Troy Hunt

Troy Hunt

Creator
0 followers

Australian security expert known for creating Have I Been Pwned and for his insights on data breaches and web security.

Kids' Cybercrime Pathway Traced Back to Gaming
SocialApr 15, 2026

Kids' Cybercrime Pathway Traced Back to Gaming

Pretty good overview of the pathway to cybercrime for kids and the genesis always coming back to gaming. Kinda feel like that Roblox statement really missed the point though (assuming they understood the context).

By Troy Hunt
AI Agents Can Now Query HaveIBeenPwned Data Securely
SocialApr 14, 2026

AI Agents Can Now Query HaveIBeenPwned Data Securely

We’re working on better exposing @haveibeenpwned data to AI agents, including via MCP (no privacy or security changes, still need a key to query the same stuff). I’m trying to craft the right narrative around how “normies” can use this:...

By Troy Hunt
Clearing Session Erases Claude's Prior Conversation Memory
SocialApr 7, 2026

Clearing Session Erases Claude's Prior Conversation Memory

It was all going great with @openclaw... until today. Been doing heaps of breach research and analysis, then it's hit the wall. I'm trying to understand the way out: clearing the session will erase Claude's memory of prior discussions, right?...

By Troy Hunt
AI Bot PwnedClaw Analyzes This Week's Data Breaches
SocialMar 31, 2026

AI Bot PwnedClaw Analyzes This Week's Data Breaches

Weekly update is up! Join Me in Investigating Today’s Data Breaches With the PwnedClaw, the OpenClaw Agentic AI Bot Doing My Legwork: https://t.co/KeML1pLTOL

By Troy Hunt
New Have I Been Pwned Features Boost Privacy, Usability, Performance
SocialMar 30, 2026

New Have I Been Pwned Features Boost Privacy, Usability, Performance

Today, after many months of hard work, we're launching a bunch of new @haveibeenpwned features that improve privacy, usability and performance. We're a little team, but we've done a lot since this pic in November. Here are all the details:...

By Troy Hunt
Inside HIBP's Core Architecture: Weekly Update
SocialMar 17, 2026

Inside HIBP's Core Architecture: Weekly Update

Weekly update is up! Behind the scenes of some of Have I Been Pwned’s most important architectural components https://www.troyhunt.com/weekly-update-495/

By Troy Hunt
Check Your Data Exposure with Free Breach Lookup Tools
SocialMar 6, 2026

Check Your Data Exposure with Free Breach Lookup Tools

“To check if your details have appeared in any other public data breaches, there are a number of online tools that you can use, such as https://t.co/nppjjGzwdR” 😎

By Troy Hunt
Proton Defends Compliance with Local Law, Sparks Backlash
SocialMar 6, 2026

Proton Defends Compliance with Local Law, Sparks Backlash

People still shocked that Proton adheres to the law in the country in which they’re based 😮

By Troy Hunt
First Age Verification Prompt Hits Social Media Users
SocialMar 4, 2026

First Age Verification Prompt Hits Social Media Users

One for the “but age verification means *everyone* has to show their gov ID or hand over biometric data” brigade. For the first time ever, I just got an age challenge on a social media platform: https://t.co/IidAL3Czai

By Troy Hunt
HungerRushRMS Breach Leads to Phishing Emails, Aussie Traffic Blocked
SocialMar 4, 2026

HungerRushRMS Breach Leads to Phishing Emails, Aussie Traffic Blocked

Looks like @HungerRushRMS got pwned and the bad guys are emailing customers. Now they’re blocking website traffic (at least they are for Aussie traffic). https://t.co/lKe74m0OTc

By Troy Hunt
AI Prompt Breaches Reveal Personal Data Tied to Identities
SocialMar 2, 2026

AI Prompt Breaches Reveal Personal Data Tied to Identities

Data breaches containing AI prompts from users create a whole new set of privacy problems. Prompts are frequently very personal in nature and, from a privacy perspective, not something users expect to see tied back to their IRL identities.

By Troy Hunt
One Email per Breach May Miss Second Dump
SocialFeb 27, 2026

One Email per Breach May Miss Second Dump

Updated breaches are a bit messy when it comes to sending domain notifications. We only send ONE email per breach to domain subscribers, so you may get an alert for dump 1 but not for dump 2. It's probably worth...

By Troy Hunt
Persona Confirms No Data Breach, Nothing to Leak
SocialFeb 26, 2026

Persona Confirms No Data Breach, Nothing to Leak

Been reading the @Persona_IDV incident write up as a bunch of people have asked “will the data be going into @haveibeenpwned?” Easy answer: no, because there’s no data: https://t.co/4oxtwYBxj2

By Troy Hunt
Canadian Tire Breach Leaks 38M Emails, Personal Data
SocialFeb 25, 2026

Canadian Tire Breach Leaks 38M Emails, Personal Data

I've had a few queries on this one (which isn't unusual for a large incident), mostly to the effect of "but I've never bought tyres in Canada". So, firstly, this isn't a tyre retailer, there are a heap of other...

By Troy Hunt