Rekey Request a beta invite
Guides

What to do when a password is already exposed.

Every guide here is about the cleanup after a breach, not everyday password hygiene. That is a deliberate narrowing. Advice on picking a strong password is everywhere and mostly fine. Advice on what to actually do at 11pm with forty exposed logins and no idea where to start is not.

NIST agrees with the narrowing. SP 800-63-4 says verifiers SHALL NOT force scheduled password changes, and SHALL force one when there is evidence of compromise. Rotating on a calendar is theatre. Rotating because your password is sitting in a breach dump is the thing everyone agrees on.

Start where you are
“I just got a breach alert.”
The order to work in, which accounts come first, and a tracker so you do not lose your place at number twenty.
Breach response guide →
“Can my password manager just do this?”
We tested all eleven. One can, partly. The answer is far more restricted than any vendor page admits.
The benchmark →
“Was I even in a breach?”
Check a password against known breach lists without sending it anywhere. Runs entirely in your browser.
Free checker →
01

Breach response

What to do once a password is known to be exposed. Priority order, realistic timings, and the failure modes nobody writes down.

Guide · 13 min · updated 8 August 2026

Your password was in a breach. Here's exactly what to do.

The priority order
Bar length is how long you have, not how many accounts.
SOONEST LATEST TIER 1 Now Email, and your phone carrierTIER 2 Today Banking, cards, taxTIER 3 This week Every account that shared itTIER 4 Delete, or leave Dead accounts you never open

The four-tier priority order, four time estimates that disagree with each other by a factor of ten, a tracker sheet you can download, and what to do when a password change fails halfway and locks you out of your own account. That last section exists because no other guide has it.

Tracker, 174 change linksFour-tier orderNIST SP 800-63-4
Read it →
02

Guided fixing

Whether a tool can do the work for you, and where every current attempt stops short.

Benchmark · original data · July 2026

Which password managers actually change breached passwords? We checked all 11.

Eleven managers, checked July 2026
Will change a breached password for you 1 TODAY (GOOGLE, PARTLY) · 1 ANNOUNCED (APPLE) Charge you just to be told it leaked 4 OF 11 PUT BREACH DETECTION BEHIND A PAYWALL
1 of 11 can do it today, and a second is announced but not shipped.
Both are locked to a single ecosystem. No shipping product does it on any site, on any platform.

First-party benchmark. Every vendor claim checked against its own documentation, with dates and sources for every row. Includes why Dashlane built this feature, shipped it to more than 500 sites, then quietly removed it, and why Google and Apple have both limited theirs to lists they control.

Original data11 managersDownloadable CSV
Read it →
03

Trust, lockout and manager breaches

What actually happens to your data when a password manager has a bad day, and what a tool has to guarantee before it touches your credentials.

In research
When your password manager is breached, what is actually exposed?

Being written now. It is the only unpublished topic on this page, because it is the only one that has cleared our own bar for demand: roughly eighteen independent posts asking it in six weeks, none of them ours.

Free tools

All three run entirely in your browser. Nothing you type is sent to a server, and there is no signup on any of them.

Was your password in a breach?
Hashed in your browser. Only five characters of the hash ever leave your device.
Strong password generator
Generated locally. Nothing is sent anywhere.
Password strength checker
Scored on your device. Length, character mix and reuse guidance.

How these are written

Four rules, and they are the reason there are two guides here rather than twenty.

  1. 01A topic has to earn its place. Nothing gets written until enough people are independently asking about it. Our own posts never count as evidence.
  2. 02Primary sources, linked. Standards, regulations and vendor documentation are quoted and linked so you can check the wording yourself rather than take ours.
  3. 03When a number does not exist, we say so. Nobody has measured how long a breach cleanup takes. The guide prints four conflicting estimates and labels all four as unmeasured rather than picking a confident one.
  4. 04Our own product sits inside the comparison, not above it. Rekey appears in the manager table as a row like any other, marked as in development and not counted in the eleven.

Written by Alex McComas while building Rekey, an open-source password tool. The code and a written security review are public, so you can check any of it yourself.

Get the tool that does the boring part

Rekey is a browser extension, in development. It finds every exposed login, takes you to the change page for each one, and keeps your old password in the vault until the new one is confirmed working. Join the early-access list and we will email you once, at launch.

Get early access

Free while in development. We will not sell your address or send you anything else.