Technical and passive OSINT · Hosted free and open-data sources
Have I Been Pwned (HIBP) Pwned Passwords
Licence or access: no-key k-anonymity API/downloads
- status access
- no-key k-anonymity API/downloads
- i o and fit
- hash prefix → suffix/count
- current limitations and safe interpretation
- for authorized password hygiene, not prospect discovery; never send/store plaintext
- official source
- API
Official sources
- API https://haveibeenpwned.com/API/v3#PwnedPasswords
Catalogued at the 2026-09-01 research baseline. Verify the licence, free-tier limits, API schema and source terms again before deployment, and record a version-pinned registry entry for whatever you select.