Have I been pwned?

Have I been pwned?

@pwned_robot
FreeEN

Send your own email address and it tells you whether that address has surfaced in a known data breach — a simple, unofficial Telegram front-end for the "have I been pwned" checking model. Never enter your actual password into it.

Key features

  • Checks an email address against known public breach datasets
  • Simple single-message interaction, no account needed
  • Follows the same model as haveibeenpwned.com
  • Free to use

What Have I been pwned? does

Pwned_robot's own profile states its function directly: "Telegram Bot that you can check if you have an account or password that has been compromised in a data breach." In practice that means one thing: you send an email address — your own — and it checks that address against known, previously published breach datasets, telling you whether it has appeared in one.

This is the correct, safe shape for a "leak check" tool: it takes an identifier you already control (an email address) and tells you a yes/no fact about public breach records, the same category of service as the well-known haveibeenpwned.com website. It is not a tool for looking up someone else's personal information, and it should never ask you to type in an actual password as "verification" — if any bot in this category ever does that, stop and treat it as a red flag regardless of what it claims to check.

As with any unofficial third-party bot in the security space, there's no way to independently audit what happens to the email address after you send it, so treat the result as informational rather than authoritative, and prefer changing a password proactively over trusting a "not found" result completely. If a breach is confirmed, change that password immediately and turn on two-factor authentication wherever the affected account supports it.

How to start

  1. Open @pwned_robot in Telegram and send /start
  2. Send your own email address
  3. Read whether it appears in a known breach
  4. Change the password on any affected account if a breach is confirmed

Pricing and limits

Free

Pros / Cons

  • Simple, clear single-purpose function
  • Free and requires no registration
  • Follows the safe "check your own identifier" model
  • Unofficial third-party bot, not haveibeenpwned.com itself
  • No transparency on how long submitted emails are retained
  • No confirmed English/Russian language toggle beyond the interface shown

Score breakdown

CriterionWeightPoints
Functionality256 / 10
Reliability & speed155 / 10
Popularity & trust154 / 10
Price & free tier1010 / 10
Usability107 / 10
Safety & privacy106 / 10
Freshness54 / 10
Localization53 / 10
No intrusive ads59 / 10
Score10059.0

How we rank

FAQ

Should I ever type my actual password into this bot?

No — never. A legitimate breach checker only needs an email address; if any bot asks for your real password "to check it," treat that as a scam regardless of its name.

What should I do if my email is found in a breach?

Change the password on the affected account immediately, avoid reusing that password anywhere else, and enable two-factor authentication if the service offers it.

Technical details

  • Inline mode
  • Mini App
  • Works in groups
  • Works in channels
  • Accepts voice
  • Accepts files
  • Requires phone number
  • Requires registration
  • Shows ads
  • Works in Russia without VPN

Checked September 4, 2026 · Updated September 6, 2026 · Report a problem