Password security guide

What to Do If Your Password Is Compromised

Use a trusted device, secure the account and its recovery channels, then replace every reused or derived credential.

Immediate response checklist

  1. Open the service from a trusted bookmark or typed address, not a warning-message link.
  2. Change the password to a unique generated value.
  3. Sign out other sessions and remove unknown devices.
  4. Review MFA, recovery email, phone and backup codes.
  5. Check account activity and connected applications.
  6. Replace the same or related password everywhere else.

Secure email and the password manager first

Primary email can reset many other accounts, and the password manager may contain all credentials. If either is involved, secure it before lower-value services. Verify forwarding rules, recovery addresses, app passwords and active sessions.

If the password was entered on a phishing page

Assume the attacker received it immediately. Change it on the legitimate service, revoke sessions and check MFA changes. If you approved a login prompt or entered a one-time code, report that too. Remove unknown OAuth or connected-app grants.

If malware may be present

Changing a password on the same compromised device can expose the replacement. Disconnect or stop sensitive use, update and scan the device, and use a known-clean device for account recovery. For a managed work device, contact the responsible security team.

Review financial and personal consequences

Check purchases, messages, profile changes and data exports. Contact the service or financial provider through official channels when unauthorized activity appears. Preserve relevant notices and timestamps without storing the compromised password in incident notes.

Monitor after recovery

Watch for reset emails, new-device alerts and unexpected MFA prompts. An attacker may retain access through a session, app token or mailbox rule even after the password changes. Review again after the immediate incident.

Replace exposed authentication factors

If an attacker received a one-time code, approved push, backup code or session, changing only the password may not remove access. Revoke sessions, remove unknown authenticators, replace backup codes and enroll a safe second factor. Follow the method checklist in the two-factor authentication guide.

Different exposure types require different actions

A breach notice may mean password hashes were taken, not that every plaintext password is known. A phishing submission should be treated as immediate disclosure. Malware can capture the replacement. An accidental message exposes the value to its recipients and any retained copies. Match the response to the most serious plausible path.

When facts are uncertain, use a trusted device, rotate the credential, revoke sessions and secure recovery. Preserve the notice and event timestamps, but never paste the compromised password into an incident ticket.

Session and token cleanup

Changing a password may or may not invalidate existing sessions, app passwords, API tokens and connected applications. Use the service controls to sign out other devices and revoke access. Review mailbox forwarding, social-page roles, cloud application grants and developer tokens according to the account type.

Recovery after email compromise

Check recovery addresses, phone numbers, trusted devices, forwarding rules, filters and delegated mailbox access. Attackers often create a quiet persistence rule that hides security notifications. Change the password and MFA from a clean device and contact the provider through the official recovery channel if settings were altered.

Avoid repeat compromise

Identify why access was lost: reuse, phishing, malware, shared access, weak recovery or provider breach. The replacement password addresses only some causes. Add a password manager, stronger MFA, device remediation, role separation or user training as the incident requires.

Sources and further reading

Generate the replacement locallyCreate a unique password on a trusted device.Open the tool →
Written and reviewed by Gabor Kohanyi

Technical claims are checked against the cited primary standards and official service documentation. Corrections are handled under the editorial policy.