Online Security

Signs Your Password Has Been Compromised and What to Do Next

Laptop screen showing a security alert with a padlock and warning symbol

Key Takeaways

  • Unexpected login alerts and unfamiliar account activity are the clearest signs of a compromised password.
  • Data breach notification services can tell you if your credentials have appeared in a known leak.
  • Changing your password immediately and enabling two-factor authentication limits the damage quickly.
  • Reusing passwords across accounts turns one breach into many — each account needs a unique credential.
  • A password manager makes creating and storing strong, unique passwords straightforward.
15–45 min
Beginner

What you will need

Access to the email address associated with your accounts
Ability to log in to the accounts you want to check
A secondary device or phone number for two-factor authentication setup

Why Compromised Passwords Are So Consequential

A stolen password is rarely an isolated problem. Because many people reuse credentials across multiple services, one breach can cascade into unauthorized access across banking, email, and social accounts simultaneously. Email accounts are especially high-value targets — whoever controls your email can trigger password resets on almost everything else you own.

Understanding how attackers actually steal passwords — through phishing, data breaches, and credential stuffing — makes the response steps below easier to understand and motivating to follow. If you also notice unusual behavior on your device itself, it's worth checking signs your device may have been compromised, since device-level compromise and account compromise sometimes occur together.

What you will need

Access to the email address associated with your accounts
Ability to log in to the accounts you want to check
A secondary device or phone number for two-factor authentication setup

Step-by-Step: What to Do When You Suspect a Breach

The steps below walk you through identifying, containing, and recovering from a compromised password. Work through them in order — the first actions you take will have the greatest impact on limiting damage.

1

Recognize the warning signs

Several indicators suggest a password may no longer be yours alone:

  • Login notifications you didn't trigger — emails or SMS alerts about sign-ins from unfamiliar devices or locations.
  • Password reset emails you didn't request — someone may be attempting to lock you out.
  • Unfamiliar activity inside an account — sent messages you didn't write, purchases you didn't make, or profile changes you didn't authorize.
  • Sudden inability to log in — your credentials have been changed by someone else.
  • A data breach notification — from a service you use, alerting you that account data was exposed.

For a broader look at account-level red flags, see warning signs your account has been targeted by phishing.

2

Check whether your credentials appear in a breach

Visit Have I Been Pwned (haveibeenpwned.com) and enter your email address. The service cross-references your address against a database of publicly disclosed breaches and tells you which ones — if any — included your data.

If a breach is listed, note which service was involved and what data was exposed (passwords, phone numbers, etc.). This helps you prioritize which accounts to address first.

[tool_cards]
Tip: You can also monitor your email address automatically by registering for breach alerts on the same site — you'll receive a notification whenever your address appears in a new leaked dataset.
3

Change the compromised password immediately

Log in to the affected account and navigate to its security or password settings. Create a new password that is:

  • At least 14 characters long
  • A random mix of uppercase and lowercase letters, numbers, and symbols
  • Completely unique — not used on any other account

If you cannot log in because your credentials were already changed, use the platform's account recovery option (typically triggered by your registered email address).

Tip: Use your password manager's built-in generator rather than inventing a password yourself. Random machine-generated passwords are far harder to crack than human-chosen ones.
4

Update any accounts that shared the same password

If you reused the compromised password elsewhere — even with minor variations — change those passwords too. Attackers routinely run credential stuffing attacks, automatically trying stolen username-and-password pairs across hundreds of other sites.

To understand exactly how these attacks work, see how attackers actually steal passwords. Prioritize accounts with the most sensitive data: email, banking, healthcare, and anywhere you shop or store payment details.

5

Enable two-factor authentication (2FA)

Two-factor authentication (2FA) requires a second proof of identity — typically a code sent by SMS or generated by an authenticator app — in addition to your password. Even if your password is stolen again, 2FA prevents an attacker from completing a login without that second factor.

Enable 2FA on every account that supports it, starting with email and financial accounts. Authenticator apps (which generate codes locally on your device) are generally more secure than SMS-based codes.

[important_callout]
6

Review account activity and revoke unfamiliar sessions

Most platforms provide a list of active sessions or recent login history under security settings. Review this list and sign out any sessions you don't recognize. Also check for:

  • Unfamiliar third-party apps connected to your account
  • Changes to recovery email addresses or phone numbers
  • Forwarding rules in email that could be redirecting your messages

Revoking access cuts off anyone currently inside your account, even if they already knew your password.

[warning_callout]

Set Up Login Alerts on All Key Accounts

Most major platforms let you enable notifications for new sign-ins via email or SMS. Turning these on means you'll be alerted the moment someone accesses your account from an unrecognized device or location — giving you an early-warning system at no extra cost.

Once you've secured your immediate situation, consider running a full password health audit across all your accounts. It's the most reliable way to find weak or reused passwords before an attacker does.

Building Habits That Prevent the Next Compromise

Responding well after a breach matters — but reducing the chances of it happening again matters more. A few durable habits cover most of the risk:

  • Use a password manager to generate and store a unique password for every account. You only need to remember one strong master password.
  • Never reuse passwords, even across accounts you consider low-importance. Attackers don't discriminate.
  • Check for breaches periodically using a service like Have I Been Pwned, especially after news of large-scale data leaks.
  • Keep recovery information current — an outdated recovery email or phone number can lock you out of your own account during a crisis.

For readers who want to go further, the Scams and Phishing hub covers the social engineering tactics attackers use to trick users into handing over credentials directly — knowledge that makes you significantly harder to deceive.

Online Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Online Security Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.