Password security guide
What to Do If Your Password Is Compromised
Use a trusted device, secure the account and its recovery channels, then replace every reused or derived credential.
Immediate response checklist
- Open the service from a trusted bookmark or typed address, not a warning-message link.
- Change the password to a unique generated value.
- Sign out other sessions and remove unknown devices.
- Review MFA, recovery email, phone and backup codes.
- Check account activity and connected applications.
- Replace the same or related password everywhere else.
Secure email and the password manager first
Primary email can reset many other accounts, and the password manager may contain all credentials. If either is involved, secure it before lower-value services. Verify forwarding rules, recovery addresses, app passwords and active sessions.
If the password was entered on a phishing page
Assume the attacker received it immediately. Change it on the legitimate service, revoke sessions and check MFA changes. If you approved a login prompt or entered a one-time code, report that too. Remove unknown OAuth or connected-app grants.
If malware may be present
Changing a password on the same compromised device can expose the replacement. Disconnect or stop sensitive use, update and scan the device, and use a known-clean device for account recovery. For a managed work device, contact the responsible security team.
Review financial and personal consequences
Check purchases, messages, profile changes and data exports. Contact the service or financial provider through official channels when unauthorized activity appears. Preserve relevant notices and timestamps without storing the compromised password in incident notes.
Monitor after recovery
Watch for reset emails, new-device alerts and unexpected MFA prompts. An attacker may retain access through a session, app token or mailbox rule even after the password changes. Review again after the immediate incident.
Replace exposed authentication factors
If an attacker received a one-time code, approved push, backup code or session, changing only the password may not remove access. Revoke sessions, remove unknown authenticators, replace backup codes and enroll a safe second factor. Follow the method checklist in the two-factor authentication guide.
Different exposure types require different actions
A breach notice may mean password hashes were taken, not that every plaintext password is known. A phishing submission should be treated as immediate disclosure. Malware can capture the replacement. An accidental message exposes the value to its recipients and any retained copies. Match the response to the most serious plausible path.
When facts are uncertain, use a trusted device, rotate the credential, revoke sessions and secure recovery. Preserve the notice and event timestamps, but never paste the compromised password into an incident ticket.
Session and token cleanup
Changing a password may or may not invalidate existing sessions, app passwords, API tokens and connected applications. Use the service controls to sign out other devices and revoke access. Review mailbox forwarding, social-page roles, cloud application grants and developer tokens according to the account type.
Recovery after email compromise
Check recovery addresses, phone numbers, trusted devices, forwarding rules, filters and delegated mailbox access. Attackers often create a quiet persistence rule that hides security notifications. Change the password and MFA from a clean device and contact the provider through the official recovery channel if settings were altered.
Avoid repeat compromise
Identify why access was lost: reuse, phishing, malware, shared access, weak recovery or provider breach. The replacement password addresses only some causes. Add a password manager, stronger MFA, device remediation, role separation or user training as the incident requires.