpwned.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Have I Been Pwned is a free breach-notification service operated by Superlative Enterprises Pty Ltd that aggregates 1,014+ breached websites and 17.67 billion+ pwned accounts, letting individuals and organizations check exposed credentials via paid API subscriptions.
- Ownership category
- akta.pro rank
Have I Been Pwned industry classification
Industry- Product category
- Breach Detection and Credential Monitoring
- NAICS
- Web Search Portals, Libraries, Archives, and Other Information Services (519)
- akta.pro primary industry
- Fraud Detection & Prevention (payments fraud, account takeover, scams) (FSAGAFAE)
Keywords
Where Have I Been Pwned is headquartered
LocationHeadquarters
- HQ city
- Surfers Paradise
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
Have I Been Pwned business model
Business model- GTM type
- B2B and B2C
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Operations
Revenue model
- Free Email Search: Free point-in-time search for email addresses in breach database. Drives user acquisition and awareness.
- Core Subscription: Direct email search via API with rate limits up to 1,000 RPM, monitoring for up to 20 domains. Pricing from $4.39 to $319/month billed annually.
- Pro Subscription: Includes k-anonymity email search, customer domain monitoring for MSPs, bulk domain enrollment, auto subdomain verification, stealer log data. Rate limits up to 16,000 RPM, monitoring for up to 800 domains. From $379/month.
- High RPM Subscription: High-throughput API access up to 24,000 RPM for fast email searches. Supports both direct and k-anonymity search. From $1,150/month.
- Enterprise Subscription: White-label deployment, real-time breach callbacks, no API rate limits, invoiced billing, custom documentation, dedicated support. Custom pricing.
- Pwned Passwords API (Free): Freely accessible password checking API with no subscription required. No licensing or attribution requirements.
- Domain Search Subscriptions: Tiered pricing based on number of breached email addresses on domain and total domains monitored. Multi-year billing discounts available.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Core 1: 10 RPM, 25 breached addresses, 1 domain |
| Subscription | Annual | Core 2: 50 RPM, 100 breached addresses, 3 domains |
| Subscription | Annual | Core 3: 100 RPM, 500 breached addresses, 5 domains |
| Subscription | Annual | Core 4: 500 RPM, Unlimited addresses, 10 domains |
| Subscription | Annual | Core 5: 1,000 RPM, Unlimited addresses, 20 domains |
| Subscription | Multi-year contract | Pro 1: 1,000 RPM, 50 domains |
| Subscription | Annual | Pro 2: 2,000 RPM, 100 domains |
| Subscription | Annual | Pro 3: 4,000 RPM, 200 domains |
| Subscription | Annual | Pro 4: 8,000 RPM, 400 domains |
| Subscription | Annual | Pro 5: 16,000 RPM, 800 domains |
| Subscription | Annual | High RPM 4000: 4,000 RPM |
| Subscription | Annual | High RPM 8000: 8,000 RPM |
| Subscription | Annual | High RPM 12000: 12,000 RPM |
| Subscription | Annual | High RPM 16000: 16,000 RPM |
| Subscription | Annual | High RPM 24000: 24,000 RPM |
| Subscription | Annual | Enterprise: Full flexibility with white-label, callbacks, no rate limits |
Go-to-market motion4 records
Distribution channels5 records
Marketing channels8 records
Have I Been Pwned product offering
Product offeringCore offering
Have I Been Pwned (HIBP) operates a searchable database of more than 17.6 billion compromised records aggregated from over 1,014 breaches. Its free consumer offering allows individuals to check whether their email or password has appeared in a known data breach, plus opt-in email notifications when future exposures occur. Its commercial offering is a paid RESTful API (with Core, Pro, High RPM, and Enterprise tiers) used by organizations, developers, and MSPs to programmatically search breach data, monitor corporate domains, and access stealer-log intelligence.
Product overview
Have I Been Pwned is a free public service that aggregates data breaches to help users check if their email addresses or passwords have been compromised. The core offering includes the main HIBP breach search, Pwned Passwords (free password checking via k-anonymity API), and the Notify Me notification service. Paid tiers (Core, Pro, High RPM) provide API access with rate limits ranging from 10 to 24,000 RPM, domain monitoring, stealer log search, and k-anonymity features. The Pro tier includes customer domain monitoring for MSPs, while High RPM focuses on high-volume email searches. An MCP Server enables AI agent integration. All data is served via Cloudflare's global network.
Differentiator
Problem solved
Functional benefit
Products and services
- Have I Been Pwned (Free Email Search)
- Pwned Passwords
- Notify Me
Quantifiable outcome
- 17,674,817,406 pwned accounts tracked
- +4 more outcomes
Companies that use Have I Been Pwned
Customer profileSegments5 records
Ideal customer profiles4 records
Have I Been Pwned technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
Have I Been Pwned partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered flagship and core.
- AuraflagshipAura, a US-based identity protection service, was added to HIBP's partner program. Aura appears in HIBP dashboards and breach pages for US users, citing identity theft risks following data breaches as the driving rationale. Partnership provides Aura with a dedicated HIBP landing page featuring a discount.
- CloudflarecoreCloudflare provides the global infrastructure for serving HIBP's Pwned Passwords service, handling over 18 billion monthly requests through 335 edge locations across 125+ countries. The partnership enables >99.9% cache hit ratio and lightning-fast responses regardless of user location.
- 1Passwordflagship1Password appears in HIBP dashboards and breach pages for US users, offering post-breach protection services. Partnership provides HIBP with a dedicated landing page featuring a discount. 1Password is positioned as a partner offering post-breach protection services to HIBP users.
- US Federal Bureau of Investigation (FBI)flagshipFBI provided HIBP with data from the Emotet malware campaign in April 2021, contributing to the malware breach data in the database. This law enforcement partnership helps expand HIBP's coverage of credential exposure.
- Dutch National High Tech Crime Unit (NHTCU)flagshipDutch NHTCU provided HIBP with data from malware campaigns, contributing to the database's malware breach coverage alongside FBI data.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
Have I Been Pwned competitors and assessment
Company assessmentDirect peers
- SpyCloud: SaaS credential-exposure intelligence platform that recaptures breached and stealer-log credentials for enterprise security teams. Closest direct competitor to HIBP's paid API and stealer-log products, with comparable data depth but a much larger sales footprint and Series-D funding.
- DeHashed: Searchable breach-data engine offering email, password, IP, and credential lookups via API to enterprise customers. Directly competes with HIBP's paid API tiers and domain-search functionality, serving similar corporate fraud-investigation and threat-intelligence buyers.
- Constella Intelligence: Identity-breach intelligence platform aggregating stolen credentials, exposed PII, and infostealer logs for fraud, AML, and security teams. Overlaps with HIBP's stealer-log and domain-search offerings, but at an enterprise tier with significantly more capital and headcount.
- LeakCheck: Paid breach-credential search service offering email, username, and password lookups via API. Closely comparable to HIBP's free and Core-tier offerings, though typically with a more raw-data approach and less emphasis on privacy-preserving k-anonymity.
- Snusbase: Breach-database search engine marketed to security researchers and fraud investigators with API and bulk-search access. Comparable to HIBP's API in functional capability, though Snusbase typically serves a more underground researcher segment.
Broad incumbents
- IntSights (Rapid7 Threat Command): Enterprise digital-risk-protection platform from Rapid7 that monitors surface, deep, and dark web for leaked credentials and brand threats. Overlaps with HIBP's domain and stealer-log monitoring at the enterprise end, but bundled into a much broader threat-intelligence suite.
- Recorded Future: Large-scale threat-intelligence platform (acquired by Mastercard for $2.6B) that ingests breach data, stealer logs, and credential leaks as part of a broader intelligence feed. Adjacent competitor to HIBP in credential-intelligence use cases, but operates at much greater scale and breadth.
- Mozilla Monitor: Consumer breach-notification service from Mozilla built directly on top of HIBP's API. Comparable end-user product for individuals but is a downstream consumer of HIBP rather than a competitor; demonstrates HIBP's role as upstream infrastructure for major browser vendors.
Emerging players
- 1Password Watchtower: Password-manager breach-alert feature (and HIBP GTM partner) that surfaces compromised-credential alerts to end users. Partly competes with HIBP's free email-check surface but is also a major distribution channel for HIBP breach data inside the 1Password product.
Others
- Aura: US consumer identity-theft-protection service and HIBP GTM partner that surfaces breach alerts in HIBP dashboards for US users. Not a direct data competitor, but a paid upgrade destination and distribution partner monetizing HIBP's breach-awareness traffic.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Have I Been Pwned social profiles
Digital presenceHave I Been Pwned financial estimates
Financial estimateRevenue estimate
Valuation estimate
Have I Been Pwned leadership team
Management profileNumber of profiles
Profiles3 records
Have I Been Pwned funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Have I Been Pwned M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Have I Been Pwned
What does Have I Been Pwned do?
Have I Been Pwned (HIBP) operates a searchable database of more than 17.6 billion compromised records aggregated from over 1,014 breaches. Its free consumer offering allows individuals to check whether their email or password has appeared in a known data breach, plus opt-in email notifications when future exposures occur. Its commercial offering is a paid RESTful API (with Core, Pro, High RPM, and Enterprise tiers) used by organizations, developers, and MSPs to programmatically search breach data, monitor corporate domains, and access stealer-log intelligence.
Is Have I Been Pwned a public or private company?
Have I Been Pwned is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Have I Been Pwned founded?
Have I Been Pwned was founded in 2013. It employs 1 to 10 people.
Where is Have I Been Pwned based?
Have I Been Pwned is headquartered in Surfers Paradise, Australia, in the Oceania region.
How does Have I Been Pwned make money?
Seven revenue lines are on record. Free Email Search is the primary driver. The others are core Subscription, pro Subscription, high RPM Subscription, enterprise Subscription, pwned Passwords API (Free) and domain Search Subscriptions.
Who are Have I Been Pwned's main competitors?
Direct peers on record are SpyCloud, DeHashed, Constella Intelligence, LeakCheck and Snusbase. Broad incumbents are IntSights (Rapid7 Threat Command), Recorded Future and Mozilla Monitor. 1Password Watchtower is listed as an emerging player. Aura is listed as an others.
Does Have I Been Pwned have an API?
Yes. RESTful API (v3) enabling programmatic search for breached email addresses, passwords, domains, stealer logs, and pastes. Requires hibp-api-key header (32-character hexadecimal string) for authenticated endpoints. Free Pwned Passwords API available without subscription using k-anonymity model. Rate limits apply based on subscription tier (10 RPM to 24,000 RPM). Supports HTTPS only (TLS 1.2/1.3). Test API keys available for integration testing. CORS supported for non-authenticated APIs only. Developer documentation is at haveibeenpwned.com/API/v3.
What industry is Have I Been Pwned in?
Have I Been Pwned's product category is Breach Detection and Credential Monitoring. Its primary akta.pro industry code is FSAGAFAE, Fraud Detection & Prevention (payments fraud, account takeover, scams). Its NAICS code is 519.