Password Managers
What to Do If Your Password Manager Account Is Locked
A locked password manager account can be stressful because it may hold access to many services. This guide explains how to recover safely, avoid scams, and protect critical accounts while access is limited.
Use only official recovery
If your password manager account is locked, use the provider's official recovery process and do not share your master password, recovery key, backup code, or one-time code with anyone who contacts you. Avoid paid recovery strangers who claim they can unlock any account.
Lockouts can happen after too many failed attempts, missing MFA, a lost device, provider security controls, payment issues, or suspected account risk. The correct path depends on the provider.
Stay calm and protect your email first, because password manager recovery often depends on your email account.
Why lockouts are sensitive
Your password manager may store email, banking, cloud, work, social, and shopping credentials. A rushed response can create more risk if you reveal recovery information to a scammer.
NIST recommends password managers because they support unique passwords, but the master account becomes highly important. That account needs strong recovery planning.
If the lockout happened after suspicious prompts or alerts, treat it as a security event until you verify otherwise.
- Too many failed attempts.
- Lost MFA device.
- New device approval problem.
- Forgotten master password.
- Provider security lock.
- Suspicious account activity.
Do not expose secrets while troubleshooting
Do not send screenshots showing recovery keys, backup codes, passwords, or vault contents. Do not paste credentials into support chats unless you are using a verified official process and the provider specifically requires non-secret account information.
Support teams should not need your master password. If someone asks for it, stop.
Secure the recovery email
Open your recovery email from a trusted device. Change reused passwords, enable MFA, review sessions, and check recovery settings. If your email is compromised, password manager recovery becomes harder.
The FTC notes that email accounts are central because they receive reset links for other accounts.
Follow provider recovery steps
Use official recovery pages, trusted devices, backup codes, recovery keys, or emergency contacts depending on the provider. Requirements vary.
Keep notes about what steps you tried and when. Avoid repeated guessing that may extend lockouts.
Prioritize critical accounts during lockout
If you cannot access stored passwords quickly, focus on accounts where recovery is possible through official channels: email, banking, payments, cloud storage, phone carrier, work tools, and social media.
Use official forgot-password flows from trusted devices and set new unique passwords once the manager is available again.
Check whether exposure is involved
Check the email tied to the password manager for exposure signals. A match does not prove the manager was accessed, but it may explain suspicious attempts.
Do not enter the master password into an exposure checker.
Improve recovery after access is restored
After recovery, review MFA, backup codes, trusted devices, emergency access, and account email. Remove unknown sessions and update recovery methods.
Create a secure recovery plan before the next emergency.
Frequently asked questions
Can support recover my master password?
It depends on the provider, but many password managers cannot see or provide your master password. Use official recovery guidance.
Should I pay someone to unlock it?
Be very cautious. Use the provider's official support and do not share secret recovery information.
What should I secure first?
Secure the recovery email first, then critical financial, cloud, work, and communication accounts.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
