How to Check If Your Password Has Been Leaked
Short answer
Open your browser's built-in check — Chrome: Settings → Autofill and passwords → Google Password Manager → Checkup; Safari's is under Passwords → Security Recommendations. Both compare saved passwords against known breaches privately. Fix reused passwords first, then leaked ones, then weak ones, and start with your email account.
On this page
Nearly everyone has at least one leaked password, and most people do not know which. The tooling to find out is already installed on your devices, requires no subscription, and takes about two minutes to run.
The useful part is not the list. It is knowing which items on that list to act on first, because the report conflates three different problems — leaked, reused and weak — and only one of them is an emergency.
Run the check that is already there
Both major browsers compare every saved password against known breach data using a method that never transmits the password itself.
Chrome and Edge. Settings → Autofill and passwords → Google Password Manager → Checkup. It reports compromised, reused and weak passwords separately, with a direct link to change each one.
Safari. Settings → Passwords → Security Recommendations on both macOS and iOS. Same categories, slightly different names.
Firefox. Firefox Monitor, reachable from the password manager, covers breach exposure for saved logins.
Any password you can type. The password search at Have I Been Pwned checks one password at a time. It uses a method where only the first five characters of a hash leave your browser, and the service returns a block of candidates your device compares locally — the site never learns your password. That design is why this specific tool is trustworthy and why a site asking for your email and password together is not.
Your email address. The main breach search at the same site lists which services exposed you and what categories of data were involved. What to do if your email was in a data breach covers how to read that list.
Fix things in this order
The checkup will probably return an uncomfortable number. Work through it by priority rather than top to bottom, because the categories are not equally urgent.
| Finding | Urgency | Why |
|---|---|---|
| Reused on your email account | First | Email resets everything else |
| Leaked, on an account with money or data | First | Directly exploitable |
| Reused across several accounts | High | One breach becomes many |
| Leaked, on a dormant account | Moderate | Fix or close it |
| Weak but not leaked | Low | Fix opportunistically |
| Flagged on a site that no longer exists | None | Ignore |
Reuse is the real problem, more than leakage. A leaked password on a single account affects one account. A reused password turns one breach into every service where you used it, through automated attempts across hundreds of sites. That is the mechanism, and it is why the reused list deserves your attention before the leaked list.
Start with your email account, always. It holds the reset link for everything else you own.
Change them properly
Generate, do not invent. Use the browser’s or password manager’s generator. Human-chosen passwords cluster around predictable patterns, and the substitutions people believe are clever — zero for O, 3 for E, a year on the end — are the first things guessing tools try.
Length beats complexity. A long passphrase of unrelated words outperforms a short string of symbols, and you can type it on a television remote. Where a site imposes a short maximum length, that tells you something unflattering about how it stores passwords.
Do not reuse a variation. Summer2025! becoming Summer2026! is not a
change. Tools apply those permutations automatically.
Turn on two-factor authentication while you are in the settings. You are already there, and it is worth more than the password change you came for. An app-based code or a passkey is stronger than SMS, though SMS is considerably better than nothing.
Consider passkeys where offered. They replace the password with a key stored on your device, bound to the real site’s domain. There is nothing to leak in a breach and nothing to type into a fake page, which removes two whole categories of this problem.
The password manager question
If the checkup produced a long list, the underlying problem is that you are remembering passwords, which caps you at a handful of real ones.
A password manager removes that cap. Unique random passwords everywhere means a breach at one service exposes one account. It also fills credentials only on the matching domain, which quietly checks for phishing every time you sign in — land on a lookalike site and the password simply is not offered.
The browser’s built-in manager is free, syncs across your devices, and is a large improvement over memory. Dedicated managers add cross-browser support, secure sharing and better recovery options. Either beats what most people do now, and arguing about which is better is a good way to avoid adopting one at all.
One warning: do not store your email password only inside a manager that requires email access to recover. Keep the master password and your email recovery route accessible by other means, written down somewhere physically safe if necessary. A password manager you cannot get into is a very effective denial of service against yourself.
What not to bother with
- Routine password changes on a schedule. Current guidance from the NCSC and others advises against it, because it drives people to predictable variations. Change on evidence.
- Password-strength meters on signup forms. They measure character variety, not whether the password has already leaked. A meter saying “strong” tells you nothing about a password that appears in a breach list.
- Writing a formula instead of a password.
[sitename]+[fixed string]is reconstructible from a single breach. - Security questions answered truthfully. Your mother’s maiden name is findable. Store invented answers in the manager.
- Paying for breach monitoring when your browser does it and Have I Been Pwned emails you free.
Realistic expectations
A first run of the checkup typically surfaces a long list, much of it on accounts you had forgotten. That is normal rather than alarming, and most of it is low priority.
Set a realistic scope: your email account, anything holding money, and anything holding documents or photographs. Fix those properly, with unique passwords and two-factor authentication, and the rest can be dealt with as you happen to sign in to each service. Perfect coverage is not the goal. The goal is that the next breach notification is something you read and ignore.