Skip to main content
FixMyTech

How to Change Every Important Password in the Right Order

By

Published

8 min read

Share

Short answer

Change them in dependency order: your main email first, then your phone carrier account, then your password manager, then financial accounts, then everything else. Email comes first because whoever controls it can reset the rest. Changing a password does not end existing sessions everywhere, so check the device list afterwards.

On this page

There are two versions of this task and they are not the same job. One is routine tidying after a password manager flags a dozen reused logins. The other is damage control after an account has been compromised, where sequence and speed both matter.

Either way the order is the same, and getting it wrong has a specific consequence: change your password manager before your email and you can find yourself locked out of the vault holding the credentials for everything else.

Work out which job you are doing

Situation Scope Urgency
A manager flagged reused passwords The reused ones Weeks, do it gradually
A service you use announced a breach That one, plus anywhere reused Today
An unfamiliar sign-in you cannot explain Email first, then the critical list Now
You typed a password into a suspicious page That account and anything sharing it Now
Nothing happened, general tidy-up Reused and weak ones only No rush

If the top rows apply, work through the full sequence below in one sitting. If it is the bottom row, do not. Spreading it over a few weeks produces better passwords and far better record-keeping.

Before you start

Three things, all of which save time later.

Set up a password manager first, if you have not. Changing forty passwords without somewhere to put them means they end up as variations of each other, which defeats the point entirely. Whether a manager or your browser is the right choice covers that decision.

Check which passwords are actually exposed. Your manager or browser will check saved passwords against known breach data and flag the hits. That list is your priority queue, and it is usually shorter than you fear.

Make sure you can receive email and texts throughout. Most password changes send a confirmation somewhere, and discovering mid-sequence that your recovery address is an account you abandoned in 2019 is a bad time to find out.

The order

1. Your main email

First, always, and not negotiable. Email is the master key, because nearly every other account will send a reset link there, so an attacker with your inbox has your other accounts regardless of how strong their passwords are.

Change it, and while you are in the settings do three more things:

  • Turn on a strong second factor if it is not on. Which type is safest explains the ranking.
  • Check forwarding and filter rules. A rule quietly copying your mail elsewhere survives a password change and is a known persistence trick.
  • Check the recovery email and phone. Changed recovery details are how someone gets back in after you have locked them out.

2. Your phone carrier account

The one almost nobody includes, and it sits this high because your phone number is a recovery route for a great many accounts. Someone who can move your number to their SIM receives every SMS code you have.

Change the password, and ask the carrier about a port-out PIN or number lock while you are there. That setting addresses SIM swapping at the layer where it actually happens.

3. Your password manager

Now, not earlier. Its master password should be long, memorable and used nowhere else — the passphrase method in creating passwords you can remember is designed for exactly this.

Generate fresh recovery codes for it and put them on paper, because this is the one account where a circular dependency leaves you with nothing.

4. Financial accounts

Banking, cards, PayPal and anything else holding money or a payment method. These generally have good fraud controls, so they are not top of the list, but they are where loss is immediate and concrete.

Check the registered contact details and any saved payees while you are in there.

5. Identity and cloud storage

Apple, Google and Microsoft accounts if they are not already covered as your email; cloud storage holding scanned documents; your tax or government portal. Anything where the contents could be used to impersonate you.

6. Social accounts

Your main one first, since it is the one used to impersonate you to people who know you. Check connected apps and any accounts you administer while you are there.

7. Everything else

Shopping, forums, streaming, newsletters. Do these at your own pace, prioritising anything with a saved card. Many can simply be deleted instead, which is both faster and better.

After each critical account, do the second half

A new password alone is not a completed change. On each of the first five accounts:

  1. Check active sessions and sign out what you do not recognise. A password change ends most other sessions on major providers, but not reliably all, and reviewing the device list is the step that confirms it.
  2. Revoke app-specific passwords. Google’s 16-character codes for legacy software bypass second factors by design and survive password changes.
  3. Review third-party app access. Those are separate tokens and are also unaffected by a new password.
  4. Save the new recovery codes. Where to keep them matters more than people think.

Step two and three are where persistent access hides. An account with a new password and an attacker’s app password still attached has not been secured.

Mistakes that make this worse

  • Small edits to the old password. Adding a digit or changing a symbol keeps the pattern, and the pattern is what is exposed.
  • One strong password everywhere. It is one breach from being the same problem at larger scale.
  • Doing forty in one evening. Fatigue produces reused passwords, unsaved recovery codes, and the two accounts you later cannot recover.
  • Changing passwords while the device is still compromised. If you suspect malware, deal with that first, or the new password is captured as you type it.
  • Removing a second factor to make the process quicker. Several services impose a waiting period before it can be re-enabled.

Realistic expectations

The critical five take about an hour done properly, including the session and app-token checks. The long tail of shopping and forum accounts takes a few weeks of doing two or three whenever you happen to log in, which is the sustainable way.

The honest limit is that none of this helps if the original exposure is still present — malware on the laptop, a phone someone else has access to, or a recovery email you no longer control. Fix the cause first. A fresh password typed into a compromised machine lasts exactly as long as it takes to be captured.

Frequently asked questions

Do I really need to change every password?
Only if they are reused, exposed in a breach, or you have reason to think someone has them. Changing a strong unique password for no reason achieves nothing and usually produces a weaker one, because people make predictable small edits to what they had.
How do I know which of my passwords have been exposed?
Every major password manager and browser now checks your saved passwords against known breach data and flags the matches. Have I Been Pwned does the same for an email address. That list is your priority queue.
Should I change passwords after a company announces a breach?
Change the one for that service immediately, and change it anywhere else you used the same password. The second part matters more than the first, because credential stuffing against other sites is what actually follows a breach.
Why does changing my password not log out the attacker?
Because sessions and passwords are tracked separately. Most providers end other sessions on a password change, but not all do reliably, and app-specific passwords and third-party authorisations are unaffected entirely. Those need revoking separately.
How long should this take?
Budget an hour for the critical accounts and do the rest over a few weeks. Attempting forty logins in one evening is how people end up with recovery codes unsaved and two accounts they cannot get back into.

All Accounts guides