GHOSTKIT/Breach & Password Check
04 Β· BREACH & PASSWORD CHECK
Check exposure without sending GhostKit your secret.
GhostKit's default mode is deliberately offline. No password is transmitted to GhostKit and this build does not call a third-party breach API from your browser. Use the official external service yourself when you choose.
Local password strength check
The value is processed only in this browser. GhostKit does not send it to its server or save it. Refreshing or closing the page clears it.
Have I Been Pwned β use directly
For an email breach lookup or Pwned Passwords check, leave GhostKit and use the official service directly. GhostKit never collects the email or password for this purpose.
If an account is exposed
- Secure the primary email first.
- Change the compromised password everywhere it was reused.
- Sign out unknown sessions and revoke unknown apps.
- Replace recovery email/phone details you do not recognize.
- Enable MFA or a passkey.
- Review forwarding rules, filters and mailbox delegates.
- Review financial and government accounts connected to the email.