Skip to main content
FixMyTech

How to Check If Your Password Has Been Leaked

By

Published

7 min read

Share

Short answer

Open your browser's built-in check — Chrome: Settings → Autofill and passwords → Google Password Manager → Checkup; Safari's is under Passwords → Security Recommendations. Both compare saved passwords against known breaches privately. Fix reused passwords first, then leaked ones, then weak ones, and start with your email account.

On this page

Nearly everyone has at least one leaked password, and most people do not know which. The tooling to find out is already installed on your devices, requires no subscription, and takes about two minutes to run.

The useful part is not the list. It is knowing which items on that list to act on first, because the report conflates three different problems — leaked, reused and weak — and only one of them is an emergency.

Run the check that is already there

Both major browsers compare every saved password against known breach data using a method that never transmits the password itself.

Chrome and Edge. Settings → Autofill and passwords → Google Password Manager → Checkup. It reports compromised, reused and weak passwords separately, with a direct link to change each one.

Safari. Settings → Passwords → Security Recommendations on both macOS and iOS. Same categories, slightly different names.

Firefox. Firefox Monitor, reachable from the password manager, covers breach exposure for saved logins.

Any password you can type. The password search at Have I Been Pwned checks one password at a time. It uses a method where only the first five characters of a hash leave your browser, and the service returns a block of candidates your device compares locally — the site never learns your password. That design is why this specific tool is trustworthy and why a site asking for your email and password together is not.

Your email address. The main breach search at the same site lists which services exposed you and what categories of data were involved. What to do if your email was in a data breach covers how to read that list.

Fix things in this order

The checkup will probably return an uncomfortable number. Work through it by priority rather than top to bottom, because the categories are not equally urgent.

Finding Urgency Why
Reused on your email account First Email resets everything else
Leaked, on an account with money or data First Directly exploitable
Reused across several accounts High One breach becomes many
Leaked, on a dormant account Moderate Fix or close it
Weak but not leaked Low Fix opportunistically
Flagged on a site that no longer exists None Ignore

Reuse is the real problem, more than leakage. A leaked password on a single account affects one account. A reused password turns one breach into every service where you used it, through automated attempts across hundreds of sites. That is the mechanism, and it is why the reused list deserves your attention before the leaked list.

Start with your email account, always. It holds the reset link for everything else you own.

Change them properly

Generate, do not invent. Use the browser’s or password manager’s generator. Human-chosen passwords cluster around predictable patterns, and the substitutions people believe are clever — zero for O, 3 for E, a year on the end — are the first things guessing tools try.

Length beats complexity. A long passphrase of unrelated words outperforms a short string of symbols, and you can type it on a television remote. Where a site imposes a short maximum length, that tells you something unflattering about how it stores passwords.

Do not reuse a variation. Summer2025! becoming Summer2026! is not a change. Tools apply those permutations automatically.

Turn on two-factor authentication while you are in the settings. You are already there, and it is worth more than the password change you came for. An app-based code or a passkey is stronger than SMS, though SMS is considerably better than nothing.

Consider passkeys where offered. They replace the password with a key stored on your device, bound to the real site’s domain. There is nothing to leak in a breach and nothing to type into a fake page, which removes two whole categories of this problem.

The password manager question

If the checkup produced a long list, the underlying problem is that you are remembering passwords, which caps you at a handful of real ones.

A password manager removes that cap. Unique random passwords everywhere means a breach at one service exposes one account. It also fills credentials only on the matching domain, which quietly checks for phishing every time you sign in — land on a lookalike site and the password simply is not offered.

The browser’s built-in manager is free, syncs across your devices, and is a large improvement over memory. Dedicated managers add cross-browser support, secure sharing and better recovery options. Either beats what most people do now, and arguing about which is better is a good way to avoid adopting one at all.

One warning: do not store your email password only inside a manager that requires email access to recover. Keep the master password and your email recovery route accessible by other means, written down somewhere physically safe if necessary. A password manager you cannot get into is a very effective denial of service against yourself.

What not to bother with

  • Routine password changes on a schedule. Current guidance from the NCSC and others advises against it, because it drives people to predictable variations. Change on evidence.
  • Password-strength meters on signup forms. They measure character variety, not whether the password has already leaked. A meter saying “strong” tells you nothing about a password that appears in a breach list.
  • Writing a formula instead of a password. [sitename]+[fixed string] is reconstructible from a single breach.
  • Security questions answered truthfully. Your mother’s maiden name is findable. Store invented answers in the manager.
  • Paying for breach monitoring when your browser does it and Have I Been Pwned emails you free.

Realistic expectations

A first run of the checkup typically surfaces a long list, much of it on accounts you had forgotten. That is normal rather than alarming, and most of it is low priority.

Set a realistic scope: your email account, anything holding money, and anything holding documents or photographs. Fix those properly, with unique passwords and two-factor authentication, and the rest can be dealt with as you happen to sign in to each service. Perfect coverage is not the goal. The goal is that the next breach notification is something you read and ignore.

Frequently asked questions

Is it safe to type my password into a checking website?
Only into a service that uses a privacy-preserving method. Have I Been Pwned's password check sends a short partial hash rather than your password, so the site never sees it. Any site asking for your plain password alongside your email address should be avoided.
My password shows as leaked but I have never used that site. How?
The check matches the password itself, not the account. A common password appears in breaches because thousands of other people chose it too, which is itself the reason to change it.
Does changing one character fix a leaked password?
Not meaningfully. Password-guessing tools apply exactly those variations as standard, so appending a digit or a year to a known password buys you very little. Generate a new one instead.
Should I change passwords regularly even without a breach?
Current guidance from bodies including the NCSC advises against forced routine changes, because they push people towards predictable variations. Change on evidence of compromise, and otherwise focus on uniqueness and two-factor authentication.
Can I check passwords I do not have saved in a browser?
Yes, through Have I Been Pwned's password search, which checks a single password without seeing it. For an email address, the main breach search tells you which services exposed you.

All Security guides