Password Security
What to Do If You Forgot Which Password Was Exposed
If you forgot which password was exposed, focus on account impact and reuse instead of trying to reconstruct the exact password. This guide explains how to prioritize changes, check exposure by identifier, and secure important accounts safely.
Do not try to prove the exact password first
If you forgot which password was exposed, do not type your current passwords into random websites to find out. Start by changing passwords on important accounts where reuse may have happened, especially email, banking, payment apps, cloud storage, phone carrier, password manager, and work accounts.
The exact exposed password matters less than whether any important account may still use it or a close variation. If you cannot remember, assume reuse is possible for accounts from the same period and replace those passwords with unique ones.
A clean exposure result for an email means no known match was found in the searched sources. It does not guarantee no password was ever exposed.
Build a realistic password history
Think in time periods instead of individual passwords. Many people reuse a password during a school period, job, address, relationship, device era, or hobby phase. Search your inbox for old signups and look at saved passwords in your password manager or browser.
Do not write the actual old password in a document. You only need enough context to decide which accounts may share the same pattern.
NIST recommends password managers because they make unique passwords practical. If you already use one, review reused or weak-password warnings there first.
- Accounts created around the same year.
- Old shopping and travel accounts.
- School, work, or forum accounts.
- Browser-saved logins.
- Password manager reuse warnings.
- Accounts tied to exposed email addresses.
Check identifiers, not secrets
Use exposure checks for emails or usernames you own or are authorized to manage. Do not check other people's identifiers without permission, and never enter current passwords, one-time codes, Social Security numbers, card numbers, passport numbers, or bank details.
If an email has exposure history, prioritize accounts using that email and any password pattern you remember using there. Treat the result as a risk signal, not absolute proof.
Change passwords in priority order
Start with accounts that can reset or unlock other accounts. Email should come first because password reset links often arrive there. Then move to money, private files, phone carrier access, and public reputation.
For each account, create a unique password and store it in a password manager.
- Primary email.
- Password manager.
- Banking and payment apps.
- Cloud storage.
- Phone carrier.
- Work or school tools.
- Social media and shopping.
Replace patterns, not just exact passwords
If you used variations of the same password, replace the whole family. Changing one number or symbol is not enough if the base pattern may be known.
Use unrelated generated passwords for each account.
Turn on MFA while changing passwords
CISA recommends multifactor authentication because it adds a second protection layer beyond the password. Enable MFA on important accounts before moving to low-risk services.
Prefer passkeys, security keys, or authenticator apps where available.
Review account activity
After changing passwords, check recent logins, active sessions, recovery email, recovery phone, connected apps, forwarding rules, and security alerts. Sign out of sessions you do not recognize.
A password change alone may not remove every access path.
Clean up old accounts
Forgotten accounts are where old passwords survive. Close unused accounts after removing payment methods and saving records.
Keep a simple list of which accounts have been updated so you do not repeat work or miss critical services.
Frequently asked questions
Should I enter old passwords into a breach checker?
No. Avoid entering current or remembered passwords into random checkers. If you suspect exposure, change the password.
What if I do not remember where I reused it?
Prioritize accounts by importance and by the time period when you likely used that password pattern.
Is changing my email password enough?
No. Also change reused passwords on other important accounts and turn on MFA.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
