T

TechyLeakz

Latest Fixes

Fix Guide

How to Check if Your Password Was Leaked

Check if your email or passwords appeared in a data breach using Have I Been Pwned, Google Password Checkup, Apple Passwords and Edge, then secure any account that was exposed.

Direct answer

To check if your password was leaked, enter your email address at Have I Been Pwned to see which breaches included it, then run the built-in checker in your browser or password manager: Google Password Checkup in Chrome, Password Monitor in Microsoft Edge, Security recommendations in Apple Passwords, or Watchtower and similar reports in a dedicated manager. These compare your saved passwords against known breaches without revealing them. Change any flagged or reused password immediately, starting with email and banking, then turn on two-factor authentication or passkeys and review recent account activity.

Common causes

  • A website or app you use suffered a data breach, and your email address and password, or a crackable version of it, were stolen and later shared or sold.
  • You reused the same password on several sites, so a single breach lets attackers try it everywhere in automated credential-stuffing attacks.
  • You typed your password into a phishing page that imitated a real sign-in screen, often reached through an email, text message or search ad.
  • Info-stealing malware on your PC copied passwords saved in your browser, along with session cookies, and sent them to attackers.
  • An old account you forgot about was breached, exposing a password you may still be using somewhere else.
  • A short or common password was guessed outright or cracked from stolen password hashes, even without a direct leak of the plain text.
  • A public or shared computer, or a malicious browser extension, captured or saved your login details without you noticing.

Advertisement

Step-by-step fixes

Step 1

Check your email address on Have I Been Pwned

Go to haveibeenpwned.com in your browser, type your email address into the search box and press Enter. If the address appears in known breaches, you will see a list of affected services with the breach date and the types of data exposed, such as email addresses, passwords, phone numbers or physical addresses. Pay closest attention to any breach that lists passwords. If no breaches are found, you will see an all-clear message, which is good news but only covers breaches the site knows about. Repeat the search for every email address you have used, including old ones. Finally, use the Notify me option to get an email if your address shows up in future breaches. Success looks like a written list of services where you need to change passwords.

Step 2

Run Google Password Checkup in Chrome or your Google account

If you save passwords in Chrome, open the three-dot menu, choose Passwords and autofill > Google Password Manager, then select Checkup. You can also visit passwords.google.com and open Password Checkup from any browser while signed in to your Google account. Checkup lists compromised passwords found in known breaches, passwords you have reused, and weak passwords. Select a compromised entry and use the Change password option to jump to that site, or change it manually by typing the site address yourself. Chrome also warns you when you sign in with an exposed password, as long as Safe Browsing is turned on under Settings > Privacy and security > Security. Success looks like an empty or shrinking compromised list after you rerun Checkup.

Step 3

Use Microsoft Edge's password security check

If Microsoft Edge stores your passwords, open Settings and more (the three dots) > Settings > Passwords and autofill > Microsoft Password Manager. Select Password security check to see passwords that were found in leaks, reused across sites, or considered weak. Under More settings, make sure the option to scan passwords for leaks is switched on; this is the feature Microsoft calls Password Monitor, and it keeps checking in the background. Like Chrome's tool, it compares encrypted fragments of your passwords against known breach data rather than sending the passwords themselves. Work through each leaked entry, change the password on the website, and update the saved entry in Edge. Success looks like no remaining leaked passwords when you rerun the check.

Advertisement

Step 4

Review Apple Passwords security recommendations

On an iPhone or iPad running iOS 18 or later, open the Passwords app and tap Security. On iOS 17 or earlier, go to Settings > Passwords > Security Recommendations. On a Mac running macOS Sequoia or later, open the Passwords app and choose Security; on older versions, use System Settings > Passwords > Security Recommendations. Make sure Detect Compromised Passwords is turned on. The list shows passwords that appeared in leaks, reused passwords and weak ones, with the most urgent at the top. Tap an entry and use the option to change the password on the website, then accept the strong password Apple suggests. Because this syncs through iCloud Keychain, fixing an entry on one device updates it on all of them. Success looks like no high-priority recommendations left.

Step 5

Use your password manager's breach monitoring

If you use a dedicated password manager, it likely has its own breach checker that covers every item in your vault, including logins your browser never saw. In 1Password, open Watchtower to see compromised, vulnerable, reused and weak passwords, plus sites where you could add two-factor authentication or a passkey. Bitwarden's vault health reports show exposed, reused and weak passwords on paid plans. Dashlane, Keeper, NordPass and Proton Pass offer breach or dark web monitoring on various plans that alerts you when your email or details appear in new leaks. Turn on alerts so you are notified automatically instead of relying on memory. Success looks like a report with no exposed or reused passwords, and alerts enabled for the future.

Step 6

Change leaked and reused passwords, most important first

Now fix what you found, starting with the accounts that matter most: your primary email account, banking and payment services, your password manager, work accounts, social media, and shopping sites that store cards. Your email comes first because it can reset everything else. For each account, type the site address yourself or use a saved bookmark rather than clicking a link in an email. Replace the password with a long, random and unique one; a password manager generator makes this easy. Then change the password on every other site where you used the same or a similar password, because attackers automatically try leaked credentials on other services. Success looks like every flagged password replaced and no two accounts sharing a password.

Step 7

Turn on two-factor authentication or passkeys

A new password protects you until the next leak; two-factor authentication protects you even after one. In each important account's security settings, turn on two-step verification using an authenticator app, a hardware security key, or a passkey. Text-message codes are better than nothing, but they can be intercepted through SIM-swap attacks. Where a site supports passkeys, as major services such as Google, Microsoft, Apple and Amazon do, create one; a passkey cannot be phished or reused because there is no password to steal. Save the backup or recovery codes each service gives you in your password manager or somewhere safe offline. Success looks like being asked for a second factor the next time you sign in on a new device.

Step 8

Check account activity and scan your PC for malware

Finally, confirm nobody got in before you changed things. For Google, go to myaccount.google.com > Security and review Recent security activity and Your devices. For Microsoft, go to account.microsoft.com > Security and open Sign-in activity. Sign out any devices or sessions you do not recognize, remove unfamiliar third-party apps, and check that email forwarding, recovery phone numbers and saved payment details have not changed. If passwords keep leaking or you see new sign-ins after changing them, your PC may be infected. Open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. The PC restarts to scan, which takes a while. Success looks like no unknown activity and a clean scan.

How to prevent it

  • Use a unique, randomly generated password for every account, stored in a password manager, so one breach cannot unlock anything else.
  • Turn on two-factor authentication or passkeys for email, banking, shopping and social media accounts.
  • Leave breach alerts switched on in your browser or password manager, and sign up for Have I Been Pwned notifications.
  • Close or delete old accounts you no longer use so their passwords cannot leak in future breaches.
  • Never enter a password after clicking a link in an unexpected email or text; type the site address yourself.

Tools that can help

The free checkers in Chrome, Edge and Apple Passwords are enough for a one-time review. A dedicated password manager is worth it if you want every login monitored continuously, strong unique passwords created for you, and alerts when a new breach includes your details.

Top pick

1Password

A polished, end-to-end encrypted password manager with a device-generated Secret Key, Watchtower breach alerts, passkey support and easy family sharing across every major platform.

Try 1Password

Best free option

Bitwarden

An open-source, independently audited password manager whose free plan syncs unlimited passwords and passkeys across all your devices, with inexpensive Premium and Families upgrades.

Try Bitwarden

Best for breach alerts

Dashlane

A paid password manager with dark web monitoring, a password health score and smooth autofill, so you are alerted when your details appear in a new breach.

Visit Dashlane

TechyLeakz may earn a commission if you buy through these links, at no extra cost to you. Affiliate disclosure

What to do next if this fails

  • Move to the next fix instead of repeating the same step multiple times.
  • Check the related guides in this cluster before attempting a full reset.
  • If startup, update, and corruption symptoms overlap, widen the diagnosis instead of treating one error in isolation.

Advertisement

FAQ

Is it safe to type my email into Have I Been Pwned?

Yes. Have I Been Pwned is a long-running, widely trusted service created by security researcher Troy Hunt. Searching an email address only shows which known breaches included it; it does not reveal your password or any breached data. If you sign up for notifications, it emails you when that address appears in newly loaded breaches, which is a useful early warning.

Is it safe to enter my password on a breach-checking website?

Be careful. Have I Been Pwned's password search uses a technique called k-anonymity, so only a small fragment of your password's hash leaves your device, and the full password is never sent. Even so, it is safer to rely on the checker built into your browser or password manager, which works the same way and saves you from typing real passwords into any website.

My email was in a breach. Does that mean my account was hacked?

Not necessarily. It means your email address, and sometimes other data such as a password, was stolen from a service you used. Attackers may or may not have tried it against your other accounts. Check what data types the breach listed. If a password was included and you used it anywhere else, change it on every site where it was reused and review those accounts for unusual activity.

What should I do if my password was found in a breach?

Change that password on the affected site right away, then change it anywhere else you used the same or a similar password. Use a unique, randomly generated password for each account, ideally stored in a password manager. Turn on two-factor authentication or a passkey, sign out of unknown sessions, and check recent activity, saved payment details and email forwarding settings for changes you did not make.

How often should I check for leaked passwords?

Turn on automatic monitoring so you do not have to remember. Chrome, Edge, Apple Passwords and most password managers check your saved logins continuously and alert you when a match appears, and Have I Been Pwned can email you about new breaches. A manual review every few months is still worthwhile, especially after news of a large breach at a service you use.

Why is my password flagged as compromised when I never got a breach alert?

Checkers compare your password against huge lists of passwords exposed in any breach, not just breaches of your own accounts. If someone else used the same password on a breached site, it will be flagged because attackers try those known passwords first. A flag means the password is unsafe to use anywhere, even if your own account was never directly breached.

TechyLeakz

Search-first tech publishing focused on fixes, comparisons, and software recommendations.