Is your password in a data breach?
Billions of passwords have leaked from hacked websites over the years. Attackers try those same email and password pairs on other sites, a technique called credential stuffing. If you reuse passwords, one leak from a forum you forgot about can open your email. Here's how to find out and fix it in order.
Step 1: Let your iPhone check for you
Settings › Passwords › Security Recommendations (iOS 17)
Turn on Detect Compromised Passwords. Your iPhone compares your saved passwords against lists of known leaked passwords without sending the passwords themselves to Apple. The list then shows three kinds of problems:
- Compromised: the password appeared in a known data leak. Change these first.
- Reused: the same password is saved for more than one site. One leak exposes all of them.
- Weak: short, common or easy to guess, such as a name followed by a year.
Step 2: Fix them in this order
- Email. Whoever controls your inbox can reset every other password.
- Apple Account. It protects your backups, photos, purchases and Find My.
- Banking, payment and shopping accounts with saved cards.
- Social media and messaging, which scammers use to message your contacts.
- Everything else, a few at a time. Old accounts you no longer use can often be deleted instead.
When you change a password, let iPhone suggest a strong one. Tap the password field and choose Use Strong Password. You don't need to remember it; it syncs through iCloud Keychain.
Step 3: Make a leak harmless next time
Two-factor authentication means a stolen password alone isn't enough to sign in. Turn it on for every account that offers it, starting with email. An authenticator code is safer than a text message code, because phone numbers can be hijacked.
Passkeys replace the password entirely. When a site offers "Sign in with a passkey", accept it. The passkey stays on your devices and can't be phished or leaked from the site's servers.
Good to know
A password appearing in a leak doesn't always mean that specific account was broken into. It means the password is on lists attackers use. Treat it as burned and replace it everywhere you used it.
What about my email address or phone number?
The Passwords app checks passwords, not whether your email, phone number or address appeared in a breach. Breach-alert services watch for those details and tell you when they show up in a new leak. They can't remove leaked data, but they tell you which accounts to secure and warn you to expect targeted scam emails.