Quick answer
Stop using the password everywhere.
Change it on the affected service and every other account where you reused it. Begin with your email and password manager if either is involved, sign out unknown sessions, verify recovery settings, enable stronger MFA, and monitor for follow-on phishing or fraud.
What a match means
A password match in Pwned Passwords means that value appears in a corpus built from real-world breach data. It does not necessarily identify which account used it, who exposed it, or whether someone has already accessed your accounts. It does mean the password is no longer suitable for use.
A “not found” result is not proof of safety. A password can be weak, phished, observed, reused, or present in data that is not in the corpus.
Respond in the right order
- Secure your email. Email commonly controls password resets for everything else.
- Change the affected account. Use the official app or manually entered domain on a trusted device.
- Replace every reused copy. Prioritize financial, identity, work, cloud, shopping, and social accounts.
- End active sessions. Remove unfamiliar devices, app passwords, tokens, and connected applications.
- Repair recovery. Confirm recovery email, phone, backup codes, and security keys.
- Enable phishing-resistant sign-in. Add a passkey or security key where supported.
Look beyond the password
An attacker may have changed forwarding rules, created API tokens, added a device, generated an app password, authorized a third-party application, or copied private data before you changed the credential. Review security history and settings instead of assuming the password change reversed everything.
Prepare for follow-on phishing
Breach notices create urgency, and criminals exploit it. They may send convincing messages that name the breached company or claim you must “verify” the account. Navigate directly to the company. Do not provide a password, MFA code, backup code, recovery key, or remote-device access to someone who contacts you.
If financial or identity data was involved
Password remediation is only one step. Review the company’s official notice to learn what data was exposed. Monitor relevant accounts and contact the appropriate financial institution or identity-protection authority when payment, tax, government ID, or other sensitive data is involved.
How the private check works
Our optional breach check follows the Pwned Passwords range API design. Your browser hashes the password locally and sends only the first five SHA-1 characters. The service returns matching suffixes, and your browser performs the final comparison. We do not receive the password, full hash, or result.
Prevent the next cascade
- Use a different generated password for every remaining password-based account
- Adopt passkeys where available
- Protect email and the password manager with strong MFA
- Keep recovery codes in a protected backup
- Review password-health and breach alerts periodically