Account security
What To Do If I Reused a Password
Reuse turns one exposure into many logins. This guide shows the order to replace secrets and how to keep the next leak from opening the rest of your life.
Why reuse is the real emergency
Attackers try an exposed secret on mail, banks, and app stores because people repeat themselves. The Federal Trade Commission has warned that a reused password can turn a breach at one company into trouble at another. A slight edit does not break the pattern. Housecat2024! and Housecat2025! are the same idea. Generate a new random string or a long unique passphrase for each site. CISA’s household advice is the same pairing: long unique passwords and a manager so you do not have to memorize them.
Which accounts to fix first
What to do if I reused a password is an order-of-operations problem.
Close accounts you no longer use, through the official settings page, instead of leaving an old reused secret sitting there. If you cannot remember every site, start with the ones that can move money or recover other logins. Add the rest as you sign in over the next week.
- The email address that receives resets
- Apple, Google, or Microsoft accounts that hold the phone
- Banks, brokerages, payroll, and tax logins
- The password manager itself
- Shopping sites that store cards
- Social accounts that can impersonate you to family
How to change them without getting phished
Type the official domain. Do not use a “reset all your reused passwords” link from unexpected mail. On each site:
The FTC’s account-protection pages treat a strong unique secret plus two-factor authentication as the baseline, not as extras.
- Create a unique password with a manager or the browser generator
- Turn on MFA or a passkey
- Sign out other sessions
- Check recovery phone and email
After the urgent replacements
Watch the inbox for reset mail you did not request. Review login activity on official security pages. If a session looks wrong, treat it as a takeover, not only reuse. If identity data may also have been exposed, pull reports at AnnualCreditReport.com and consider a freeze. Reused passwords and a leaked Social Security number are different doors. Close both if both are open. Do not send the old password to anyone who offers to “check where else it was used.” A checker should take an email or identifier, not the secret.
Build a setup that makes reuse hard
Reuse feels efficient until the first notice. Unique secrets feel like work until the second site stays closed. Knowing what to do if I reused a password is useful once. Letting a manager issue the next fifty passwords is what keeps you from needing this article again.
- One password manager or a built-in generator
- Autofill only after you look at the address bar
- Passkeys on sites that offer them
- A household rule: no shared Netflix-style password on a bank
Practical checklist
- Assume every copy of the old phrase is unsafe.
- Change email first, then money accounts.
- Use a new random password each time.
- Enable MFA or a passkey.
- Sign out unknown sessions.
- Close dead accounts on official pages.
- Store new secrets in a manager.
- Review credit if identity data may also be involved.
Frequently asked questions
How many sites do I have to change?
Every site that used the same secret, with priority on email and money. If you are unsure, change the important ones today and the rest as you log in.
Can I keep the old password on a throwaway forum?
You can, but that forum can still be the source of the next reuse attempt. Unique is simpler than deciding which sites “do not matter.”
Does MFA mean reuse is safe?
No. MFA helps if the second factor holds. Unique passwords still stop the first guess.
What should I do first?
Use the official account or service website, change affected credentials, review recent activity, and enable multifactor authentication where available.
Can a clean check guarantee that I am safe?
No. A clean result only means the available sources did not show a match. Continue using unique credentials and account security alerts.
Should I enter my password into a checker?
No. Use an identifier such as an email address or username, and never share a password or authentication code with an untrusted checker.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
