Skip to content
All guides

Password Security

What to Do If You Shared a Password by Text Message

A password shared by text should be treated as no longer private, especially for important accounts. This guide explains how to change it, check account access, and use safer sharing options.

By the 4safer teamUpdated August 29, 20268 minutes read

Change the password if the account matters

If you shared a password by text message, treat that password as no longer fully private. Change it on the account, change it anywhere else it was reused, and use a unique replacement. This is especially important for email, banking, cloud storage, work tools, phone carrier accounts, and social media.

Text messages can be seen on lock screens, synced devices, backups, shared tablets, compromised phones, or by the recipient later. Even if the person is trusted, the password itself has left your control.

Do not ask the recipient to text it back or forward codes. Replace the credential instead.

Why texting passwords is unsafe

Passwords are meant to be secrets used only for sign-in. Texting turns the secret into a stored message. That message may remain searchable long after you forgot about it.

NIST recommends password managers for creating and storing unique passwords. Many password managers also offer safer sharing features that can be revoked.

If the password was reused, the risk is broader than the one account you meant to share.

  • Messages can be backed up.
  • Notifications may show previews.
  • Shared devices may sync texts.
  • Recipients may forward messages.
  • Phones can be lost or stolen.
  • The same password may protect other accounts.

Check exposure by account identifier

Check the email or username tied to the account if you want exposure context. Do not enter the shared password into an exposure checker.

A clean result does not guarantee safety. It only means no known match was found in searched sources.

Replace the password and sign out sessions

Change the password from the official account site. Then sign out other sessions if available, especially if the recipient no longer needs access.

If this is a shared service, create separate profiles or accounts if the platform supports it.

Change reused passwords

If the texted password was used anywhere else, change those accounts too. Start with email, banking, payments, cloud storage, phone carrier, and work accounts.

Use a password manager to generate unique replacements.

Turn on MFA

CISA recommends MFA because it helps protect accounts when passwords are exposed. Enable it on important accounts after changing the password.

Do not share one-time MFA codes by text. Codes are temporary secrets.

Use safer sharing next time

When sharing is legitimate, use built-in account sharing, family plans, delegated access, or password manager sharing that can be revoked. Avoid sending raw passwords by text or email.

For business accounts, each person should have their own account where possible.

Watch for suspicious activity

Review recent logins, devices, recovery settings, and account alerts. If anything changed without permission, use the provider's official recovery process.

If financial harm occurs, use official reporting channels.

Frequently asked questions

Is texting a password always dangerous?

It increases risk because the password becomes stored and shareable. Change it if the account matters.

Can I ask the person to delete the text?

You can, but deletion is not reliable across backups and synced devices. Change the password instead.

Should I text a one-time code?

No. Never share one-time codes by text, phone, email, or chat.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.