---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure and enable Have I Been Pwned integration

# Configure and enable Have I Been Pwned integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure API credentials and enrichment behavior through the dedicated Have I Been Pwned (HIBP) configuration tile in TISC integration settings.

## Before you begin

Role required: sn_sec_tisc.admin
Prerequisites  
* The Have I Been Pwned integration depends on the Threat Intelligence Security Center (TISC) application. To enrich email and domain observables, verify that the TISC plugin (`sn_sec_tisc`) is installed.
* Obtain a valid API key from the Have I Been Pwned portal before you begin.
{#tisc-config-hipw-integration__ul_tf4_kzf_k3c}

## About this task

The HIBP integration is an observable enrichment integration that determines whether a submitted email address or domain name has been part of a publicly known data breach.

When an analyst submits a supported observable, the integration queries the HIBP database and returns breach details, including the total number of breaches found and the type of data compromised.  
The integration supports the following observable types:

* Email address
* Domain name
{#tisc-config-hipw-integration__ul_g14_rzf_k3c}  
Note:  
Before you begin, [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterEnrichment IntegrationsAll IntegrationsObservable Enrichment.
2. Select Configure New Enrichment.
3. Select the integration.  
   For example, Have I Been Pwned to configure the HIBP integration.
4. Fill in the fields on the Configure New Enrichment form.  
   {#tisc-config-hipw-integration__table_iqf_n4p_tzb__entry__2}

   | Field | Description |
   |-|-|
   | Enrichment Integration ||
   | Name | Name for the new enrichment integration. For example, Have I Been Pwned. |
   | Integration Category | Integration category that you selected. |
   | Vendor Name | Name of the vendor. The details of the selected vendor is populated by default. For example, Have I Been Pwned. |
   | Integration Type | Type of integration that you selected. |
   | Description | Description for the new enrichment integration. |
   | Integration Configuration ||
   | API Key | API key that you obtained from the Have I Been Pwned site. |
   [Table 1. Enrichment Integration]

   {#tisc-config-hipw-integration__table_iqf_n4p_tzb}
5. Navigate to the Integration Configuration section.
6. Enter (or paste) the API Key you acquired from the Have I Been Pwned site.
7. Select Save.  
   The integration details are validated, and by default the Have I Been Pwned integration status is set to inactive.
8. Select Enable to enable the Have I Been Pwned integration.  
   Important:  
   Only one Have I Been Pwned integration card can exist per instance. Attempting to create a second card results in an error.
{#tisc-config-hipw-integration__steps_rbj_3bz_5zb}

## Result

After configuration, you can select Have I Been Pwned for performing enrichment on observables in Threat Intelligence Security Center.

## What to do next

To run observable enrichment, see [Run Have I Been Pwned enrichment integration](https://servicenow-prod.fluidtopics.net/2XvUvqcpnmWSyrsY6kPWng "Run the Have I Been Pwned (HIBP) enrichment on an email address or domain name observable to determine whether it has been involved in a known data breach.") for the detailed procedure.

*[\>]: and then


