Risk level: critical. Can you change it: yes. Found in 674 breaches in this directory.
What this data is
The secret you use to sign in, stored by the breached service either in plain text, in a scrambled form called a hash, or encrypted. How it was stored decides how quickly it can be recovered.
The risk on its own
A leaked password opens the account it belongs to unless two-factor authentication is on, and it is often recoverable even when the site scrambled it. Weak or common passwords fall to automated cracking quickly. Once recovered, it goes into lists that attackers try against every other major site.
The risk combined with other data
Paired with your email address it is a ready made login. Attackers feed these pairs into credential stuffing tools that test them automatically across email, banking, shopping and social sites. Anyone who reused the password is exposed on every account that shares it, including their main email, which unlocks password resets for everything else.
How criminals use it
Your email and password pair is tested automatically on hundreds of sites, and opens the ones where you reused it.
An attacker gets into your email with the reused password and resets the passwords of your bank and shopping accounts.
A sextortion email quotes the leaked password in the subject line as proof it has hacked your device.
Your old password is used to guess its variations, such as the same word with a new number at the end.
A shopping account with a saved card is used to place orders delivered to a different address.
What to do now
Change the password on the breached account now, and on every other account where you used the same or a similar password.
Start with your main email account, since whoever controls it can reset almost everything else.
Use a password manager such as Bitwarden, 1Password or the one built into your phone to create a unique password for every account.
Turn on two-factor authentication using an authenticator app or passkey on email, banking and social media.
Review recent sign in activity and connected devices on your important accounts and sign out any you do not recognise.
Check your email address with a breach checker to find other leaks that might contain older passwords.
Frequently asked questions
The company said passwords were encrypted. Am I safe?
Not necessarily. Scrambled passwords can often be cracked, especially common ones. Change it anyway, and change it anywhere you reused it.
I got an email quoting my old password and demanding payment. Is it real?
The password probably came from a breach, but the claim to have hacked your device or recorded you is almost always false. Do not pay. Change the password if you still use it.
How do I remember a different password for every site?
You do not have to. A password manager remembers them for you, and you only need one strong master password plus two-factor authentication.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.