Before you begin

If you save passwords in Chrome, Google Password Manager can check those credentials for known compromises, reuse across sites, and weak combinations. The results are a prioritization tool, not a guarantee that every unflagged account is safe.

Run the check on a device you trust. Avoid public or shared computers, and make sure you are signed in to the intended Google account before changing anything.

Check passwords on a computer

  1. Open Chrome’s three-dot menu.
  2. Select Passwords and autofill → Google Password Manager.
  3. Choose Checkup in the side menu.
  4. Complete identity verification and review the results.

You can also visit passwords.google.com in another browser to review credentials stored in the same Google account. Menu names can change by browser version, so use Google’s current help page if your screen differs.

Understand the three warning types

“Compromised” means the credential may match information found in a known breach and deserves the fastest response. “Reused” means the same password protects more than one service; a breach at one site could then unlock another. “Weak” generally means the password is short or easy to guess.

Do not prioritize only by the number of warnings. Email, mobile carrier, financial, cloud storage, and password-manager accounts often control recovery for other services. Secure those first. If an account is obsolete, go directly to the official site to delete it and remove the saved credential afterward.

What to do after a compromise warning

Open the service’s official app or type its address yourself, then set a new password that you have never used elsewhere. Review recent sign-ins and connected devices, sign out unknown sessions, and verify that the recovery email and phone number are yours. Turn on two-step verification or a passkey when supported.

If the affected account is your email, inspect forwarding rules and filters. An attacker may create a rule that hides password-reset messages. For a financial account or payment method, contact the provider through its official support channel if you see unfamiliar activity; changing the password alone may not resolve a fraudulent transaction.

Build stronger replacements

Use a long, unpredictable, unique password for every site. A password manager can generate and store these values so you do not need to memorize them all. Protect the password manager itself with a particularly strong primary credential and multi-factor authentication.

If a service supports passkeys, consider adding one. Passkeys reduce the need to type a reusable secret into websites and can resist many phishing attempts. Before removing an existing login method, confirm that the passkey sync and account-recovery process work on your other devices.

Turn on ongoing warnings

A manual check shows the state known at that moment. Chrome’s security settings can also warn you when a saved credential appears in a known compromise. The exact option may vary between standard and enhanced protection, so read the description shown in your current version.

Automatic warnings are one layer of defense. They may not immediately cover a credential entered into a phishing page, a password stored only on another device, or a breach that has not yet been discovered. Unique passwords, two-step verification, software updates, and careful link checking still matter.

Do not use a public computer

Avoid checking or changing passwords on a library, hotel, school, or internet-café computer. You cannot reliably verify whether it records keystrokes, captures the screen, or retains a session. Use your personal device and a trusted connection instead.

On a family computer, separate operating-system profiles and use a screen lock. Anyone who can access your browser-sync account may also affect saved credentials. Never save a new password when a public browser prompts you to do so, and sign out of every session if emergency use was unavoidable.

Watch for phishing during cleanup

A checkup result may offer a link to change a password, but confirm the domain before entering credentials. If the destination looks unfamiliar, close it and navigate to the official site yourself. Never share a password, recovery code, or one-time verification code with someone claiming to help.

Take notes about which accounts you changed, but do not put passwords or recovery codes in screenshots or plain-text documents. If you receive threats, financial demands, or evidence of account takeover, preserve non-secret details such as timestamps and usernames and contact the relevant provider.

Completion checklist

  • Change email, financial, carrier, and recovery accounts first.
  • Give every reused account a different new password.
  • Remove unknown sessions and connected devices.
  • Verify recovery details and enable two-step verification.
  • Check for suspicious messages, forwarding rules, and transactions.

The goal is not merely to make the warning count reach zero. It is to stop one compromised account from becoming the key to every other account you own.