Local Tech Fix (626) 655-0020
All articles

Your Password "Appeared in a Data Leak": What That Warning Means and What to Do

August 18, 2026

It is not a hacking notification and it is not a sales pitch. It means a working key to one of your accounts is sitting on a public list — and where that list came from decides whether you change the password first or clean the computer first.

red padlock on black computer keyboard
Photo by FlyD on Unsplash

The wording depends on what you were holding at the time. An iPhone puts up "This password has appeared in a data leak." Chrome says a data breach on a site or app exposed your password. Edge quietly files it under Password security check and waits for you to notice. Same message, three dialects, and it usually turns up while you are trying to do something else entirely.

There are two common reactions and both of them are wrong. The first, and by far the more popular, is to tap Dismiss — partly because the alert reads like an advert for something, and partly because after years of fake virus pop-ups a lot of people quite reasonably suspect the warning itself is the scam. The second is to assume the account has been broken into, and to start frantically changing passwords everywhere, in no particular order, on whatever computer is in front of you.

The short version is calmer than either. The warning means a username-and-password pair matching one of yours has turned up on a list of stolen credentials that is circulating publicly. It is not, by itself, a statement that anybody has been in your account. It is a statement that a working key to it is in public. That is worth an hour of your day, not a panic — but there is one question to answer before you start typing new passwords, because the answer changes the order you should do things in, and almost nothing written about this topic mentions it.

What the warning is actually telling you

Your phone and your browser both keep a list of the logins you have saved. Periodically they compare that list against a much larger collection of credentials that have been stolen from companies and published or sold. When one of yours matches, you get the alert. Apple describes the outcome in deliberately careful language: "You will receive a warning for any passwords that are determined to possibly have been included in a data leak."

Notice what is not in that sentence. It does not say your account was accessed. It does not say Apple, Google or Microsoft was breached — the leak came from one of the sites or apps you have an account with, not from the company that showed you the warning. And it does not tell you which site, or when, because the lists that circulate are usually stripped of that context long before they reach a checker.

One consequence catches people out. Having been in a leak is permanent. Have I Been Pwned, the long-running independent breach index, puts it plainly: the fact an email address was in a breach "is an immutable historic fact; it cannot later be changed." You cannot be scrubbed off a list that has already been copied a thousand times. What you can do is make the leaked key stop working — which is a five-minute job, and is the entire point of the alert.

No, the warning itself is not a scam — and the check does not hand over your password

The suspicion is healthy and worth taking seriously, because there is an entire industry of fake security alerts, and we have written about several of them. So here is the tell that separates the real thing from the fake. A genuine breach warning appears inside your own settings or your browser's password manager. It never appears as a full-screen web page. It never gives you a phone number to call. It never asks you to install anything, download a "security tool", or let somebody connect to your computer. If any of those are present, you are looking at a tech-support scam wearing this month's costume, and the right move is to close it.

The other half of the suspicion is subtler and, in our experience, the reason most people ignore these alerts: if something is checking my passwords against a list of stolen passwords, does that mean my passwords are being sent somewhere? It is a fair question and the answer is genuinely reassuring, because all four of the major checkers were designed specifically so the answer could be no.

Apple: the feature "uses strong cryptographic techniques to regularly check derivations of your password against a list of leaked passwords in a secure and private manner," and "your actual passwords are never shared with Apple, and Apple does not store the information calculated from your passwords." Google: "Chrome first encrypts your username and password. Then it sends the encrypted credentials to Google for comparison against an encrypted list of known breached data," and "Google never learns your usernames or passwords during this process." Microsoft: in Edge, "when Password Monitor checks your passwords against the database of known leaked credentials, they're hashed and encrypted before being sent to the service."

The independent option is the most explicit of all about its own plumbing. On Have I Been Pwned's password search, "your password is hashed locally and only the first 5 characters of the SHA-1 hash are sent to the API. The service returns a list of matching suffixes, and the full comparison happens on your side." In other words the site is handed five characters of a scrambled fingerprint, sends back every leaked password that starts the same way, and your own device works out whether one of them is yours. It never learns what you searched for.

Why a leak at a shop you barely remember matters at your bank

The instinct is to shrug: that account had nothing in it. But the thing that got stolen is not the account, it is the pair — an email address and the password you used with it. That pair has resale value precisely because it is portable.

What happens next is automated and impersonal. Software works through the stolen list and tries each pair against hundreds of well-known sites: the big email providers, banks, retailers, streaming services, airline loyalty programmes. No guessing and no cracking is involved, which is why the usual defences do not fire — from the site's point of view, somebody typed the correct password on the first attempt. Every account where you reused that password opens. That is the whole mechanism, and it is why one forgotten forum breach can end at your inbox.

A related habit is worth naming, because we see it constantly. Near-variants are not protection. If the leaked password was Sunshine2019 then Sunshine2020, Sunshine2019! and Sunshine2019a are not new passwords in any meaningful sense — the lists are churned through variation rules as a matter of routine, and the obvious mutations of a known password are among the first things tried.

The question that changes what you do first: did it leak from a company, or off a computer?

This is the part that other guides skip, and it decides the order of everything below. Leaked credentials reach those public lists by two quite different routes.

The first is the one everybody pictures: a company you had an account with was breached, its database of usernames and passwords was taken, and eventually it was published. If that is what happened, your devices are fine. You change that one password, change it anywhere you reused it, and you are done.

The second route is now enormous and hardly anybody outside the security world has heard of it. It is called a stealer log, and Have I Been Pwned describes the source exactly: these are "the result of malicious software running on infected machines that collect email addresses, passwords and the website they're entered into at login." Malware sits on somebody's computer and harvests logins as they are typed or lifts them straight out of the browser's saved passwords, then the harvest is bundled up with millions of others and dumped in public. The scale is not marginal — one aggregation of this kind of threat data loaded into the index in October 2025 covered 183 million unique email addresses.

The reason this matters more than any other sentence on this page: if the leak came off your machine, then your machine is the leak. Changing your password on an infected computer hands the attacker the new one about as fast as you can type it. Microsoft's own account-recovery guidance says to run a full scan on your PC before you change your password, and it is advice we give on every hacked-account job we take.

You often cannot be certain which route applies, but the pattern is usually readable. A single old password flagged on one site, especially a site that had a breach in the news, points to the first route. Several passwords flagged at once, or a password you know you never reused anywhere, or a password you only set recently, or a cluster of flagged logins that were all only ever typed on one particular computer — those point at the machine. When it is ambiguous, treat the device as suspect. A scan costs you twenty minutes and rules out the expensive possibility.

The fix, in the order that actually works

Start from a device you trust. If there is any suspicion about the computer, scan it before you type anything new, or do the whole job from a phone you are confident is clean. This is step zero and it is the one people skip.

Change the flagged password by going to the site yourself — type the address, or use a bookmark you saved. Never through a link in an email telling you about a breach, because that is exactly where the follow-up scam lives, and a convincing "reset your password after the breach" page is trivially easy to build.

Make the new password genuinely different, not a variant, and let the password manager you already own generate and remember it. Every phone and every browser has one built in, and it is free.

While you are in the account settings, turn on two-factor authentication. This is the single change that most reduces the damage a leaked password can do — in the FTC's words, requiring two or more credentials to log in "makes it harder for scammers to get into your account, even if they get your username and password."

Then sign out of all devices, or revoke active sessions, wherever the account offers it. This matters because an attacker who already had a live session can stay signed in after a password change; the session is a separate key, and it has to be cancelled separately.

Now sweep for reuse. Anywhere you used the same password, or a close cousin, change it too — email first, then anything with money attached, then the rest. Your email account is the priority even if it was not the one flagged, because it is the reset route for everything else you own.

Finally, look at the recovery settings on your email: the phone number, the backup address, and any forwarding rules or filters. Someone who has been in an inbox usually leaves a way back in, and a quiet forwarding rule is the classic one.

How to check the rest of your saved passwords

Having found one, it is worth reviewing the lot. Every platform has this built in and none of them charge for it.

On an iPhone, iPad or Mac, open the Passwords app and tap Security. Apple sorts the findings into three kinds and explains each: passwords marked reused "have been used across different domains, and using the same password for more than one service may leave the account vulnerable to an attacker who has discovered your credentials"; passwords marked weak "may be easily guessed by an attacker"; and passwords are marked as leaked "if the Password Monitoring feature has identified them in a known data leak." The switch that drives it is called Detect Compromised Passwords.

On Chrome or Android, go to passwords.google.com and run Password Checkup, which reviews the strength and security of everything saved to your Google Account and flags what has turned up in a breach. The automatic warnings are controlled in Chrome under Settings, then Privacy and security, then Security, where the option reads "Warn you if passwords are exposed in a data breach" — it is on by default.

On Edge, the path is Settings, then Passwords and autofill, then Microsoft Password Manager, then Password security check. Each flagged entry gives you Change, which takes you to the relevant website, or Ignore for accounts that no longer matter. If you are signed in to Edge and syncing, this is already running.

For an independent second opinion, haveibeenpwned.com is free and searches by email address rather than by saved login, which means it can surface breaches at sites you no longer have saved anywhere. It is worth doing all of these at least once rather than picking one, because they do not draw on identical lists — a password flagged in one may be silent in another.

If an article told you to use Google's dark web report, that article is out of date

This was, for a couple of years, the standard recommendation in every guide on this subject, and it has quietly stopped existing. Google's own support page gives the schedule: "January 15, 2026: The scans for new dark web breaches stop," and "February 16, 2026: The dark web report is no longer available."

Google's stated reason is unusually candid, and it is the right lesson to take from this whole topic: the report "didn't provide helpful next steps," and the company said it wanted to focus on tools that give people clearer, actionable steps instead. It now points users at Security Checkup, Google Password Manager, Password Checkup, passkeys, and the separate Results about you tool for getting personal information removed from Search results.

The broader point outlives the product. Monitoring is not protection. Being told that your email address is on a list somewhere changes nothing on its own, and paid services that do little more than tell you that are selling anxiety. What actually changes your exposure is the boring pair: a unique password on every account that matters, and a second factor on the ones that matter most.

The email that quotes one of your real passwords

Sooner or later, a leak produces this: an email that opens by stating a password you genuinely recognise, then claims the sender has been watching you through your webcam or has some other compromising material, and demands payment — usually in cryptocurrency, sometimes in gift cards — within a short deadline.

It is very effective, because the password is real and everything else in the message is a lie. The FTC's description of the mechanics is exactly right: your email may have been exposed in a data breach, and "the scammers may really know one of your old – or recent – passwords, and they include it in the message to prove it." The consumer alert is equally blunt about the rest of it: while the sender may claim to have a video or know about something embarrassing, "it's all fake."

So do not pay, and do not reply — a reply only confirms the address is live. If the quoted password is one you still use anywhere, change it now, which is the one genuinely useful thing the email has done for you. Then report it at ReportFraud.ftc.gov, and you can forward phishing messages to the Anti-Phishing Working Group at reportphishing@apwg.org. If you did pay, be ready for the second wave: people who lose money to a scam get contacted by someone offering to recover it, and that is a separate scam we have written about in full.

Three things not to do

Do not pay anyone to remove your data from the dark web. Nobody can do this. A list that has been copied and resold cannot be recalled, which is what "an immutable historic fact" means in practice. Services that offer removal are, at best, selling you monitoring with a more dramatic name.

Do not just add a character to the leaked password. See above — the variants are tried as a matter of course, and the ten seconds you save are not worth it.

Do not skip an account because there is nothing valuable in it. The value is the pair and the email address attached to it, both of which travel; and a neglected account with an old address on it is often the softest route into a recovery chain that ends somewhere you do care about.

"Not found" does not mean safe

The reverse check is worth understanding too, because a clean result is easy to over-read. Have I Been Pwned says so itself when a password comes back clear: "This password wasn't found in any of the Pwned Passwords loaded into Have I Been Pwned. That doesn't necessarily mean it's a good password, merely that it's not indexed on this site."

That caveat applies to every checker on the list. These tools can only know about breaches that have been discovered, collected and loaded. A breach that happened last month, or one the company has not disclosed, or a set of credentials being kept private and used quietly rather than dumped in public, will not show up anywhere. A clean report is good news about the past. It is not a certificate.

When it is more than a password problem

Everything above assumes the leak is the whole story. Sometimes it is not, and there are specific signs that somebody is already inside rather than merely holding a key: sign-in alerts from places you have never been, messages in your Sent folder you did not write, notifications of a password or recovery-address change you did not make, or two-factor prompts arriving on your phone that you did not trigger.

That last one deserves emphasis because it is widely misread as a glitch. A verification prompt you did not start means someone is entering your correct password right now and is waiting for you to wave them through. Never approve one you did not initiate, and treat it as the moment to change that password from a device you trust.

If any of those signs are present, this stops being a password hygiene job and becomes a cleanup, with a different order of operations — evicting the intruder, cancelling their sessions, and undoing the back doors they left behind. Our guides to a hacked email account and a hijacked Facebook or Instagram account walk through both, and the email one is the priority, because your inbox is the master key to everything else.

How we can help

Most of this you can do yourself in an evening, and if you do, you have genuinely fixed the problem. The parts people call us for tend to be the judgement calls rather than the clicking: confirming a computer is actually clean before anything gets retyped on it, working out whether a flagged cluster of passwords points at a company breach or at the machine on the desk, and sorting out the reuse across a household where four people have been sharing three passwords since 2016.

We also do the setup that stops it recurring — a password manager chosen so that the least technical person in the house will actually use it, two-factor turned on with the recovery codes printed and put somewhere findable rather than saved on the phone that is the second factor, and, for a small business, shared logins arranged so that one leaked password is not the whole company. We do this work across Southern California and the Coachella Valley, and we do not sell subscriptions, monitoring services or antivirus, so the advice about what you need is not a sales pitch.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →