Table of Contents
The safest way to check for a compromised password is to use the leak-monitoring feature built into your password manager or browser. It can compare saved credentials with known breach data and identify reused or weak passwords without asking you to paste a live password into an unknown website.

What a breach result actually means
- Email found in a breach: The address appeared in a known incident. Review which data types were exposed; this does not automatically prove that the current password was included.
- Password flagged as compromised: The saved credential matches known leaked data and should be replaced immediately.
- Password flagged as reused: The same secret protects more than one account, so one breach could expose the others.
- No result: No match was found in the service's available data. It is not proof that the account or device is secure.
Check saved passwords in your browser or device
Google Password Manager
Open Chrome's password manager or visit Google Password Manager while signed in, then run Password Checkup. Review compromised, reused, and weak-password categories. Change the password on the actual service before updating the saved entry.
Microsoft Edge
Open Settings > Passwords and autofill > Microsoft Password Manager > Password security check, then run a scan. Edge Password Monitor lists saved credentials that match known leaked data and links to the affected services.
Apple Passwords
Open the Passwords app on a current Apple device and review its security recommendations. It can flag passwords that are compromised, reused, or weak. On older system versions, equivalent recommendations may appear under Passwords in Settings or System Settings.
Check whether an email address appeared in a breach
Have I Been Pwned can check whether an email address appears in its catalog of known breaches and show which types of information were involved. Search only addresses you own or are authorized to monitor.
An email-address result and its Pwned Passwords database are separate: the service does not show which specific password belonged to an email address. Do not pay a third party that claims it can reveal someone else's current password from a breach.
Never paste a current password into a random checker
A site that asks for the exact password you still use could collect it. Prefer a reputable password manager's integrated check, and navigate to the service directly rather than through a link in an unexpected breach email. A legitimate alert should not ask you to send a password or one-time verification code.
What to do if a password is compromised
- On a trusted device, open the affected site's official app or type its address yourself.
- Change the password to a new, unique one generated by a password manager.
- Sign out other sessions and review recent logins, recovery addresses, forwarding rules, and connected apps.
- Change every other account that reused the same password. Prioritize the primary email account because it can reset other logins.
- Enable multi-factor authentication or a passkey and save recovery codes separately.
- If you entered the password on a suspicious page or ran an unknown file, scan the device and change the password from a clean device.
Use the current guide to creating strong, unique passwords, then choose a tool from the password manager overview. For supported Microsoft accounts and services, the Microsoft Authenticator guide explains two-factor verification.
When should you change a password?
Change it when there is evidence of exposure, reuse, accidental sharing, or suspicious account activity. Arbitrary periodic changes can encourage predictable variations and do not repair password reuse. A long, unique password stored in a manager can remain in place until there is a reason to replace it.
Reader Comments 0
Sign in with email or Google to join the discussion.