The contents of this page may be used wherever a bio or photos are required. You're welcome to pick and choose at will and tailor the content to suit the intended audience.
Short Bio
Troy Hunt is an Australian web security researcher and the Founder and CEO of Have I Been Pwned - the most trusted name in data breach intelligence. Launched in 2013, Have I Been Pwned now indexes tens of billions of breach records across more than 1,000 discrete breaches and serves 18 billion+ API requests every month. The service is relied upon by individuals, enterprises, over half the Fortune 500, and dozens of national governments. The FBI, NCA, and Europol regularly contribute compromised credentials from active investigations, and Have I Been Pwned is cited and recommended by cybersecurity agencies worldwide, including CISA, NIST, and the NCSC. Troy has testified before the United States Congress, is a Microsoft Regional Director, and writes at troyhunt.com from his home on the Gold Coast, Australia.
The Longer, More Personal Version
Background
Troy Hunt began building software for the web in 1995, working across various roles in Australia and the UK. In 2001 he joined Pfizer in Sydney, spending 14 years building and managing software, first as a developer, then as an Architect responsible for software delivery across Asia Pacific, covering systems for clinical trials, patient safety reporting, and sales force operations. He left Pfizer in 2015 to work independently, focusing primarily on information security and the continued growth of Have I Been Pwned.
Have I Been Pwned
In December 2013, Troy Hunt founded Have I Been Pwned, a free service that lets anyone check whether their email address or passwords have been exposed in a data breach. What started as a personal project has grown into the most trusted name in data breach intelligence: it now indexes tens of billions of breached records across more than 1,000 discrete incidents, covering more than 6 billion unique email addresses. More than 400,000 domains are actively monitored by over 200,000 organisations, including more than half of the Fortune 500. The service handles 18 billion+ API requests every month.
The Pwned Passwords service, which allows anyone to check whether a password has appeared in known breach data, is free and open source, with both the data and client code published on GitHub. It is embedded into password managers, authentication systems, and security products used by hundreds of millions of people worldwide.
HIBP has become an essential service that has helped shape the internet as we know it.
Government and Law Enforcement
The FBI, NCA, and Europol regularly contribute compromised credentials discovered during active cybercrime investigations to the Have I Been Pwned dataset. When the FBI dismantled the darknet marketplace Genesis Market in 2023, they directed victims to Have I Been Pwned to check their exposure. Have I Been Pwned is cited and recommended by national cybersecurity agencies across more than 20 countries, including CISA, NIST, NCSC, ASD, ICO, BSI, CERT-FR, and many more.
In November 2017, Troy testified before the United States House Committee on Energy and Commerce on identity verification in a post-breach world.
Today, dozens of national governments rely on the service to provide them insights into the impact of data breaches on their departments.
Media
Troy regularly appears in print, broadcast, and online media discussing cybersecurity, data breaches, and privacy. His work has been covered by the BBC, CNN, The Guardian, Forbes, WIRED, TIME, Ars Technica, TechCrunch, and most major publications covering technology and security. He is a regular contributor and commentator on Australian broadcast media. A comprehensive list of media appearances is on his media page.
Microsoft Regional Director
Troy has held titles of recognition from Microsoft since 2011 and is currently a Microsoft Regional Director. The RD title is bestowed upon "the world's top technology visionaries for their proven cross-platform technical expertise, community leadership, and commitment to business results", and recognises his commitment to cross-platform technical expertise and community leadership.
Advisory Roles
Troy has previously held advisory and insider roles with organisations including Microsoft, 1Password, NordVPN, Lenovo, and Ubiquiti. He is currently an advisor to Report URI, a security policy violation monitoring service.
Training and Speaking
Troy speaks at security conferences around the world and runs workshops for enterprises, banks, and government agencies on building more secure software.
Pluralsight
Troy has published more than 100 hours of online security courses on Pluralsight, covering topics ranging from OWASP Top 10 to HTTPS, ethical hacking, and browser security.
Personal
Troy lives on the Gold Coast, Australia, with his wife Charlotte (who serves as COO of Have I Been Pwned), and their two teenage kids.
Photos











