Troy Hunt
Troy Hunt is the cybersecurity expert behind Have I Been Pwned, helping organisations and governments understand and respond to modern data breaches.
Troy Hunt is the cybersecurity expert behind Have I Been Pwned, helping organisations and governments understand and respond to modern data breaches.
Troy Hunt is a globally respected cybersecurity expert, software developer, and founder of the data breach notification platform Have I Been Pwned. With decades of experience in software development, enterprise systems, and information security, he helps organisations understand the real impact of data breaches and how to defend against them. Troy has delivered workshops and keynotes around the world for banks, governments, and technology companies. His work has shaped how organisations and individuals approach password security, breach awareness, and online safety in an increasingly connected world.
Troy Hunt is a cybersecurity expert, software developer, and founder of the globally recognised breach notification platform Have I Been Pwned. Through his work, he has helped organisations, governments, and individuals understand the scale and consequences of data breaches and the importance of stronger digital security.
Troy’s career in technology began in 1995, when he started building software for the web. Over the years, he held multiple technical roles across Australia and the United Kingdom, gaining deep experience in software development and enterprise systems.
In 2001, Troy joined Pfizer in Sydney, where he spent the next fourteen years building and managing software systems within one of the world’s largest healthcare companies. During his time there, he worked first as a software developer and later as an architect responsible for software delivery across the Asia-Pacific region. His work included systems used to manage clinical trials, report patient adverse events, and optimise sales force operations.
This experience gave him a strong understanding of large-scale systems, security challenges, and the importance of protecting sensitive information in complex environments.
In 2013, Troy founded the data breach search and notification service Have I Been Pwned (HIBP). The platform allows individuals and organisations to check whether their data has been exposed in known breaches and receive notifications when new breaches occur.
Since its creation, HIBP has grown into one of the most widely recognised cybersecurity resources on the internet. The service now includes hundreds of data breaches containing many billions of records and is used daily by hundreds of thousands of people worldwide.
One of its most impactful tools is the Pwned Passwords service, which helps organisations prevent users from choosing passwords that have already been exposed in breaches. The service is used more than two billion times every month to help block compromised passwords from being reused.
Today, dozens of national governments rely on the platform to better understand the impact of data breaches across their departments. Through HIBP, Troy has played a significant role in improving awareness around password security and online safety.
Since leaving Pfizer in 2015, Troy Hunt has focused primarily on information security. As an independent expert, he has delivered workshops and presentations for organisations around the world.
He has published dozens of online courses on Pluralsight and created additional training content for technology companies. His educational work focuses on developer security, secure coding practices, and understanding the evolving landscape of cyber threats.
Troy has also delivered more than one hundred workshops globally for organisations including banks, government agencies, and e-commerce companies. Alongside this, he regularly speaks at international conferences and cybersecurity events where he shares practical insights into data breaches, identity protection, and real-world security challenges.
Many of these public presentations have been recorded and continue to be used as educational resources for developers, security professionals, and technology leaders.
Through his work with Have I Been Pwned and his role as a speaker and trainer, Troy regularly collaborates with governments and law enforcement agencies around the world.
Organisations such as the FBI and the UK’s National Crime Agency provide compromised passwords discovered during investigations to help strengthen the Pwned Passwords service. These contributions help organisations identify weak credentials and improve security across digital platforms.
Troy also speaks at internal cybersecurity events for law enforcement agencies and has testified before the United States Congress on identity verification in a post-breach world. His work and the HIBP platform are frequently referenced and recommended by national cybersecurity centres internationally.
Troy Hunt is a widely recognised voice in cybersecurity and frequently contributes to discussions about data breaches, online privacy, and digital identity. His work has been featured across global media including CNN, BBC, TIME, WIRED, and many other major publications.
His expertise has also been recognised by Microsoft through two honorary titles. Since 2011, he has been a Microsoft Most Valuable Professional (MVP), focusing on developer security and related technologies. In 2016, he was also named a Microsoft Regional Director, a title awarded to technology experts recognised for their cross-platform technical expertise, community leadership, and ability to deliver business impact.
Alongside his public work, Troy serves as a strategic advisor to security companies. Since 2020, he has been a Strategic Advisor for NordVPN and has also served on the Board of Advisors for 1Password.
As a keynote speaker, Troy Hunt brings real-world cybersecurity insights drawn from decades of hands-on experience in software development, enterprise systems, and breach analysis.
His presentations help audiences understand how data breaches occur, why password security matters, and what organisations can do to better protect their systems and users. Drawing on stories from the billions of records indexed by Have I Been Pwned and his work with governments and law enforcement, Troy provides a rare perspective on how cyber threats evolve and how organisations can respond.
Based on the Gold Coast in Australia, Troy lives with his wife and two children and continues to work globally with organisations that want to better understand and improve cybersecurity in an increasingly connected world.
Keynote by Troy Hunt:
What really happens when data breaches occur and why do they keep happening?
In this keynote, Troy Hunt takes audiences behind the scenes of the modern cybersecurity landscape, drawing on years of first-hand experience investigating data breaches, analysing compromised passwords, and working closely with organisations, governments, and law enforcement agencies around the world.
As the founder of the widely used breach notification service Have I Been Pwned, Troy has seen the patterns, mistakes, and vulnerabilities that repeatedly lead to large-scale security incidents. Through real-world stories and practical examples, he explores how passwords are compromised, how attackers exploit weaknesses, and why many breaches are still preventable.
This keynote is highly adaptable and typically shaped in collaboration with the organisation hosting the event. Troy works with clients in advance to tailor the content to the audience, industry, and current challenges they face. Topics may include password security, breach awareness, identity protection, developer security practices, and the evolving threat landscape.
Audiences leave with a clearer understanding of how breaches happen, why security often fails in predictable ways, and what organisations and individuals can do to reduce risk in an increasingly connected world.