Start with Identity
Community Builder

Troy Hunt

Creator, Have I Been Pwned · Have I Been Pwned · 13+ years in identity
Focus areas
Credential BreachesPassword SecurityCredential StuffingSecurity Education
Notable work
  • Created Have I Been Pwned in December 2013
  • Built Pwned Passwords, the breached-credential corpus with k-anonymity lookup
  • Long-running security educator and Microsoft Regional Director

Bio

Troy Hunt created Have I Been Pwned in December 2013 as a way for people to find out whether their accounts appeared in a data breach. It now indexes billions of breached records, and its Pwned Passwords service is queried by password managers, identity platforms, and browsers.

Profile built from public project and press records.

Where their work shows up

NIST 800-63 tells you to screen new passwords against known-breached lists. Pwned Passwords is how most implementations actually do it, using a k-anonymity range query so the checking service never learns the password or its full hash. That single design choice made breached-credential screening safe enough to be a default, which is why it now sits inside CIAM platforms and password managers rather than being a security team's side project. See the breach teardowns for what the underlying data is drawn from.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].