Interview with Troy Hunt, founder and sole employee of Have I Been Pwned, on his reluctance to retain breached data, future revenue streams, being pwned himself
Zack Whittaker / TechCrunch : Tweets: @swiftonsecurity , @troyhunt , and @zackwhittaker Tweets: @swiftonsecurity : Great new article on the reticulating splines of @haveibeenpwned and its singular owner @troyhunt, which by all signals is on track to become even more integrated with global commerce and security https://twitter.com/... Troy Hunt / @troyhunt : This is a great piece by @zackwhittaker, it gives some real insight into what it's taken to run @haveibeenpwned, especially in more recent times during the M&A process (and some insights into what that was like) https://twitter.com/... Zack Whittaker / @zackwhittaker : New: @haveibeenpwned has become the go-to site to see if you were affected by a data breach. Now at almost 10 billion breached records, I spoke to its founder, @troyhunt, about what it means to be the site's one and only decision maker. https://techcrunch.com/...
Context & Ripple Effects
The interview lands a year after Hunt first put Have I Been Pwned up for sale, citing an archive approaching 10 billion breached records that had outgrown a one-person operation. What he reveals here is that the buyer process ran its course as a real M&A effort — and that he is still the sole employee weighing how the service sustains itself through new revenue streams while staying reluctant to hold onto breached data.
First-order effects
- Hunt's own admission that he has been pwned underscores the operational reality: a single person is curating nearly 10 billion records of other people's worst security moments, with the M&A path explored in the TechCrunch interview leaving ownership and funding unresolved rather than solved by acquisition.
Second-order effects
- Every enterprise and consumer who checks credentials against Have I Been Pwned carries key-person risk — if Hunt steps back without a buyer, password-checking integrations lose their data source, which is precisely the gap his subsequent move to open-source the code base addresses.
Third-order effects
- If the pattern holds — solo stewardship, failed M&A, then open sourcing culminating in the FBI feeding compromised passwords into the site per the ZDNet report — breach-notification infrastructure shifts from a founder-owned business into shared public utility territory, governed by transparency rather than ownership.
The trend: Breach-notification services are evolving from founder-run commercial projects into openly licensed, institutionally supplied security infrastructure.