Mastodon

About

Hi, I'm Troy Hunt, I write this blog, started the Have I Been Pwned Data Breach intelligence service and am a Microsoft Regional Director

I'm Troy Hunt, the guy who founded Have I Been Pwned, which somehow became the most trusted name in data breach intelligence. I'm also a Microsoft Regional Director, and whilst I don't work for Microsoft (it's a title of recognition), they're kind enough to acknowledge my community contributions through their various award programs, which I've been part of since 2011. You'll regularly find me in the press talking about security and even testifying before US Congress on the impact of data breaches.

Have I Been Pwned

Have I Been Pwned launched on 4 December 2013 as a way for anyone to check whether their email address had been exposed in a data breach. What started as a personal project has grown into something considerably larger: it now indexes tens of billions of breach records across over 1,000 discrete incidents, covering more than 6 billion unique email addresses. More than 400,000 domains are actively monitored, including by more than half the Fortune 500. Dozens of national governments use the service (free of charge) to protect their citizens and government systems.

Pwned Passwords, the companion service for checking exposed passwords, processes hundreds of millions of searches every day. The FBI, Europol and other law enforcement agencies regularly contribute compromised credentials discovered during cybercrime investigations. That service (which is free and open source), helps protect accounts on thousands of online services worldwide.

The work I do in the data breach space took me all the way to the United States Congress in 2017, where I testified before the United States House Committee on Energy and Commerce on identity verification in a post-breach world. In essence, I highlighted the risks associated with proving our identities online when so much of our identity data has already been leaked in breaches.

Speaking and Workshops

I regularly speak around the world and run developer-focused security workshops. You'll frequently find me at major technology events, and I publish both my upcoming travels and previous speaker scores as soon as they're known: 2014, 2015, 2016, 2017, 2018, 2019, 2020, 2021, 2022, 2023, 2024, 2025, 2026. You can also find any of the previous presentations I've done that have been published online via my recorded talks page.

Pluralsight

In 2013, I started creating online courses for Pluralsight. I went on to author 47 courses for the online training company, predominantly in the information security space. Creating content for Pluralsight gave me the opportunity to pursue independence, and after publishing more than 100 hours of content, I moved on to focusing on HIBP and public engagements in 2018.

Pfizer

For fourteen years prior to going fully independent, I worked at Pfizer, with the last seven years being responsible for application architecture in the Asia Pacific region. Time spent in a large corporate environment gave me huge exposure to all aspects of technology as well as the diverse cultures my role spanned. Many of the things I teach in post-corporate life are based on these experiences, particularly from working with a large number of outsourcing vendors across the globe. For more corporatey background, there's always my LinkedIn profile.

Location

I'm based on the Gold Coast in Australia (the sunny part of the sunny country!) where I live with my wife Charlotte (also the COO of HIBP) and our two teenage kids. I can be reached via the contact page, where I'm happy to be emailed about technical queries, press inquiries and certainly any corrections or suggestions for material.