Password Leak: How to Check and What to Do
Be the first to rate this page
A password leak alert means that a password connected to your email address turned up in data published from a breach of some company's systems. It is a warning about a password, not proof that your phone, computer, or any specific account has been broken into.
The leak almost always happened at a service you used, not on your device. That is why the fix is changing passwords rather than scanning your phone for viruses.
Why did my phone tell me my password was leaked?
Modern phones and browsers compare the passwords you have saved against published lists of leaked credentials. When one matches, they warn you. Apple, Google, and Microsoft all do some version of this in their built-in password managers.
The comparison is designed so your actual password is not sent anywhere in readable form. The alert is not evidence that the company running the check knows your password.
An alert can appear long after the breach itself, because leaked data sometimes circulates privately for years before it is published and indexed. An old password you stopped using may still trigger a warning.
How do I check whether my email and password were leaked?
Use the tools already on your devices first. They check the passwords you actually use, which a general lookup by email address cannot do.
- On iPhone or iPad, open Settings, go to the passwords section, and look for the security recommendations or compromised passwords list.
- On Android or in Chrome, open the password manager and run its password checkup.
- In other browsers, look for a password health, monitor, or safety check feature in settings.
- For your email address as a whole, use a reputable breach-notification service to see which known breaches included your address.
Never enter a current password into a site that offers to check it for you. A legitimate check either runs on your device or works from your email address alone. A page asking you to type a password to see if it leaked is collecting passwords.
Which accounts should I fix first after a password leak?
Do not start at the top of an alphabetical list. Work in this order, because the accounts differ enormously in what they protect.
- Your email account. Fix this first, always. Whoever controls your email can reset the password on nearly everything else.
- Your phone or computer account, meaning your Apple Account, Google Account, or Microsoft account, since they hold your saved passwords and your devices.
- Banking and payment accounts.
- Any account where you reused the leaked password, even on a site that seems unimportant.
- Shopping and delivery accounts, which usually store an address and a saved payment method.
Reuse is the real danger. A leak at a forum you forgot about matters only because the same password opens your email, and attackers try leaked pairs across popular services automatically.
How do I change a leaked password properly?
- Go to the service directly, through its app or by typing the address yourself. Do not use a link from the alert email.
- Sign in and find the security or password section of the account settings.
- Set a new password that you have never used anywhere else.
- Let your phone or browser generate and save it, so you never have to remember it.
- Turn on two-step verification for that account while you are in the settings.
- Check the account's list of active sessions or devices and sign out anything you do not recognize.
That last step is often skipped and often the one that matters. Changing a password does not always end a session someone else already has open.
Why does two-step verification matter more than the new password?
Two-step verification means an account needs a second proof beyond the password, such as a code from an app, a prompt on your phone, or a security key. With it turned on, a leaked password on its own is not enough to get in.
Prefer an authenticator app or a security key over codes sent by text where the service offers a choice, since text codes can be intercepted through phone number takeover.
Save the backup or recovery codes the service gives you when you turn it on, somewhere that is not the account you just protected. Losing access to your second step locks you out as effectively as losing the password.
What if someone already changed my password and I cannot get in?
Move fast, and start with the email account even if it is not the account you noticed the problem on.
- Use the account's own recovery process: forgotten password, then the verification options it offers.
- If the recovery email or phone number has been changed, look for the service's account recovery form for exactly this situation.
- Contact the service's support and state plainly that the account was taken over. That phrase routes you differently than a routine password reset.
- If money or payment details are involved, contact your bank or card issuer separately and immediately.
- Once you regain access, review the recovery email, recovery phone, forwarding rules, and connected apps, since attackers often change those to keep a way back in.
Mail forwarding rules are the most commonly missed item. An attacker can lose the password and still read your mail if a forwarding rule they created is left in place.
How do I stop getting the same password leak warning?
The warning repeats because the password is still in use somewhere, or still saved on your device. Clear both.
- Change it everywhere it was used, not just on the account named in the alert.
- Delete stale saved entries in your password manager for accounts you no longer use.
- Close accounts you have abandoned rather than leaving them with an old password.
- Where the service supports passkeys, which sign you in with your device instead of a password, switch to one and remove the password entirely.
What scams follow a password leak?
Leaked data gets used to make threats look credible. Expect emails quoting a real old password of yours and demanding payment, claiming to have recorded you. These messages are sent in bulk and the claim is false; the password came from a published breach.
Also expect fake alerts imitating the real ones, urging you to click a link and sign in to secure your account. Both are handled the same way: do not reply, do not pay, do not click. Go to the service yourself and change the password there.
Was this page helpful?
Be the first to rate this page