Question & answer

How do you know if your password has been leaked?

The short answer

Check your email address on haveibeenpwned.com, the free standard for breach data, or use the built-in breach scanner in your password manager. If a password appears in a leak, change it immediately at that service and everywhere you reused it.

Data breaches happen daily, and you usually notice nothing until it is too late. The site haveibeenpwned.com collects verified breaches and lets you look up, for free, which ones include your email address. You can also subscribe to alerts for new breaches; it costs nothing and is among the most useful five minutes of security work there is.

Modern password managers build that check in and go further: they continuously compare all your stored passwords against known leaks and warn you per password. NordPass calls it the data breach scanner, Dashlane even monitors the dark web, and Bitwarden, 1Password, and Proton Pass report leaked and reused passwords in their vault health overviews.

If you get a hit: do not panic, act. Change the password at the affected service, check where else you used the same one (the manager shows you), and enable two-factor authentication where possible. After that, you are better protected than before the leak.

Relevant to this question

Our picks
Dashlane logoDashlane
Dashlane Inc.
Dashlane

Dashlane Inc.

Top picks4.3
From $4.99/moView
Free
Bitwarden logoBitwarden
Bitwarden Inc.
Best free option
Bitwarden

Bitwarden Inc.

Free & open source4.7
FreeView