- Privacy & Data
Have I Been Pwned alternatives: the best ways to check your email for breaches in 2026

The trouble with breach checkers is that they answer the easy question well. “Have I been breached?” has the same answer for almost everyone, and that answer is yes. The harder question is what you’re supposed to do next, and no checker on this list can answer it for you. That includes ours.
We should say up front that we make one of these tools. Yorba is ours, it’s last on the list, and we’ll tell you where the others beat it. It’s also built differently from the rest. Our free checker, Breach Beacon, is the front door to a larger system that finds the accounts behind your breaches and closes them for you. If all you want is a free alert when your email turns up in a new breach, Mozilla Monitor is the better pick today. Have I Been Pwned is still the best free place to run a check.
So why write a guide to alternatives at all? Because this year Google shut down its own breach tool and told everyone why, and the reason it gave describes the gap this whole category has been stepping around.
In this article
- Google retired its dark web report because people didn’t know what to do with the results, which is the real gap in breach checking
- Several of the best-known alternatives run on Have I Been Pwned’s own data, so a “second opinion” often returns the same list
- Your password manager may already be running a breach check you’ve never opened
- Changing your password protects the next login, but it doesn’t make the account go away
- The useful question after any breach result is whether that account should still exist
The sentence that explains the category
Google switched off its dark web report this year. Scans for new breaches stopped on 15 January 2026, and the report disappeared for good on 16 February, along with everyone’s stored results. Google’s support page gave the reason plainly: feedback showed the report “didn’t provide helpful next steps.”
That’s a remarkable thing for Google to admit. It built a breach tool and concluded that telling people about a breach, without telling them what to do about it, wasn’t worth keeping.
Mozilla made a smaller cut a few weeks earlier. Monitor Plus, its paid data broker removal service, shut down on 17 December 2025. The free breach alerts survived, and Mozilla raised the number of addresses you can monitor to 20. Some comparison pages ranking for this search still describe Monitor Plus as available, so check the date on whatever you’re reading, this one included.
We call what Google described the after-alert gap. It’s the distance between knowing your data leaked and knowing which account to deal with. Every tool below either closes that gap or hands it back to you.
Start with Have I Been Pwned, because it’s still the best
Have I Been Pwned was started by security researcher Troy Hunt and has been independently run since 2013. On 2 October 2026 its homepage counted 1,039 breached websites and more than 17.8 billion breached addresses.
The free version covers what most people need. You can search any address in your browser and sign up for an email the moment it turns up in a new breach. A separate tool, Pwned Passwords, checks whether a password has appeared in leaked data. The paid plans, from $4.39 a month billed annually, are built for API access and monitoring company domains, so checking your own inbox doesn’t require one.
It also handles the awkward cases with more care than most of its imitators. Breaches from sites like dating apps are flagged as sensitive, and they only appear once you’ve proved you own the address by signing in. Breaches that can’t be fully confirmed are labelled unverified or fabricated rather than hidden.
None of the alternatives below replace it. The reasons to look further all come down to what happens after the result.
Four beliefs to let go
Most of what people assume about breach checkers comes from the word “monitoring.” Here’s what the tools themselves say.
“A clean result means I’m safe”
Have I Been Pwned’s own FAQ says the database holds only a small subset of everything that has ever been breached. Plenty of breaches are never published, and some are never detected. A clean result means you aren’t in the breaches it holds. It doesn’t mean you’ve never been breached.
“A second checker gives me a second opinion”
Often it doesn’t. Mozilla Monitor, Bitwarden and 1Password all name Have I Been Pwned as their data source, so if you’ve already searched Have I Been Pwned, those tools will mostly tell you what you already know in a different layout. A genuine second opinion needs a different dataset, which is why the Cybernews checker below is on this list.
“Dark web monitoring means someone is watching the dark web for me”
The phrase suggests a person combing criminal forums on your behalf. In practice, most consumer tools check your address against breach data that has already been collected and indexed. That isn’t a criticism of any one product. It just means you should know where a tool’s data comes from before you pay for it.
“Changing the password fixes it”
It fixes the next login. Have I Been Pwned treats your appearance in a breach as a permanent historical record, so the entry stays. More importantly, the company still holds everything else it knows about you for as long as you have an account there. You can’t be caught in a breach at a company you’ve genuinely left, and that’s the only version of this that ends.
The alternatives, with a drawback each
A comparison where every tool suits everyone isn’t worth reading, so each of these gets a drawback, ours included.
1. Mozilla Monitor
The closest like-for-like alternative, and the best free option for ongoing alerts. Mozilla Monitor gives you a free scan, then watches your address and emails you when a new breach appears. Since Monitor Plus closed, you can monitor up to 20 addresses for free. It works in any browser, though you’ll need a Mozilla account for alerts and to see sensitive breaches.
Where it improves on Have I Been Pwned is the walkthrough. Each breach comes with guided steps for resolving it, and Mozilla tracks which ones you’ve marked as done.
The drawback: it isn’t a second opinion. Mozilla’s FAQ says its breach data comes from Have I Been Pwned, so a scan returns the same breaches. The data broker removal it used to sell is gone.
2. The password manager you already use
You may be paying for a breach checker already.
- Bitwarden. The Data Breach report is free on every plan and checks your address against Have I Been Pwned. It only runs from the web vault, not the phone or desktop apps.
- 1Password. Watchtower’s Breach Report queries Have I Been Pwned without sending it your full address, and it lists breached sites where you have no saved login at all. That second list is the interesting one, because it’s a list of accounts you’ve probably forgotten.
- Proton Pass. Dark Web Monitoring is on paid plans and covers your Proton addresses, your hide-my-email aliases and up to 10 other addresses.
- Apple Passwords. On an iPhone or Mac, Detect Compromised Passwords warns you when a saved password shows up in a data leak, without revealing your passwords to Apple. It checks passwords, not your email address.
These tools can see your actual saved logins, so they can point at the exact password to change.
The drawback: they only know about what you saved. Accounts you created before you started using the manager, or never got round to importing, stay invisible.
3. Cybernews Personal Data Leak Checker
The best free second opinion, because it isn’t built on the same data. The Cybernews checker claims 36,030 breached websites and more than 18.6 billion breached accounts, and it’s the only free checker here that accepts a phone number as well as an email address. Cybernews says it doesn’t collect or store the addresses you search.
A different dataset can surface a breach Have I Been Pwned doesn’t have, and the reverse is just as likely, so run it after Have I Been Pwned rather than instead of it.
The drawback: it’s a one-off lookup with no alerts and no guidance on what to do next. Cybernews is also a commercial review site, so expect product recommendations around your result.
4. DeHashed
For investigators, not for most people. DeHashed is a paid search engine over breached records, built for security analysts and researchers. It searches far more than email addresses, including usernames, phone numbers and IP addresses, and lets you dig into the leaked records themselves.
The drawback: you don’t need to see a leaked password to know you should change it. If you’re checking your own exposure, everything above is simpler and free.
5. Yorba
This one is ours, and it works differently from everything above. Every other tool on this list stops at the alert. Yorba starts there and carries on through the rest of the after-alert loop, and most of that work we can do for you.
Here’s how the pieces fit together:
- Check. Breach Beacon is free, needs no signup, and checks one or more email addresses against known breaches, showing which breaches exposed each one.
- Find. A free Yorba account scans your Google or Microsoft inbox for the signup confirmations and automated emails that show you have an account somewhere, including the ones you’ve forgotten making. After the first scan it keeps checking every week, so new accounts show up without you hunting for them. That gives you what a breach result can’t: a list of the companies still holding your data.
- Close. Delete Desk, our free database of account deletion instructions, tells you how to close each account yourself. On Premium, our deletion team of human agents sends the deletion requests for you.
- Watch. Premium also adds ongoing breach monitoring. When a company you still use gets breached, you hear about it, and the account behind it is already on your list.
The same scan picks up the mailing lists and recurring subscriptions those accounts generate. On Premium, at $60 a year, we can unsubscribe you automatically when a sender crosses the limits you set, and cancel subscriptions for you.
What it won’t do: Breach Beacon on its own is a one-off check, and ongoing monitoring is a Premium feature. Have I Been Pwned and Mozilla Monitor alert you for free, so if alerts are all you want, use them. We only connect Google and Microsoft mailboxes, and we don’t remove your profile from data broker sites. Deletion isn’t instant either, because it depends on each company acting on the request. Like every tool here, we can’t pull your data back out of a breach that has already happened.
Which one should you use?
Match the tool to the question you’re actually asking.
- “Am I in any breaches?” Have I Been Pwned. It’s free, and it’s the source most of the others draw on.
- “Tell me if it happens again.” Mozilla Monitor, for up to 20 addresses with guided fixes, or Have I Been Pwned’s free Notify Me alerts.
- “Did the first check miss anything?” The Cybernews checker, which uses a separate dataset and also takes phone numbers.
- “Which of my saved passwords leaked?” The breach report in your password manager, or Apple Passwords on an iPhone or Mac.
- “I’m investigating exposure professionally.” DeHashed.
- “I got a result. Now what?” Yorba. We find the accounts behind your breaches and can close the ones you don’t need for you.
The after-alert loop
Every breach result should run through the same four steps:
Check → Read → Secure → Close
Most breach guides cover the first three. The fourth is where your risk actually goes down. Skip it, and you’ve cleaned up after a breach at a company that can lose your data again.
You can run the whole loop yourself with free tools, and the steps below show you how. If you’d rather hand it off, Yorba takes on the checking and the closing, which are the parts most people never get round to.
1. Check
Run Have I Been Pwned, then the Cybernews checker for a different dataset. Turn on alerts with Mozilla Monitor or Have I Been Pwned’s Notify Me. Breaches are often loaded months or years after they happen, which Mozilla says outright, so an old account can show up in a new result long after you’ve stopped thinking about it.
2. Read
Have I Been Pwned lists the types of data exposed in each breach. A leaked password needs action today. A leaked email address with no password mostly means more spam and phishing, so be wary of messages that mention that company.
If you don’t recognise the company, don’t panic. Often it was bought or renamed after you signed up. Sometimes your address arrived in a combined list stitched together from older breaches, which Mozilla calls a combolist. Searching your inbox for the company’s name usually turns up an old signup email.
3. Secure
Change the password on that account, and anywhere else you used it. Reuse is how one breach becomes several, because attackers take leaked email and password pairs and try them on other sites. Then turn on two-factor authentication, starting with your email account and anything that holds money. Your email is the key that resets everything else.
4. Close, the step every checker skips
Ask whether the account should still exist. If you haven’t used it in years, close it. Delete Desk has free deletion instructions, with no account needed. A breach result is a list of companies that lost your data, and once you read it as a list of accounts to close, starting with the ones you’d forgotten you had, it finally becomes useful.
This is the next step Google said its own report was missing. Doing it by hand for every account is the slow part, and it’s the part Yorba was built for. Our scan finds the accounts, including the forgotten ones, and on Premium our deletion team closes them for you.
Is it safe to type your email into a breach checker?
With the reputable ones, yes. Your email address isn’t a secret, and on its own it isn’t enough to get into any of your accounts. Have I Been Pwned says searches aren’t logged, and that Pwned Passwords anonymises a password before it leaves your browser. Cybernews says it doesn’t store the addresses you search. Breach Beacon encrypts your data and never shares it.
Signing up for alerts is a slightly different trade. Any service that monitors your address has to keep it so it can contact you when a new breach lands. Have I Been Pwned says its alert service stores only your address, the date you signed up and a verification token.
The real red flag is a checker that asks for your password alongside your email. You never need to hand both to a website to find out whether you’ve been breached.
The best breach check ends with fewer accounts
Every tool on this page, ours included, works after the fact. By the time your address shows up in a result, the data is already out, and nobody can call it back. What you control is how many companies are holding your details the next time one of them gets breached.
A password manager makes each of those accounts harder to break into. Closing the ones you don’t use means there’s nothing left to break into.
If you want to see where you stand, Breach Beacon is free and takes one click. Run Have I Been Pwned too. Then look at the results and ask which of those accounts you’d actually miss. Close the rest yourself, or let us do it for you.
Frequently asked questions
Is Have I Been Pwned safe to use?Yes. It has run since 2013, and its FAQ says searches aren’t logged. An email address alone can’t unlock your accounts. If you sign up for alerts, it stores your address so it can contact you, along with the date you subscribed and a verification token.
Is Have I Been Pwned accurate?What it shows is reliable, and doubtful breaches are labelled unverified or fabricated. It isn’t complete, and it says so itself. A clean result means you’re not in the breaches it holds, not that you’ve never been breached.
What is the best free alternative to Have I Been Pwned?Mozilla Monitor, for ongoing alerts on up to 20 addresses with guided steps. For a genuine second opinion, use the Cybernews checker, since Mozilla’s data comes from Have I Been Pwned and the Cybernews data doesn’t.
Do I need to pay for breach monitoring?Most people don’t. Have I Been Pwned and Mozilla Monitor both alert you for free. Paying makes sense when the subscription does something with the result, like closing accounts for you, rather than just telling you about it.
What replaced Google’s dark web report?Nothing from Google directly. Scans stopped on 15 January 2026 and the report closed on 16 February 2026. Mozilla Monitor is the closest free replacement for alerts.
Why does my email show up in breaches for sites I never joined?Usually the site was bought or renamed after you signed up, or it’s an account you’ve forgotten. Sometimes someone else used your address, or the breach is a list combined from older leaks. Searching your inbox for the company’s name often settles it.
Can breach checkers see my password?The email checkers don’t need it and shouldn’t ask. Have I Been Pwned doesn’t load passwords alongside the addresses it stores. Password checks like Pwned Passwords and Apple’s Detect Compromised Passwords work from an anonymised version, so the password itself never reaches the service.
Can I remove my email from Have I Been Pwned?Yes, through its opt-out page. That hides your address from public searches. It doesn’t remove your data from the breach itself, which is already circulating, and it doesn’t close the account that leaked.
Sources
- Have I Been Pwned, FAQs, pricing and opt-out
- Google, Learn about updates to dark web report
- Mozilla Monitor and Mozilla Monitor FAQ
- Mozilla, Monitor Plus has shut down
- Bitwarden, Vault health reports
- 1Password, Watchtower breach report
- Proton, What is Pass Monitor
- Apple, Passwords and privacy
- Cybernews, Personal Data Leak Checker
- DeHashed
- Yorba, Breach Beacon, breach monitoring, deletion team and pricing
- Yorba homepage, for Premium features
- Delete Desk

