LankyBox01 Well, that's not the case. Password checking isn't completed with the actual password itself, but rather the stored hash version of it. If there is a hash match at https://haveibeenpwned.com for example, then despite the passwords not being the same, all an attacker needs to do is pass the hash itself and will be able to login as you.
Just because your password is not there is a misconception.