Password security guide

How to change a password safely

Use the service’s official security settings, create a completely new credential, review active sessions, and protect the recovery path.

Quick answer

Change it from the official account settings.

On a trusted device, navigate directly to the provider’s website or app, open its security settings, and replace the old password with a new unique one from your password manager. Then sign out unfamiliar sessions, verify recovery details, and enable stronger MFA.

Change versus reset

A password change normally means you can still sign in and know the current credential. A reset uses a recovery channel because you forgot the password or lost access. Recovery links and codes are high-value targets, so start from the service’s official app or a manually entered domain—not a link in an unexpected email or text.

When a change is warranted

  • The service reports a breach or suspicious sign-in
  • The credential appears in known breach data
  • You reused it on another exposed account
  • Someone else knew, received, or saw it
  • It is short, predictable, or based on personal information
  • Your device or password manager may have been compromised

Current NIST guidance does not recommend arbitrary periodic changes without evidence of compromise. Forced schedules often lead people to make predictable changes. Replace a password when there is a reason, and make the replacement meaningfully different.

The safe sequence

  1. Use a trusted device and network. If malware is suspected, clean or replace the device first.
  2. Go directly to the provider. Use a saved bookmark, official app, or manually typed address.
  3. Generate a new unique value. Do not append a number or recycle part of the old password.
  4. Update the password manager. Confirm the new entry saved and that autofill points to the correct domain.
  5. Review sessions and devices. Sign out anything unfamiliar and use “sign out everywhere” after compromise when available.
  6. Protect recovery and MFA. Confirm your recovery email and phone, regenerate backup codes if needed, and prefer phishing-resistant authentication.

Change the most important accounts first

If a reused password is exposed, begin with the email account that receives your recovery links. Then secure banking, identity, password-manager, work, cloud-storage, and social accounts. An attacker who controls your email can often reset other services even after you change those passwords.

What if you cannot sign in?

Use the provider’s official recovery process. Avoid third parties offering paid “password recovery,” and never give anyone an MFA code, backup code, recovery key, or remote access to your device. If the account belongs to an employer, school, or client, contact its authorized administrator rather than bypassing policy.

After the change

Watch for new login alerts, forwarding rules, connected applications, changed recovery methods, and transactions you do not recognize. Changing the password blocks one path; it does not automatically undo actions an attacker already took.

If the old credential was reused, use your password manager’s duplicate-password report or make a written account list that does not contain the passwords themselves. Replace every reused instance.

Primary sources