Skip to content

BirdGuard for Windows 11

Is your password in a leaked database? How to find out without giving it away

Security · 4 min read

Why leaked passwords matter

When data leaks from online services, passwords end up with attackers too. They then try them on other services, because many people use the same password in several places. If your password is in such a database, it needs to be changed even if nobody has signed in to your account yet.

How a password is checked without being sent

Reputable checking services do not receive the whole password. A hash is first computed from the password and only its beginning, roughly five characters, is sent. The service returns all known hashes with the same beginning and your computer completes the comparison. Neither the password nor the whole hash ever leaves your computer.

BirdGuard checks a password in exactly this way and runs it only on your explicit action.

What to do if the password leaked

  1. Change the password immediately on every service where you use it.
  2. Choose a different password for each service. A password manager that remembers them for you will help.
  3. Where possible, turn on two-factor authentication, ideally through an app or a hardware key.
  4. Check that nothing was added to your account that you did not set up (e-mail forwarding, new devices).

What the check does not tell you

Not finding a password in the database does not mean it is safe. It only means it has not yet appeared in publicly known leaks. A short or predictable password is weak even if it is not on the list.

Do not let changes like this surprise you

BirdGuard will check these settings for you and, after your approval, offer reversible fixes. We are preparing version 1.0.

More from the guides

All guides