Breaches and Hacked Accounts
What Does Compromised Password Mean on iPhone and Google?
What does compromised password mean on iPhone or Google? Here's what the alert checks, why it rarely means you were hacked, and which passwords to fix first.
Last updated October 4, 2026 · 8 min readWhat does compromised password mean? When your iPhone or Google flags a password as compromised, it has found that password in a known data leak, so it's no longer secret. It doesn't mean your phone was hacked, but you should change that password soon, on the site it belongs to.
The warning looks alarming, but it's fixable. Here's what the alert checks, how to spot a real break-in, and which passwords to fix first.
What does compromised password mean on iPhone, Android, and Chrome?
The wording depends on where your passwords are saved, but the meaning is the same everywhere. That password has shown up in a data leak, so criminals may already have it.
- iPhone, iPad, or Mac: Open the Passwords app and choose Security. Flagged accounts show a note such as "This password has appeared in a data leak." On older software, look in Settings, then Passwords, then Security Recommendations.
- Android or Chrome: Google Password Manager has a Password Checkup that lists compromised passwords. Find it in Chrome's settings or at passwords.google.com. Chrome may also pop up a warning when you sign in with a leaked password.
- Other password managers: Look for a security or password health report.
What the alert checks, and what it doesn't
A data breach, or leak, is when a company's customer data is stolen or exposed, often including passwords. Those passwords end up in lists that criminals share and sell. Some lists also come from malware, which is harmful software that steals passwords saved on infected computers.
Apple's Passwords app, Google Password Manager, and many other password managers compare your saved passwords against these lists. If one matches, it gets flagged.
A match tells you that password is out there. Here's what it can't tell you:
- Which site leaked it. If you used the same password in several places, the leak could have come from any of them, not just the account that was flagged.
- Whether it was your copy. Some checks look only at the password. If yours is common, like "Summer2024!", the match may come from a stranger who picked the same one. Other checks compare your username and password together, which points more directly at your own account.
- Whether anyone used it. The alert doesn't mean someone has signed in to your account.
The check also only covers passwords saved in that app. It can't check ones you keep in your head or in a notebook.
To see which known breaches included your email address, search for it on Have I Been Pwned, a free breach lookup site.
Wherever the leak came from, treat every match as real. Once a password is on a leaked list, criminals can try it anywhere you've used it.
Does it mean your phone or account was hacked?
Usually not. The alert is about a password, not your device. The leak most likely happened at a website or app you signed up for, sometimes years ago.
Think of it like learning that a copy of your house key is floating around. Nobody has broken in, but you'd still change the lock.
There's one exception. If lots of strong passwords you never reused are flagged at once, malware on a computer may have copied them. Scan your computers for malware and install updates, then change those passwords from a device you trust.
Signs that someone actually got into an account look different:
- A sign-in alert from a device or place you don't recognize
- Password reset or security emails you didn't ask for
- Messages, posts, or purchases you didn't make
- Being locked out when your password should still work
If you see any of these, follow our step-by-step checklist for after a data breach. If it's your email account, start with our plan for recovering a hacked email.
How to fix compromised passwords in the right order
A long list of flagged passwords can feel overwhelming, but you don't have to fix them all today. Start with the accounts that would hurt most if someone got in. If you're helping a parent, sit down together and do the most important few in one go.
For each flagged password:
- Go to the site or app yourself. Scammers send fake "your password was compromised" texts and emails, so don't tap links in them.
- Open the account or security settings and choose a new password.
- Make it long, random, and used nowhere else. A password manager can create one for you. For the few you type by hand, four random words work well.
- When your phone or browser offers to save the new password, say yes. Otherwise the old one stays saved and keeps getting flagged.
Start with email and banking
Fix these first, in this order:
- Your main email account. Whoever controls your email can use "forgot password" to get into almost everything else. After changing it, check that the recovery phone and backup email are yours, and sign out any devices you don't recognize.
- Banking, credit cards, and payment apps. This includes PayPal, Venmo, and shopping sites that store your card.
- Your Apple Account (formerly Apple ID) or Google account. These hold backups, photos, and often your saved passwords.
- Your phone carrier and tax or government accounts. Criminals can use these to take over your phone number or steal your identity.
Then add a second lock to these accounts. Two-step verification asks for something extra after your password, such as a code from an authenticator app. That's a phone app that shows a new code every 30 seconds.
Where a site offers passkeys, consider setting one up. A passkey lets you sign in with Face ID, a fingerprint, or your screen lock, and there's no password for a leak to expose.
Then anything that shares the same password
Next, deal with reuse. If the flagged password also opens three other accounts, all four are at risk, even if only one shows a warning.
Criminals count on reuse. They use software to try leaked email-and-password pairs on other sites. This is called credential stuffing, and it's how an old leak becomes a hacked account somewhere else.
Give every account that shared the flagged password its own new password. If family members use one of those accounts, share the new password in person or through a password manager's shared vault, not by text.
Then work through the rest of the list, like old forums, games, and free trials. If you no longer use an account, consider deleting it instead.
Once you've finished, you don't need to change passwords on a schedule. Experts now advise changing a password when there's a reason, such as a leak. Here's how often you should change your password, and why.
Why you keep getting alerts
Fixed a few and still seeing warnings? These are the usual reasons:
- The saved copy didn't update. If your phone didn't save the new password, the old one stays flagged. Update the saved entry, and delete any old copies.
- It's saved in two places. Many families save passwords both on their iPhone and in Chrome. Each one checks its own list, so update both.
- One password, many sites. A reused password can be flagged once for every site that uses it.
- New leaks keep happening. A password that was fine last month can appear in a new leak this month. That's not your fault.
- Simple passwords keep turning up. Common words and patterns appear in leak after leak. Long, random passwords rarely do.
You may also see other labels. Here's what each one means:
- Compromised or exposed: it appeared in a leak. Fix these first.
- Reused: it's on more than one account.
- Weak: it's easy to guess.
Hiding an alert doesn't make the password safe. If you're putting one off, make a note to come back to it.
Checking passwords without revealing them
How can anything check your passwords without seeing them? It uses a hash, a one-way scramble that turns a password into a string of letters and numbers. The same password always gives the same hash, but you can't unscramble it.
A well-designed check sends only the first few characters of that hash. The service replies with every leaked hash that starts the same way, often hundreds of them. Your device then finishes the comparison privately.
This is called k-anonymity: your request blends in with many others, so the service can't tell which password is yours. Our guide on whether Have I Been Pwned is safe walks through it step by step. Apple and Google say their checks also keep your passwords private.
Pinzen's password health check flags weak, reused, and exposed passwords in your vault. Its exposure check uses this Have I Been Pwned method, so only five characters of a hash ever leave your browser, never the password itself. Here's how Pinzen protects your vault.
The health check comes with the free plan. So does importing from another password manager with a CSV file, which is a spreadsheet-style export. Delete that file afterward, since it holds your passwords in plain text.
The free plan works on one trusted device at a time. Pinzen+ adds sync across devices. You can create a free vault whenever you're ready.
A password manager can't undo a leak that already happened. What it can do is make the cleanup easier: a unique, random password for every site, and one clear list of what still needs attention.
Frequently asked questions
What does compromised password mean on iPhone?
It means a password saved on your iPhone matches one found in a known data leak. The leak almost always happened at a website or app, not on your phone. Open the Passwords app and tap Security to see which accounts are affected, then change those passwords.
Does a compromised password mean I've been hacked?
Usually not. It means the password is no longer secret, not that someone has used it. Change it soon and watch for real warning signs, like sign-in alerts you don't recognize or reset emails you didn't request. If many unique passwords are flagged at once, check your computers for malware.
Why does my iPhone say my password appeared in a data leak?
Your iPhone checked your saved passwords against lists of leaked ones and found a match. The leak may have happened at a site you used years ago, or at any site where you reused that password. If it's a common password, someone else may have picked it too, but change it anyway.
How do I fix compromised passwords?
Start with your email, then banking and payment accounts. Go to each site directly and set a new, unique password, including on any account that shared the old one. Then turn on two-step verification and update your saved passwords so old entries stop triggering alerts.