Rekey Request a beta invite
Breach response Free guide ยท no signup to read

Your password was in a breach. Here's exactly what to do.

After a data breach you need to change the leaked password and every account where you reused it, not every password you own. The order matters more than the speed, and email comes first because it's the reset path to everything else.

The short version
  • Change the leaked password and every account you reused it on. Not all of them. Everything else can wait.
  • Email first, then money. Whoever holds your inbox can reset everything else you own.
  • Budget about 73 seconds per account, and expect one in five to fight you. We timed 28 sites in August 2026. Six of them could not be changed at all.
Start here
Open the tracker Download the tracker

Tiers 1 and 2 pre-filled, and 17 rows arrive with the change-password link already in them. Works in Excel, Numbers and Sheets.

By Alex McComas (about), building Rekey, an open-source password tool Published 24 July 2026 Last verified 8 August 2026 ~13 min read

Two versions of this question get asked and they have different answers. "Should I change all my passwords?" No. "Should I change every password caught in this breach?" Yes, and everywhere it was reused. This guide answers the second, because the first is how people end up with a half-finished list and quietly give up.

What follows is the order to work in, how long it realistically takes, a sheet to track it with, and what to do when a change fails halfway. That last part is the one nobody writes down.

The seven steps, in order

Work down the list. Each step assumes the one above it is done, which is the whole reason the order matters.

  1. 1

    Confirm what actually leaked

    Check your email address at haveibeenpwned.com. It is the standard free tool and it is safe to use, though not for the reason usually given, and the FAQ below sets out what actually gets sent. While you are there, turn on "Notify me" so the next breach finds you instead of the other way round. Then the mindset shift: attackers do not stop at the site that leaked. They run credential stuffing, feeding your email and password pair into hundreds of other sites automatically. Every account sharing that password is now a target, so make a list of them before you start.

  2. 2

    Change the breached password first

    The leaked login is the one with a clock on it. The four tiers below decide the order for everything after it.

  3. 3

    Change every other account that shared that password

    This is the actual exposure, and the part that takes real time. Track it in batches with the sheet below.

  4. 4

    Turn on two-factor where it is missing

    Start with tier 1 and tier 2. Prefer an authenticator app or a passkey over SMS, and remember your carrier account can undo this, which is why it belongs in tier 1.

  5. 5

    Check for a break-in you have not noticed yet

    Changing the password does not always end a session an attacker already has open. Look at recent activity first. In Gmail that is "Last account activity" at the bottom of your inbox, and most services have a "where you are signed in" page. If you see a device or a location that is not you, sign out of all sessions, then change the password again so the intruder's copy is dead.

  6. 6

    Watch the money, and freeze your credit

    Changing tier 2 passwords is step 2. Watching what happens on those accounts afterwards is this step, and it runs for weeks rather than an afternoon. Skim bank and card statements for charges you do not recognise. If the breach exposed financial or identity data, you can place a free fraud alert and a free credit freeze with the three bureaus. A freeze is the stronger of the two, and you lift it temporarily when you actually need credit.

  7. 7

    Stop the reuse that caused it

    The breach only hurt because a password was reused. Move every account to a unique, generated password, which is the one job a password manager does well, and the next leak is contained to exactly one login instead of forty. That is the whole game: unique passwords shrink the blast radius. The manual part, actually resetting them all when a breach hits, is the part almost nobody has automated.

Which passwords should I change first?

Passwords fall into four tiers, and the tier decides which day you do it rather than whether you bother at all. Start with the account that resets the others. Anyone holding your email can reset almost everything else you own, which is why email sits alone at the top.

1
Tier
AccountsEmail: Gmail, Outlook, iCloud, Proton. Your phone carrier account
Why hereThe reset path to everything else. Certo calls it the master key and that's the right word
Now
2
AccountsBanking, PayPal, anything holding a card. Government and tax logins
Why hereDirect money loss, and recovery is slow and manual. Changing these is step 2; watching the statements is step 6
Today
3
AccountsEvery account that shared the leaked password
Why hereCredential stuffing tries the same pair everywhere. This is the actual breach exposure
This week
4
AccountsOld accounts you don't use
Why hereLow value, high effort. See below
Delete, or leave
Worth knowingYour phone carrier belongs in tier 1 even though almost nobody lists it there. It is the one account that can undo the two-factor you set up in step 4.

Dead accounts split the advice, and neither side shows its working. Google's AI Mode tells you to delete unused accounts instead of changing them. Perplexity tells you to change them. Neither cites anything. Deleting removes the exposure for good, though plenty of services keep the record anyway. Changing costs you time on an account you'll never open again. Pick whichever one you'll actually finish, because a tier 4 account you never get to is the same either way.

Isn't changing passwords all the time bad advice now?

Yes, and it's worth clearing up properly, because the guidance everyone quotes has been replaced.

NIST swapped SP 800-63B for SP 800-63-4 in August 2025 and the wording got harder. The old version said organisations should not force scheduled rotation. The current one says shall not, which in standards language is the gap between advice and a rule.

Superseded 1 Aug 2025
SP 800-63B
June 2017

Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).

Current
SP 800-63-4
August 2025

Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically.

Read the next sentence though. Verifiers SHALL force a change if there is evidence the password has been compromised. A breach is that evidence, so this isn't a judgement call, it's what the standard requires.

Rotation for no reason is theatre. Rotation because your password is sitting in a breach dump is the thing every standards body agrees on. This checklist is that, the right rotation at the right moment.

Worth knowingMost articles on this still quote the 2017 document, including every AI assistant we tested. If a page tells you NIST "recommends against" scheduled changes, it's working from a version that was retired on 1 August 2025.

How do you keep track of which ones you've done?

Tracking is the part that beats people, and almost no password manager helps. Apple added a Live Activity for it on Apple devices, and nobody else ships anything. Forty resets in, you'll lose your place. Everyone does, and it's where most people abandon the job half finished.

Ask any AI assistant and it'll describe a spreadsheet, then offer to build you one. That's the tell: three separate assistants reached for the same workaround because the tool doesn't exist.

So here is that sheet, already built, and built as a tool rather than a blank grid. Type the sites you need to fix. It sorts them into the four tiers above, attaches the direct change-password page for each one from a directory of 174 sites, and gives you the single next account to do rather than all forty at once. Nothing you type leaves your device, and when you are done you export your list, not an empty one. Pair it with our password generator for the replacements.

Your worklist
Runs in your browser. Nothing is sent anywhere.

One site per line, or separated by commas. You can paste the site column straight out of a password manager export. Only the site names are read. If your paste contains a password, secret, note or one-time code column, those columns are skipped and never touched.

Tick Changed when you have set the new password, and Logged back in only after you have signed out and signed back in with it. That second tick is the one that catches a change that never saved.
Two separate ticks, on purpose. Making the new password and changing it on the site are two steps, and the gap between them is where people lose track. The list will not count a row as done until you have signed out and signed back in, because a change that looked fine but never saved is the most common way people lock themselves out of their own account. Prefer to work offline? Spreadsheet version · plain CSV · single file you can keep.

The one rule people skip

The rule is this. Don't tick a row off until you've logged out and logged back in with the new password. A change that looked fine but never saved to your vault is the most common way people lock themselves out of their own account, and logging back in is the only way to catch it.

How long does it actually take?

A password change takes about 73 seconds when nothing goes wrong, and one site in five will not let you finish at all. We know because we sat down in August 2026 and timed 28 of them with a stopwatch, on real accounts, changing real passwords.

We went looking for a published measurement first and could not find one. Everything we found was an estimate, so we made our own.

What not to expect from these numbers
  • This is one person on his own accounts, not a survey. One afternoon, one country, in August 2026.
  • He knew he was being timed, which makes people faster. Read every figure as a floor.
  • He is technical and had used most of these sites before. A first-timer will be slower.
  • The median counts only the changes that worked. Six sites could not be finished at all and are not in it.
  • Your list is not our list. Ours skewed towards retail and work tools because those were the accounts he had.
72.8sMedian, whole change, start to verified
25.5Median clicks per change
6 of 28Sites we could not change at all
Timed password changes, 28 sites, August 2026
What we measuredMedianRange
Whole change, start to verified72.8s44s to 164s
Finding the change-password page18.8s11s to 111s
Filling in and submitting the form28.1s10s to 119s
Logging out and back in to verify18.4s8s to 105s
Clicks25.511 to 40

Where the time actually goes

The form is the slowest part, not the hunting. Filling in and submitting took a median of 28 seconds against 19 for navigation, because sites demand your current password, then the new one twice, then often something else on top.

The verify loop costs another 18 seconds and almost nobody tells you to do it. That is the step where you log out and log back in with the new password to confirm it actually saved. It sounds optional. It is the only way to catch a change that silently failed, and on one site in our set it took 105 seconds because the new password did not work and the whole thing had to be done again.

What about 300 passwords?

At our measured median, 300 password changes is roughly 6 hours of uninterrupted work. One hundred accounts is about 2 hours. Forty is about 48 minutes.

Those projections are optimistic on purpose, and you should read them as a floor rather than a forecast. They multiply the median of the changes that succeeded. They exclude the six sites that could not be finished at all, which still consumed 11 minutes between them before being abandoned. They exclude the reading, the deciding and the finding of accounts you forgot you had.

The honest version: budget a full day for a few hundred accounts, and do it in batches. At 73 seconds each, fifteen accounts is about 18 minutes of work, which is a realistic sitting.

How we measured this
  • 28 sites across email, banking, shopping, social and work tools, all accounts the tester actually held. 22 completed, 6 could not be finished.
  • The clock started on the site's logged-in home page and stopped only after logging out and back in with the new password, so the verify loop is counted.
  • A browser extension recorded four marks per run and counted every click and page load. It never read the value of any field.
  • One run per site, first attempt. Passwords were generated in a manager and pasted.
  • Check the numbers. Download every run as a spreadsheet. All 32 runs are in it, including the 10 left out of the medians, each with the reason it was excluded. Recompute the median and you should get 72.8 seconds.
  • Or run it yourself. Download the timer extension we used, load it in Chrome, and time your own accounts. It never reads the value of any field.

Corrections. 13 August 2026: first publication. Any change to these figures will be dated and listed here.

What goes wrong, and how to stop it

Password changes fail more often than anyone admits, and they fail quietly. Across 28 sites, six could not be completed at all and six more failed on the first attempt. That is nearly half the set giving trouble in some form.

You cannot find the page

Only 4 of the 28 sites we tested could be navigated to their own change-password page. On the other 24, we ended up using a search engine, the browser address bar, or a bookmark.

On four sites we never found it at all. On Gucci, Bitwarden and IndieHackers no change-password option was found anywhere we looked. On PressWhizz we went through 15 page loads and 12 clicks in 107 seconds and still came away empty.

What to do: stop hunting after about a minute and search the web for "change password" plus the site name. That is what worked for us on 24 of 28 sites, and it is not a failure of yours.

The site rejects your password

Shopify would not accept our current password. It had been generated, saved and filled in from a password manager, and the form said it was wrong. After 243 seconds and 66 clicks, the longest and most click-heavy run in the entire study, we gave up without changing anything.

We cannot tell you whether the vault held a stale value or the site rejected a valid one. From where you sit those are the same event, and it is the single most common way people lock themselves out: the site and your password manager disagree about what your password is.

What to do: use the site's forgot-password link rather than fighting the form. Your email is the way back in, which is exactly why email is tier 1.

It sends a code somewhere else

7 of 28 sites made us leave the site mid-change to fetch a verification code, usually from email, sometimes by text. Netlify, RBC, WeTransfer, Amazon, GitHub and Louis Vuitton all did it.

Amazon did it twice: an email code that failed, a page reload, then an SMS code, then a rate limit. It is the only site in the study that rate-limited us.

What to do: have your email open in another tab before you start. It turns a context switch into a copy and paste.

It fails on the first attempt

6 of 28 changes failed the first time. GitHub was the worst: the new password did not work, which triggered an email verification, then a second reset, then a fingerprint prompt. 146.8 seconds, of which 104.6 was just the verify loop.

What to do: the fifteen-second habit below. It catches every one of these.

The fifteen-second habit

All four have the same fix, and it's the only habit on this page worth memorising.

01Save the new password in your manager before you hit submit
02Submit the change
03Log out completely
04Log back in, then tick it off

Do that and your list means something. Skip it and you'll be back here next month with no idea which of the forty actually took.

Which raises the obvious question. Seventy-three seconds each, twenty-five clicks, and roughly one site in five that fights back. Why are you doing any of this by hand?

Why won't a password manager do it?

Password managers almost never do this for you. We checked all eleven of the major ones in July 2026 and exactly one will change a breached password on your behalf today, and the two that come closest are locked to a single ecosystem.

Password managers checked July 2026
Manager Auto-changes a breached password? The catch
Google Password Manager Yes, partly Chrome only, participating sites only, needs sync on, US, 18 or over, Android first
Apple Passwords Announced, not shipped Announced 8 June 2026 for iOS 27. Apple devices and Safari, limited to "eligible accounts", which Apple doesn't define
Bitwarden Takes you there Premium and Families only. Opens the change page, fills the old password, generates a new one, then hands the form back to you
Dashlane Built it, then removed it Password Changer covered 500+ sites, relaunched 2021, retired 2022. No reason ever published
1Password No Watchtower detects and alerts. The reset is yours to do
Proton Pass No Pass Monitor detects and alerts. The reset is yours to do
NordPass No Detects and alerts, and detection sits behind Premium
Keeper No Detects and alerts through the BreachWatch add-on. The reset is yours to do
LastPass No Detects and alerts. The reset is yours to do
KeePassXC No Offline by design. Detection is a manual HIBP check you run yourself
Passbolt No Detects and alerts on Pro. The reset is yours to do
Rekey in development, not counted in the eleven Takes you there Same guided hand-off as Bitwarden, with three differences: free rather than a paid tier, it keeps your old password in the vault until the new one is verified working, and it is open source so you can read what it does

Why did Dashlane remove Password Changer?

Dashlane has never published a reason, which is itself the interesting part. It relaunched Password Changer in 2021, covered more than 500 sites, and retired it in 2022, describing it in its own announcement as "the experimental Password Changer" that "is no longer available". The support article they pointed users to for an explanation has since been replaced by an unrelated page.

What's left is the shape of the problem. There's no standard way to change a password on the web, so every supported site has to be hand-built and hand-maintained, and sites redesign their forms without telling anyone. A funded market leader built that and walked away from it. Google and Apple have both restricted their versions to lists they control rather than attempt the open web.

Which password manager has never been hacked?

No password manager has a clean record, and any page that names one is telling you something it can't know. LastPass lost vault data in 2022, and several other vendors have had incidents of their own. The useful question isn't which vendor has a clean record. It's what happens to your data when a vendor has a bad day. Three things decide that: whether the vault is encrypted so the vendor can't read it, whether the code is open to inspection, and whether there's a dated independent audit you can go and read for yourself.

Worth knowingIn four of the eleven, breach detection itself sits behind a paywall: Bitwarden Premium, NordPass Premium, Keeper's BreachWatch add-on and Passbolt Pro. Being told your password leaked is not always a free feature.

The full breakdown, with dates and sources for every row, is in our capability benchmark of all eleven managers.

Straight answers

Key takeaways

TakeawayIn one line
Not every password, just the reused onesThe leaked login plus every account sharing it
Email first, alwaysWhoever controls your inbox can reset everything else
NIST requires this changeSP 800-63-4, Aug 2025: verifiers SHALL force a change on evidence of compromise
A change takes about 73 secondsMeasured across 28 sites, August 2026. Range 44s to 164s
One site in five cannot be changed at all6 of 28 defeated us, including Shopify and Gucci
Log back in before ticking it offA change that never saved is the top cause of lockout
One of eleven managers can do thisAnd it's Chrome only, on participating sites, in the US

Here's the part I'd argue with the rest of the internet about.

Every guide we read, including all three AI assistants we tested in July 2026, gives the priority order and stops. Not one of them told us how long it takes. Not one offered a way to track it. Not one admitted a change can fail halfway and lock you out. Three of them ended by offering to build me a spreadsheet, which is a tell: they're all describing a tool that doesn't exist, and then apologising for its absence.

The advice isn't wrong. It's just written by people who've never sat down and done forty of them.

Alex McComas, building Rekey, an open-source password tool. The code and a written security review are public, so you can check any of this yourself.

Get the tool that does the boring part

Rekey is a browser extension, in development. Join the early-access list and we will email you once, at launch.

Get early access
  • Finds every exposed login by checking your saved passwords against Have I Been Pwned
  • Takes you to the change page for each one, with a strong new password ready to paste
  • Keeps your old password in the vault until the new one is confirmed working. No lockouts, by design
  • Open source, and nothing leaves your device. No server, no database, read the code yourself

Free while in development. We will not sell your address or send you anything else.

Keep reading