Password Security
Should I Change My Password After a Data Breach?
Change a password when the affected service used it, when you reused it elsewhere, or when exposure is suspected. Use a new unique password, enable MFA, and secure your email and financial accounts first.
When is a password change necessary?
Change the password if it was used on the affected service, appears in a known exposure, was reused elsewhere, or may have been entered into a phishing page. Do not wait for proof of successful access.
- Affected service
- Reused password
- Phishing disclosure
- Known exposure
Which accounts should come first?
Prioritize email, banking, payment, work, cloud-storage, and accounts that can reset other services. Then work through less critical accounts where the password was reused.
- Financial accounts
- Work accounts
- Recovery accounts
What makes a replacement strong?
Use a unique, long credential or a password manager-generated password. Do not make a predictable variation of the old password.
Change it through the official service
Type the service address yourself or use the official app. Avoid reset links from unexpected messages and confirm that the new password was saved.
- Use the official site.
- Avoid message links.
- Confirm the change.
Change every reused copy
One exposed password can create risk across several accounts. Replace it everywhere and do not reuse the new credential.
- List reused accounts.
- Change each copy.
- Do not reuse the replacement.
Enable MFA and review sessions
Enable multifactor authentication, sign out unknown sessions, and check recovery settings, forwarding rules, and connected apps.
- Enable MFA.
- Sign out unknown devices.
- Review recovery settings.
Use exposure results responsibly
A 4safer result can add context about known matches for an owned identifier. It cannot guarantee that a password is safe or prove that a breach caused a specific event.
Frequently asked questions
Do I need to change every password after one breach?
Change the affected password and every account where you reused it. Review other important accounts as a precaution.
Should I change passwords regularly even without a breach?
Change them when compromised, reused, or exposed, and use unique credentials with MFA rather than relying on needless routine changes.
Can I reuse a password after changing it?
No. Use a unique password for each important account.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
