Troy Hunt is looking for a buyer for Have I Been Pwned to help keep up with the exploding growth of the archive of breaches and take it to the next level
Context & Ripple Effects
By mid-2019 Have I Been Pwned had stopped being a side project: its breach-search API was already wired into password managers and browsers through the 1Password Watchtower integration and the Firefox Monitor trial, yet the entire operation still ran on one person — Troy Hunt, founder and sole employee. His announcement that he wants a buyer is framed explicitly around scale: the breach archive keeps growing faster than a solo operator can absorb.
What came after in the coverage sharpens the picture of why a buyer mattered. A year later Hunt was still running it alone and talking publicly about revenue streams, his own discomfort with holding breached data, and being breached himself (his TechCrunch interview as sole employee) — before choosing to open-source the codebase and take compromised-password data directly from the FBI instead of selling.
First-order effects
- Hunt, as the site's only employee, is directly constrained by archive growth: finding a buyer is his proposed fix for storage, ingestion, and notification workload he cannot staff alone.
- Downstream integrators — 1Password's Watchtower and Mozilla's Firefox Monitor — face continuity risk, since their breach-lookup features ride on infrastructure maintained by a single person.
Second-order effects
- Any acquirer would be buying distribution, not just a database: an embedded position inside password managers and browser monitors that already query the service daily.
- Opening the codebase lowers the technical due-diligence barrier for prospective buyers while also reducing dependence on any single owner — a hedge that partially substitutes for a sale if none materializes.
Third-order effects
- Breach notification is drifting from a volunteer-run public good toward institutionalized infrastructure — backed by corporate ownership, open governance, or official data feeds like the FBI's password-sharing arrangement — with whoever funds the archive gaining leverage over the security-notification layer.
- If solo-maintained critical services keep outgrowing their founders, expect more quasi-exits where maintainers seek owners or open governance rather than shutting down or charging users directly.
The trend: Critical security infrastructure built by individuals is being forced toward institutional homes — through acquisition, open source, or government partnership — because breach archives grow faster than any lone operator can sustain.