Password Security
How to Check If My Password Was Exposed
A password found in known exposure data should usually be treated as unsafe, especially if you still use it. Learn how password exposure happens and how to protect every account where the password may have been reused.
What does an exposed password mean?
A password is considered exposed when password-related information becomes available outside the system where it was supposed to remain protected.
That can happen after a data breach, account compromise, malware infection, phishing attack, or other security incident.
The important distinction is between:
They are not the same thing.
A password can appear in known exposure data even when nobody successfully logged into your current account.
But once a password is no longer secret, you should no longer rely on it.
This is especially important if you reused it.
NIST's current digital identity guidance emphasizes the importance of distinct passwords because attackers can try credentials compromised on one service against accounts on other services.
Why reused passwords are particularly dangerous
Imagine that you created the same password for an old shopping account, your email, a streaming service, and another website.
Years later, the shopping account experiences a security incident.
Even if your email provider itself was never breached, the password you used for your email may now be known because you reused it somewhere else.
An attacker can attempt that combination on other services.
This kind of activity is one reason using a unique password for each important account matters.
A password manager can make this practical.
NIST recommends password managers because they can create and store strong, unique credentials so that people do not have to memorize a different password for every service.
How to check if my password was exposed safely
Password checking requires more caution than checking an email address.
Your current password is an authentication secret.
Treat it differently from ordinary identifying information.
Before entering a password into any checker, understand how the service handles it.
Do not provide your password:
A safe password-exposure system should minimize how much information needs to leave your device and should not require you to publicly reveal the password.
If you are unsure whether a website can be trusted, do not enter the password.
Instead, assume a password you strongly suspect has been exposed should be changed.
Changing a compromised password is usually more valuable than proving with absolute certainty where it came from.
- In a public forum
- In a social media post
- In an email to someone offering help
- To an unknown support account
- In response to an unexpected text
- On an unfamiliar website with no clear privacy explanation
What should I do if my password was exposed?
If a password you currently use is known or strongly suspected to be exposed, replace it.
Do not wait for evidence that someone successfully logged into your account.
Change the exposed password.
Create a new credential that is not a variation of the old one.
Avoid transformations such as:
becoming:
The goal is a new, unrelated credential.
NIST recommends long passwords when passwords are necessary and recommends using a password manager to generate and manage them.
Change it everywhere you reused it.
This step is critical.
If the exposed password was used on five different accounts, changing only one leaves the other four vulnerable.
Then continue through less important accounts.
Turn on multifactor authentication.
After changing the password, enable MFA.
CISA recommends MFA because it adds another verification requirement beyond the password. If someone obtains the password, they may still be unable to complete the additional authentication step.
Where supported, passkeys are another strong option.
NIST describes passkeys as an authentication method that can reduce reliance on passwords and provide stronger resistance to phishing.
- Your primary email
- Banking and financial accounts
- Cloud storage
- Social accounts
- Shopping accounts with stored payment information
- Work or business accounts
Check whether someone actually accessed the account
A password exposure does not automatically mean account takeover occurred.
Look for evidence.
If you find an unfamiliar session, sign it out.
If the service supports signing out every other session, consider doing so after changing your password.
The FTC recommends changing the password, signing out of devices, turning on two-factor authentication, and verifying recovery information after recovering a compromised account.
- Recent login history
- Devices currently signed in
- Active browser sessions
- Security alerts
- Recovery-email changes
- Recovery-phone changes
- Connected apps
- Sent messages
- Account settings
Check identifiers connected to your accounts
Checking an email address or username can help identify exposures associated with accounts where a password may also require attention.
What if I changed the password years ago?
An old exposed password may no longer create an immediate login risk if:
Even so, an old exposure can still teach you something important.
If you recognize that password as one you reused widely, check whether any forgotten accounts still use it.
Old accounts are easy to overlook.
Your current email might have a strong unique password while an old shopping account, forum account, or subscription still uses a credential that was exposed years ago.
- You stopped using it
- You replaced it with a unique password
- You did not reuse it elsewhere
What if my password was exposed but my email was not?
That is possible.
Password exposures and identifier searches do not always produce identical results.
A password could become known through several routes, and not every dataset or security incident contains the same fields.
The safest approach is not to treat a negative email search as proof that a password is safe.
If you know or reasonably suspect a password is compromised, replace it.
What if my password is not found?
A checker can only evaluate the information available to it.
The password could have been obtained through:
So the safest interpretation is:
rather than:
- An undisclosed breach
- Phishing
- Malware
- A compromised device
- An account that is not represented in the data being searched
- Another method entirely
Protect your email account first
If you need to prioritize, protect your primary email account.
Email frequently serves as the recovery channel for other services.
Someone with access to your inbox may be able to initiate password resets elsewhere.
The FTC specifically highlights this risk when explaining why securing an email account is so important.
Your email account should ideally have:
- A unique password
- MFA or a passkey
- Correct recovery information
- Login alerts
- No unfamiliar active sessions
- No unauthorized forwarding rules
Be careful with “your password was leaked” messages
Scammers know that breach warnings create urgency.
You might receive a message saying:
Your password has been compromised. Click here immediately.
Do not assume the message is genuine.
The FTC advises consumers who receive suspicious messages to contact the organization through a website or phone number they know is legitimate rather than relying on links contained in the message.
- Do not use the link in the message.
- Open the official app or type the service's address yourself.
- Sign in normally.
- Check the account's security area.
- Change the password through the official service if necessary.
Practical password-exposure checklist
If you think a password may have been exposed:
- [ ] Stop using the affected password
- [ ] Change it on the affected account
- [ ] Find every other account where it was reused
- [ ] Replace those passwords too
- [ ] Use unique passwords going forward
- [ ] Store them in a password manager
- [ ] Enable MFA
- [ ] Use passkeys when supported
- [ ] Review active sessions
- [ ] Remove unfamiliar devices
- [ ] Verify recovery email addresses and phone numbers
- [ ] Enable login and security alerts
- [ ] Protect your primary email account first
- [ ] Avoid links in unsolicited security messages
Frequently asked questions
Should I change a password if it was exposed?
Yes, if you still use it. You should also change it on every other account where the same password was reused.
Does an exposed password mean someone hacked my account?
No. Exposure means the password may no longer be secret. Account compromise requires someone to actually gain unauthorized access.
Is it safe to type my password into a breach checker?
Only use systems whose privacy and security practices you understand and trust. Never provide your password to unknown sites, people, messages, or support accounts simply to check whether it was leaked.
What password should I use after a breach?
Use a new, unique credential that is unrelated to the exposed password. A password manager can generate and store unique passwords for you.
Should I enable two-factor authentication after a password leak?
Yes. MFA adds another authentication requirement and can help protect an account even if someone obtains its password.
Is a password manager safer than reusing passwords?
Using a reputable password manager allows you to maintain different passwords across accounts without memorizing all of them. NIST recommends password managers as part of modern password security practices.
What if a checker says my password was never exposed?
Treat that as “no known exposure found,” not proof that the password is completely safe. Continue using unique credentials and additional authentication.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
