Password Hacked or Leaked? What to Do, Step by Step
Password hacked or found in a data breach? Change it everywhere it was used, starting with email, then move to a password manager, passkeys and two-step verification.
If your password was hacked or leaked, change it immediately on the account it belongs to and on every other account where you used the same or a similar password, starting with your email. Then turn on two-step verification, sign out of other sessions, and check the account for changes. Going forward, a password manager, unique passwords and passkeys stop one leak from turning into many.
A leaked password is rarely a disaster on its own. The danger is reuse: criminals take email and password pairs from one breach and try them on email, banking, shopping and social accounts. Acting quickly and in the right order closes that door.
How you usually find out a password leaked
- A password manager alert. Google Password Manager (in Chrome and Android) and Apple’s Passwords app and iCloud Keychain can warn you when a saved password appears in a known data leak. Look for their security or password checkup section.
- A breach notification service. Have I Been Pwned lets you check whether your email appears in known breaches and sign up for alerts. Our Have I Been Pwned guide explains how to use it, and our guide to a dark web scan explains what paid monitoring alerts can and can’t tell you.
- A company’s breach notice. Businesses that suffer a breach often email affected customers.
- Suspicious activity. Login alerts, codes you didn’t request, or changes to an account.
- An extortion email quoting an old password. These are usually bluffs built from breach data. See our guide to the “you’ve been hacked” email scam.
A warning that a password was “found in a data leak” means it’s on a list criminals can access. It doesn’t mean anyone has used it yet, but assume someone will.
Leaked, reused or actually hacked?
| Situation | What it means | What to do |
|---|---|---|
| Password appears in a breach alert | The password is exposed; the account may be fine | Change it, plus anywhere it was reused |
| Login codes or alerts you didn’t trigger | Someone has the password and is trying to sign in | Change it now, turn on two-step verification, sign out other sessions |
| You can’t sign in, or details changed | The account has been taken over | Use the platform’s official recovery route; see the account hacked guides |
| You typed the password into a fake page | Phishing; the attacker has it fresh | Change it immediately and check for changes |
What to do if your password was hacked or leaked
- Secure your email first. Change your main email password to a new, unique one and turn on two-step verification. Email is where every other reset link goes, so it comes before anything else.
- Change the leaked password on the affected account. Go there directly by typing the address or using the app, never through a link in an alert email.
- Find everywhere you reused it. Include close variations, like the same word with a different number at the end. Attackers try those too. A password manager’s security check can list duplicates for you.
- Change each reused password to a unique one, prioritizing banking, payment apps, shopping sites with saved cards, your phone carrier, cloud storage and social media. If a streaming account was taken over, our guide to a hacked Netflix account covers the account-specific steps.
- Turn on two-step verification on each important account, preferring an authenticator app, passkey or security key over text messages.
- Sign out of other sessions and devices from each account’s security settings.
- Check for changes: recovery emails and phone numbers, forwarding rules, connected apps, saved payment methods and recent orders.
- Update security questions if they were stored with the leaked data. You can use made-up answers saved in your password manager.
If any account has already been taken over, the my account was hacked checklist links to official recovery guides for each major platform.
Use a password manager so it can’t happen twice
People reuse passwords because remembering dozens of unique ones is impossible. A password manager solves that: it creates long random passwords, stores them encrypted and fills them in for you, so you only remember one strong master password.
- Built-in options: Google Password Manager and Apple Passwords are free and already on many devices, and both check for leaked and reused passwords.
- Standalone managers work across different browsers and operating systems, which suits people who mix, say, an iPhone with a Windows laptop.
- Protect the manager itself with a long passphrase and two-step verification. It holds the keys to everything.
A password manager also helps against phishing, because it won’t autofill your password on a fake site with a different address. If it doesn’t offer to fill, stop and check where you are.
Switch to passkeys where you can
Passkeys replace passwords with a cryptographic key stored on your device or in your password manager, unlocked with your fingerprint, face or device PIN. There’s no password to leak in a breach and nothing for you to type into a fake page, because a passkey only works on the real site it was created for.
Many major services, including Google, Apple, Microsoft, Amazon and PayPal, now support passkeys. Look for a passkeys option in each account’s security settings and set one up on your most important accounts first. Keep a backup sign-in method, such as a second device or recovery codes, in case you lose your phone.
A worked example
This is an illustrative scenario, not a real client. Marcus gets a Chrome warning that a password saved for an old hobby forum was found in a data leak. He shrugs, since he hasn’t used the forum in years. Then he remembers it’s the same password he uses for his email and his online store account.
He changes his email password first and turns on app-based two-step verification. He checks the email’s recent sign-in activity, which looks clean, and removes an old app password he’d forgotten. Next he runs the password checkup in his password manager, which lists eleven accounts sharing variations of the same password. He changes the four that involve money or email resets that evening and the rest over the weekend.
Finally, he sets up passkeys on his Google and Amazon accounts and deletes his forum account entirely, so it can’t be part of the next breach.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditWhen a leaked password affects more than one account
Sometimes the leak reveals more than a password: your address, date of birth, phone number or even ID documents. If so, watch for follow-up risks.
- Targeted phishing that uses your real details to seem convincing.
- Identity theft, if your Social Security number or ID was exposed. Consider a credit freeze; our guide on ways to prevent identity theft explains how.
- SIM swap attempts, where someone uses your details to move your number to their phone. Add a PIN or port-out protection with your carrier.
- Account takeovers used to post in your name, which can affect your reputation. Our personal reputation management team can help if damaging content ends up associated with you.
Common mistakes to avoid
- Changing only the account that was breached. Reuse is the real risk.
- Adding a number or symbol to the old password. Attackers try predictable variations.
- Clicking the link in a breach email. Some “your password was leaked” messages are phishing. Go to the site yourself.
- Relying only on text message codes for your most important accounts, when an app, passkey or security key is available.
- Storing passwords in a notes app or spreadsheet. Use a proper password manager.
- Ignoring old accounts. Delete accounts you no longer use so they can’t leak again.
Frequently asked questions
What should I do if my password was hacked?
Change it on that account and everywhere else you used it, starting with your email. Turn on two-step verification, sign out of other sessions and check each account for changed recovery details, forwarding rules or new payment methods.
How do I know if my password was leaked?
Check your email address on a breach notification service such as Have I Been Pwned, and look at the password checkup in Google Password Manager or Apple’s Passwords app, which flag saved passwords found in known leaks.
Does a leaked password mean I've been hacked?
Not necessarily. It means the password is exposed and could be used. If you change it, and anywhere it was reused, before anyone signs in, the account may never be touched.
Are passkeys safer than passwords?
For most people, yes. A passkey can’t be leaked in a website breach or typed into a phishing page, because it stays on your device and only works with the real site. Keep a backup sign-in method in case you lose your device.
Is it safe to use a password manager?
A reputable password manager, protected by a strong master password and two-step verification, is far safer than reusing passwords. It encrypts your passwords and helps you spot fake sites by refusing to autofill on them.