Breach intelligence, for the people breached

Your passwords are
already out there.

Billions of credentials leak every year from companies you trusted. Cipher shows you exactly which breaches exposed your email — and what to do before someone else finds out first.

See how it happens
Aggregating Have I Been Pwned XposedOrNot DeHashed

A new data breach is disclosed almost every day. Once your email and password leak, they are copied, combined, and traded across the internet forever. The only real defense is knowing what's already exposed.

How a breach reaches you

From their server to your inbox

STEP 01
A company gets hacked
STEP 02
The database is dumped
STEP 03
It's sold & combined
STEP 04
Your accounts are opened
01

A company gets breached

An app, forum, or retailer you signed up for years ago is compromised — often through a stolen employee login or an unpatched server. Most breaches aren't discovered for months.

02

The user table is dumped

Attackers export the whole users table: emails, usernames, and password hashes — sometimes plaintext passwords, phone numbers, and addresses too.

03

It's sold, cracked & combined

The dump is traded on forums, weak hashes are cracked back to plaintext, and it's merged into massive "combolists" that map one person across dozens of leaks.

04

Reused passwords open your accounts

Bots replay those email + password pairs against banking, email, and social logins. If you reused a password anywhere, one old breach unlocks your life today.

Take back control

How to protect yourself

You can't un-leak a breach — but you can make it worthless. Five habits stop almost every account takeover.

Unique password everywhere

Never reuse. A leak from one site should never unlock another. This single habit defeats credential-stuffing.

Turn on 2FA / passkeys

A second factor — an authenticator app or a passkey — blocks logins even when your password is known.

Use a password manager

Let it generate and remember long random passwords, so "unique everywhere" is effortless instead of impossible.

Monitor your exposure

Know the moment your email shows up in a new leak, so you can rotate that password before it's abused.

Rotate old passwords

Retire the passwords you set a decade ago. Assume anything old and reused has already leaked somewhere.

Separate your identities

Use aliases for throwaway signups so one hobby-forum breach can't be tied straight to your primary inbox.

Where our big data comes from

Built on the world's breach record

We don't hack anyone. We aggregate already-public breach intelligence from the same trusted feeds security teams use, so you can check your own exposure in one place.

Have I Been Pwned
Breach directory

Troy Hunt's canonical index of known breaches and pastes — which sites were hit, when, and what classes of data were exposed.

XposedOrNot
Open exposure feed

An open dataset of breached accounts and password prevalence, used to confirm where an address appears and how common a password is.

DeHashed
Deep record search

A commercial intelligence provider covering thousands of datasets — powering the deep search that pulls your own leaked records live.

Cipher is a defensive, data-subject-access tool. We never store plaintext emails or passwords, every credit-charged search is logged, and you can only ever pull records for an address you prove you control. We are independent and not affiliated with Have I Been Pwned, XposedOrNot, DeHashed, or any other provider.

Find out in 60 seconds

See where you've been leaked.

Free breach and password checks. Create an account to run a deep search on the address you own.

Deep search

Query the full breach corpus across emails, usernames, names, IPs, phones and more. Each search costs 10 credits and is logged.

Authorized use only. Search only data you're allowed to (your own, your organization's, or with lawful authorization). Every query is logged. Misuse — stalking, harassment, unauthorized access — gets the account banned.