PARTLY

As of 13 August 2026, AI can only partly check whether your password has appeared in a data breach.

Most people should hand this to a purpose-built tool.

Can you do it?

5 minutesto a draft.

15 minutesto something you’d act on.

Cost, all in£0

Skill needednone

Who has to check ityou

What the alternative costsThe alternative is to check the password yourself with a reputable breach-checking service; this answer does not assign it a price.

If this goes wrong, you may treat a reused password as safe and leave accounts exposed.

What to actually do

  1. Use a tool built for this

    The route this page recommends

  2. Do it yourself

    Second choice

    A chat interface, no skill needed, and roughly 15 minutes until you can act on the result.

    How to actually do it

    1. Open the official Have I Been Pwned Pwned Passwords checker in your browser, rather than giving the password to a chatbot.
    2. Enter the password directly into that checker and submit it; do not copy the password into this chat, an email or a form you do not recognise.
    3. Record whether the checker reports a match, then ask the chatbot to explain the displayed result without sharing the password itself.
    4. If there is a match, open your password manager or account list and change that password on every account where it was used, starting with email, banking and shopping accounts.
    5. Create a different long password for each account and enable multi-factor authentication in each service's security settings.
    6. If there is no match, keep the password unique and change it if it is reused, old, short or exposed in any other way; compare the checker's explanation with its own help information.

    Prompt

    Help me check whether a password has appeared in a known data breach without asking me to paste the password into this chat. Give me safe, current instructions for using a reputable password-breach checker that supports privacy-preserving checking, such as a k-anonymity method. Explain how to interpret both a match and no match. Do not claim that no match proves the password is safe. Tell me what to do if it has appeared, including changing it everywhere it was reused, using a unique password for each account, and enabling multi-factor authentication where available. If you cannot verify a live result yourself, say so clearly.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

  3. Hand it to a person

    The distant third

    A person who owns the outcome does this end to end, worth it when the failure is dear.

What it gets wrong

What caps this at PARTLY: private data access, real time truth and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification2
Liability1
Effort delta1
Total6 / 10

FAQ

Can ChatGPT tell me if my password has been hacked?
Not directly. It cannot query a live breach database from this chat, and you should never paste your password into it; use a reputable password-breach checker yourself and ask AI to explain the result without sharing the password.
Is it safe to check my password on Have I Been Pwned?
Its Pwned Passwords checker is designed to support privacy-preserving checks, but you should open the genuine service yourself and avoid sending the password anywhere else. A match means you should stop using that password and change it wherever it was reused.
What should I do if my password was found in a data breach?
Change it immediately on every account where you used it, starting with your email and financial accounts. Use a unique password for each account, store them in a password manager and enable multi-factor authentication where available.
What if my password was not found in a breach?
That is not proof that the password is safe or has never been exposed. Keep it unique, change it if it was reused or weak, and treat any warning from an account provider or password manager as a reason to replace it.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.