Historical passwords leaked: what it means and what to do
Risk level: high. Can you change it: yes. Found in 5 breaches in this directory.
What this data is
Passwords you used on an account before changing them, kept by a service in a password history so you cannot reuse them, or gathered from older breaches into combined lists.
The risk on its own
An old password can seem harmless because you already changed it. The trouble is that people change passwords in predictable ways, such as adding a number or a new year, and many still use an old password on some forgotten account. A list of your past passwords shows an attacker exactly how you build them.
The risk combined with other data
With your email address, historical passwords feed targeted guessing: each old password and its obvious variations are tried on your email, bank and social accounts. Sextortion emails also quote old passwords so a bluff looks like proof of hacking.
How criminals use it
An attacker who sees Summer2019 in your history tries Summer2024 and Summer2025 on your email account.
A forgotten account that still uses the old password is logged into and used to send spam in your name.
A sextortion email quotes a password you used years ago and claims to have recorded you through your webcam.
The pattern in your old passwords is used to guess the master password for your password manager.
What to do now
Change any password that matches or resembles one in the leak, including versions with different numbers or symbols.
Use a password manager to generate new random passwords, so nothing follows your old pattern.
Run your password manager's security report, such as Password Checkup in Google Password Manager or Security Recommendations in the Passwords app on iPhone.
Turn on two-factor authentication or passkeys on email, banking and social media first.
Close accounts you no longer use rather than leaving old passwords active on them.
Ignore emails that quote an old password and demand payment. They are built from breach lists.
Frequently asked questions
I changed that password years ago. Why does it matter?
Because attackers use old passwords to predict new ones, and you may still use the old one on an account you have forgotten.
An email quoted my old password and says it hacked my webcam. Is it real?
Almost certainly not. The password came from a breach list and the webcam claim is a bluff. Do not pay, and change the password anywhere you still use it.
Is adding a number to my old password enough?
No. That is the first variation attackers try. Use a completely new random password from a password manager.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.