Two versions of this question get asked and they have different answers. "Should I change all my passwords?" No. "Should I change every password caught in this breach?" Yes, and everywhere it was reused. This guide answers the second, because the first is how people end up with a half-finished list and quietly give up.
What follows is the order to work in, how long it realistically takes, a sheet to track it with, and what to do when a change fails halfway. That last part is the one nobody writes down.
The seven steps, in order
Work down the list. Each step assumes the one above it is done, which is the whole reason the order matters.
-
1
Confirm what actually leaked
Check your email address at haveibeenpwned.com. It is the standard free tool and it is safe to use, though not for the reason usually given, and the FAQ below sets out what actually gets sent. While you are there, turn on "Notify me" so the next breach finds you instead of the other way round. Then the mindset shift: attackers do not stop at the site that leaked. They run credential stuffing, feeding your email and password pair into hundreds of other sites automatically. Every account sharing that password is now a target, so make a list of them before you start.
-
2
Change the breached password first
The leaked login is the one with a clock on it. The four tiers below decide the order for everything after it.
-
3
Change every other account that shared that password
This is the actual exposure, and the part that takes real time. Track it in batches with the sheet below.
-
4
Turn on two-factor where it is missing
Start with tier 1 and tier 2. Prefer an authenticator app or a passkey over SMS, and remember your carrier account can undo this, which is why it belongs in tier 1.
-
5
Check for a break-in you have not noticed yet
Changing the password does not always end a session an attacker already has open. Look at recent activity first. In Gmail that is "Last account activity" at the bottom of your inbox, and most services have a "where you are signed in" page. If you see a device or a location that is not you, sign out of all sessions, then change the password again so the intruder's copy is dead.
-
6
Watch the money, and freeze your credit
Changing tier 2 passwords is step 2. Watching what happens on those accounts afterwards is this step, and it runs for weeks rather than an afternoon. Skim bank and card statements for charges you do not recognise. If the breach exposed financial or identity data, you can place a free fraud alert and a free credit freeze with the three bureaus. A freeze is the stronger of the two, and you lift it temporarily when you actually need credit.
-
7
Stop the reuse that caused it
The breach only hurt because a password was reused. Move every account to a unique, generated password, which is the one job a password manager does well, and the next leak is contained to exactly one login instead of forty. That is the whole game: unique passwords shrink the blast radius. The manual part, actually resetting them all when a breach hits, is the part almost nobody has automated.
Which passwords should I change first?
Passwords fall into four tiers, and the tier decides which day you do it rather than whether you bother at all. Start with the account that resets the others. Anyone holding your email can reset almost everything else you own, which is why email sits alone at the top.
Dead accounts split the advice, and neither side shows its working. Google's AI Mode tells you to delete unused accounts instead of changing them. Perplexity tells you to change them. Neither cites anything. Deleting removes the exposure for good, though plenty of services keep the record anyway. Changing costs you time on an account you'll never open again. Pick whichever one you'll actually finish, because a tier 4 account you never get to is the same either way.
Isn't changing passwords all the time bad advice now?
Yes, and it's worth clearing up properly, because the guidance everyone quotes has been replaced.
NIST swapped SP 800-63B for SP 800-63-4 in August 2025 and the wording got harder. The old version said organisations should not force scheduled rotation. The current one says shall not, which in standards language is the gap between advice and a rule.
Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).
Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically.
Read the next sentence though. Verifiers SHALL force a change if there is evidence the password has been compromised. A breach is that evidence, so this isn't a judgement call, it's what the standard requires.
Rotation for no reason is theatre. Rotation because your password is sitting in a breach dump is the thing every standards body agrees on. This checklist is that, the right rotation at the right moment.
How do you keep track of which ones you've done?
Tracking is the part that beats people, and almost no password manager helps. Apple added a Live Activity for it on Apple devices, and nobody else ships anything. Forty resets in, you'll lose your place. Everyone does, and it's where most people abandon the job half finished.
Ask any AI assistant and it'll describe a spreadsheet, then offer to build you one. That's the tell: three separate assistants reached for the same workaround because the tool doesn't exist.
So here is that sheet, already built, and built as a tool rather than a blank grid. Type the sites you need to fix. It sorts them into the four tiers above, attaches the direct change-password page for each one from a directory of 174 sites, and gives you the single next account to do rather than all forty at once. Nothing you type leaves your device, and when you are done you export your list, not an empty one. Pair it with our password generator for the replacements.
One site per line, or separated by commas. You can paste the site column straight out of a password manager export. Only the site names are read. If your paste contains a password, secret, note or one-time code column, those columns are skipped and never touched.
The one rule people skip
The rule is this. Don't tick a row off until you've logged out and logged back in with the new password. A change that looked fine but never saved to your vault is the most common way people lock themselves out of their own account, and logging back in is the only way to catch it.
How long does it actually take?
A password change takes about 73 seconds when nothing goes wrong, and one site in five will not let you finish at all. We know because we sat down in August 2026 and timed 28 of them with a stopwatch, on real accounts, changing real passwords.
We went looking for a published measurement first and could not find one. Everything we found was an estimate, so we made our own.
- This is one person on his own accounts, not a survey. One afternoon, one country, in August 2026.
- He knew he was being timed, which makes people faster. Read every figure as a floor.
- He is technical and had used most of these sites before. A first-timer will be slower.
- The median counts only the changes that worked. Six sites could not be finished at all and are not in it.
- Your list is not our list. Ours skewed towards retail and work tools because those were the accounts he had.
Where the time actually goes
The form is the slowest part, not the hunting. Filling in and submitting took a median of 28 seconds against 19 for navigation, because sites demand your current password, then the new one twice, then often something else on top.
The verify loop costs another 18 seconds and almost nobody tells you to do it. That is the step where you log out and log back in with the new password to confirm it actually saved. It sounds optional. It is the only way to catch a change that silently failed, and on one site in our set it took 105 seconds because the new password did not work and the whole thing had to be done again.
What about 300 passwords?
At our measured median, 300 password changes is roughly 6 hours of uninterrupted work. One hundred accounts is about 2 hours. Forty is about 48 minutes.
Those projections are optimistic on purpose, and you should read them as a floor rather than a forecast. They multiply the median of the changes that succeeded. They exclude the six sites that could not be finished at all, which still consumed 11 minutes between them before being abandoned. They exclude the reading, the deciding and the finding of accounts you forgot you had.
The honest version: budget a full day for a few hundred accounts, and do it in batches. At 73 seconds each, fifteen accounts is about 18 minutes of work, which is a realistic sitting.
- 28 sites across email, banking, shopping, social and work tools, all accounts the tester actually held. 22 completed, 6 could not be finished.
- The clock started on the site's logged-in home page and stopped only after logging out and back in with the new password, so the verify loop is counted.
- A browser extension recorded four marks per run and counted every click and page load. It never read the value of any field.
- One run per site, first attempt. Passwords were generated in a manager and pasted.
- Check the numbers. Download every run as a spreadsheet. All 32 runs are in it, including the 10 left out of the medians, each with the reason it was excluded. Recompute the median and you should get 72.8 seconds.
- Or run it yourself. Download the timer extension we used, load it in Chrome, and time your own accounts. It never reads the value of any field.
Corrections. 13 August 2026: first publication. Any change to these figures will be dated and listed here.
What goes wrong, and how to stop it
Password changes fail more often than anyone admits, and they fail quietly. Across 28 sites, six could not be completed at all and six more failed on the first attempt. That is nearly half the set giving trouble in some form.
You cannot find the page
Only 4 of the 28 sites we tested could be navigated to their own change-password page. On the other 24, we ended up using a search engine, the browser address bar, or a bookmark.
On four sites we never found it at all. On Gucci, Bitwarden and IndieHackers no change-password option was found anywhere we looked. On PressWhizz we went through 15 page loads and 12 clicks in 107 seconds and still came away empty.
What to do: stop hunting after about a minute and search the web for "change password" plus the site name. That is what worked for us on 24 of 28 sites, and it is not a failure of yours.
The site rejects your password
Shopify would not accept our current password. It had been generated, saved and filled in from a password manager, and the form said it was wrong. After 243 seconds and 66 clicks, the longest and most click-heavy run in the entire study, we gave up without changing anything.
We cannot tell you whether the vault held a stale value or the site rejected a valid one. From where you sit those are the same event, and it is the single most common way people lock themselves out: the site and your password manager disagree about what your password is.
What to do: use the site's forgot-password link rather than fighting the form. Your email is the way back in, which is exactly why email is tier 1.
It sends a code somewhere else
7 of 28 sites made us leave the site mid-change to fetch a verification code, usually from email, sometimes by text. Netlify, RBC, WeTransfer, Amazon, GitHub and Louis Vuitton all did it.
Amazon did it twice: an email code that failed, a page reload, then an SMS code, then a rate limit. It is the only site in the study that rate-limited us.
What to do: have your email open in another tab before you start. It turns a context switch into a copy and paste.
It fails on the first attempt
6 of 28 changes failed the first time. GitHub was the worst: the new password did not work, which triggered an email verification, then a second reset, then a fingerprint prompt. 146.8 seconds, of which 104.6 was just the verify loop.
What to do: the fifteen-second habit below. It catches every one of these.
The fifteen-second habit
All four have the same fix, and it's the only habit on this page worth memorising.
Do that and your list means something. Skip it and you'll be back here next month with no idea which of the forty actually took.
Which raises the obvious question. Seventy-three seconds each, twenty-five clicks, and roughly one site in five that fights back. Why are you doing any of this by hand?
Why won't a password manager do it?
Password managers almost never do this for you. We checked all eleven of the major ones in July 2026 and exactly one will change a breached password on your behalf today, and the two that come closest are locked to a single ecosystem.
Why did Dashlane remove Password Changer?
Dashlane has never published a reason, which is itself the interesting part. It relaunched Password Changer in 2021, covered more than 500 sites, and retired it in 2022, describing it in its own announcement as "the experimental Password Changer" that "is no longer available". The support article they pointed users to for an explanation has since been replaced by an unrelated page.
What's left is the shape of the problem. There's no standard way to change a password on the web, so every supported site has to be hand-built and hand-maintained, and sites redesign their forms without telling anyone. A funded market leader built that and walked away from it. Google and Apple have both restricted their versions to lists they control rather than attempt the open web.
Which password manager has never been hacked?
No password manager has a clean record, and any page that names one is telling you something it can't know. LastPass lost vault data in 2022, and several other vendors have had incidents of their own. The useful question isn't which vendor has a clean record. It's what happens to your data when a vendor has a bad day. Three things decide that: whether the vault is encrypted so the vendor can't read it, whether the code is open to inspection, and whether there's a dated independent audit you can go and read for yourself.
The full breakdown, with dates and sources for every row, is in our capability benchmark of all eleven managers.
Straight answers
Key takeaways
Here's the part I'd argue with the rest of the internet about.
Every guide we read, including all three AI assistants we tested in July 2026, gives the priority order and stops. Not one of them told us how long it takes. Not one offered a way to track it. Not one admitted a change can fail halfway and lock you out. Three of them ended by offering to build me a spreadsheet, which is a tell: they're all describing a tool that doesn't exist, and then apologising for its absence.
The advice isn't wrong. It's just written by people who've never sat down and done forty of them.
Alex McComas, building Rekey, an open-source password tool. The code and a written security review are public, so you can check any of this yourself.
Rekey is a browser extension, in development. Join the early-access list and we will email you once, at launch.
Get early access- Finds every exposed login by checking your saved passwords against Have I Been Pwned
- Takes you to the change page for each one, with a strong new password ready to paste
- Keeps your old password in the vault until the new one is confirmed working. No lockouts, by design
- Open source, and nothing leaves your device. No server, no database, read the code yourself
Free while in development. We will not sell your address or send you anything else.