How to Change Every Important Password in the Right Order
Short answer
Change them in dependency order: your main email first, then your phone carrier account, then your password manager, then financial accounts, then everything else. Email comes first because whoever controls it can reset the rest. Changing a password does not end existing sessions everywhere, so check the device list afterwards.
On this page
There are two versions of this task and they are not the same job. One is routine tidying after a password manager flags a dozen reused logins. The other is damage control after an account has been compromised, where sequence and speed both matter.
Either way the order is the same, and getting it wrong has a specific consequence: change your password manager before your email and you can find yourself locked out of the vault holding the credentials for everything else.
Work out which job you are doing
| Situation | Scope | Urgency |
|---|---|---|
| A manager flagged reused passwords | The reused ones | Weeks, do it gradually |
| A service you use announced a breach | That one, plus anywhere reused | Today |
| An unfamiliar sign-in you cannot explain | Email first, then the critical list | Now |
| You typed a password into a suspicious page | That account and anything sharing it | Now |
| Nothing happened, general tidy-up | Reused and weak ones only | No rush |
If the top rows apply, work through the full sequence below in one sitting. If it is the bottom row, do not. Spreading it over a few weeks produces better passwords and far better record-keeping.
Before you start
Three things, all of which save time later.
Set up a password manager first, if you have not. Changing forty passwords without somewhere to put them means they end up as variations of each other, which defeats the point entirely. Whether a manager or your browser is the right choice covers that decision.
Check which passwords are actually exposed. Your manager or browser will check saved passwords against known breach data and flag the hits. That list is your priority queue, and it is usually shorter than you fear.
Make sure you can receive email and texts throughout. Most password changes send a confirmation somewhere, and discovering mid-sequence that your recovery address is an account you abandoned in 2019 is a bad time to find out.
The order
1. Your main email
First, always, and not negotiable. Email is the master key, because nearly every other account will send a reset link there, so an attacker with your inbox has your other accounts regardless of how strong their passwords are.
Change it, and while you are in the settings do three more things:
- Turn on a strong second factor if it is not on. Which type is safest explains the ranking.
- Check forwarding and filter rules. A rule quietly copying your mail elsewhere survives a password change and is a known persistence trick.
- Check the recovery email and phone. Changed recovery details are how someone gets back in after you have locked them out.
2. Your phone carrier account
The one almost nobody includes, and it sits this high because your phone number is a recovery route for a great many accounts. Someone who can move your number to their SIM receives every SMS code you have.
Change the password, and ask the carrier about a port-out PIN or number lock while you are there. That setting addresses SIM swapping at the layer where it actually happens.
3. Your password manager
Now, not earlier. Its master password should be long, memorable and used nowhere else — the passphrase method in creating passwords you can remember is designed for exactly this.
Generate fresh recovery codes for it and put them on paper, because this is the one account where a circular dependency leaves you with nothing.
4. Financial accounts
Banking, cards, PayPal and anything else holding money or a payment method. These generally have good fraud controls, so they are not top of the list, but they are where loss is immediate and concrete.
Check the registered contact details and any saved payees while you are in there.
5. Identity and cloud storage
Apple, Google and Microsoft accounts if they are not already covered as your email; cloud storage holding scanned documents; your tax or government portal. Anything where the contents could be used to impersonate you.
6. Social accounts
Your main one first, since it is the one used to impersonate you to people who know you. Check connected apps and any accounts you administer while you are there.
7. Everything else
Shopping, forums, streaming, newsletters. Do these at your own pace, prioritising anything with a saved card. Many can simply be deleted instead, which is both faster and better.
After each critical account, do the second half
A new password alone is not a completed change. On each of the first five accounts:
- Check active sessions and sign out what you do not recognise. A password change ends most other sessions on major providers, but not reliably all, and reviewing the device list is the step that confirms it.
- Revoke app-specific passwords. Google’s 16-character codes for legacy software bypass second factors by design and survive password changes.
- Review third-party app access. Those are separate tokens and are also unaffected by a new password.
- Save the new recovery codes. Where to keep them matters more than people think.
Step two and three are where persistent access hides. An account with a new password and an attacker’s app password still attached has not been secured.
Mistakes that make this worse
- Small edits to the old password. Adding a digit or changing a symbol keeps the pattern, and the pattern is what is exposed.
- One strong password everywhere. It is one breach from being the same problem at larger scale.
- Doing forty in one evening. Fatigue produces reused passwords, unsaved recovery codes, and the two accounts you later cannot recover.
- Changing passwords while the device is still compromised. If you suspect malware, deal with that first, or the new password is captured as you type it.
- Removing a second factor to make the process quicker. Several services impose a waiting period before it can be re-enabled.
Realistic expectations
The critical five take about an hour done properly, including the session and app-token checks. The long tail of shopping and forum accounts takes a few weeks of doing two or three whenever you happen to log in, which is the sustainable way.
The honest limit is that none of this helps if the original exposure is still present — malware on the laptop, a phone someone else has access to, or a recovery email you no longer control. Fix the cause first. A fresh password typed into a compromised machine lasts exactly as long as it takes to be captured.