What to Do if Your Password Shows Up on the Dark Web
Finding out that one of your passwords is circulating on the dark web is unsettling, but it is not the end of the world, and it is not a sign that you did something wrong. Passwords leak constantly, usually because a company you had an account with was breached, or because malware quietly copied it from a device. What matters now is how quickly and completely you respond. Here is exactly what to do, in the right order.
First, what it actually means
A password "on the dark web" means the login is out of your control and available to criminals, who will try it (often automatically) against many services. It does not necessarily mean your account has already been broken into. Think of it as someone having a copy of your key: the lock still works, but you want to change it before they walk in. The goal for the next few minutes is to close that window before anyone uses it. (If you landed here from a browser alert, we also break down exactly what "the password you used was found in a data breach" means.)
The steps, in priority order
1. Change the password on the affected account now
Go straight to the account that leaked and set a new password that is long, unique, and not a small tweak of the old one. ("Summer2024!" becoming "Summer2025!" does not count.) If you can, do this from a device you trust.
2. Sign out of all active sessions
Changing the password is not always enough on its own. If a session cookie leaked alongside it, an attacker may already be logged in, and can stay logged in even after you change the password. Most major services have a "log out of all devices" or "sign out everywhere" option in their security settings. Use it.
3. Turn on two-factor authentication
Two-factor authentication (a code from an app or your phone, in addition to the password) means a leaked password alone is useless to an attacker. Turn it on for the affected account, and for your most important accounts generally. An authenticator app is stronger than SMS, but SMS is far better than nothing.
4. Change the password anywhere you reused it
This is the step most people skip, and it is the one that causes the most damage. Attackers assume you reused the password, and they test it against email, banking, and popular apps automatically. If that leaked password protects any other account, change those too, starting with your email.
5. If it came from malware, clean the device
If the leak came from an infostealer (malware that copies saved passwords from a device), changing passwords is not enough while the malware is still there, because your new passwords can simply be stolen again. Run a reputable malware scan on the affected device, and only log back in once it is clean.
6. Watch for follow-on attacks
After a leak, keep an eye out for unexpected password-reset emails, login alerts, or unusually well-targeted phishing messages. These can be signs that someone is testing what else they can reach.
A few special cases
- It's your email password. Treat this as the top priority. Your email is the reset key to almost everything else, so a compromised inbox can unlock a chain of other accounts. Change it, enable two-factor, and check your forwarding and recovery settings for anything you did not add.
- A session cookie was included. This is session cookie theft, and a password change alone will not lock the attacker out. Signing out of all sessions (step 2) is essential here.
- It's a business account. Consider who else uses it, revoke any shared access, and check connected vendor or admin permissions. Let the right person on your team know so nothing slips through.
What not to do
- Don't ignore it. "Nothing has happened yet" is not safety. It is the window before something does.
- Don't just tweak the old password. A predictable variation is easy to guess. Make it genuinely new.
- Don't reuse the new password anywhere else. That is how one leak becomes many.
How to stop it happening again
Two habits prevent most of this pain. First, use a password manager so every account has a long, unique password you do not have to remember. Second, put monitoring in place so that the next time a credential leaks, you find out immediately instead of months later. A leak you know about within the hour is a minor chore. One you discover after the damage is done is a crisis. Not sure whether you are already exposed? Here is how to check if your business email has been in a data breach.
How GuardPilot helps
GuardPilot watches dark-web marketplaces and infostealer logs for your emails and domains, and alerts you the moment a login appears. Instead of a scary, jargon-filled warning, you get a plain-English explanation of what happened and a short, guided checklist that walks you through every step above, in the right order. We even track your progress and remind you until the incident is fully resolved. You can start a free scan in about two minutes.
The takeaway
A leaked password is common, and fixable. Change it, sign out everywhere, turn on two-factor, and update anywhere you reused it. Do that quickly and the exposure becomes a non-event. The real key is speed, and speed comes from finding out early.
See what’s already exposed.
Run a free scan of your business email and domain. It takes about two minutes.
Start your free scan →