Pinzen
GuidesUse casesFAQSupportOpen Pinzen
  1. Home
  2. Guides
  3. How Often Should You Change Your Password? What Experts Say Now

Breaches and Hacked Accounts

How Often Should You Change Your Password? What Experts Say Now

How often should you change your password? Not every 90 days. Experts now say only when there's a reason, like a breach. Shared codes are the exception.

Last updated October 4, 2026 · 7 min read
On this page
  1. How often should you change your password? A quick guide
  2. Why the every-90-days rule went away
  3. When you should change a password right away
  4. The exception: PINs and codes other people know
  5. What to do instead of regular changes
  6. Setting reminders for the codes that do need rotating
  7. Frequently asked questions

You don't need to change a strong, unique password on a schedule. Experts now advise changing it only when there's a reason to think someone else has it, such as a data breach, a warning that it was leaked, or sharing it with someone who no longer needs it. The exception is codes other people know, like door codes and shared PINs, which are worth changing once or twice a year.

If you were taught to change every password every 90 days, you can stop.

How often should you change your password? A quick guide

  • Strong, unique passwords for personal accounts: no set schedule. Change them when something happens, like a breach alert.
  • Weak or reused passwords: now, even if nothing has gone wrong.
  • Your email password: first, at any sign of trouble, because email can reset your other accounts.
  • Passwords you've shared, like streaming or Wi-Fi: when someone who knew them no longer needs access.
  • Door, garage, alarm, and smart lock codes: when someone's access ends, and every 6 to 12 months.
  • Your bank card PIN: when someone may have seen it or you shared it.
  • Work or school accounts: whatever your organization requires.

Why the every-90-days rule went away

For years, many workplaces had a password expiration policy that made everyone pick a new password every 60 or 90 days, a practice often called password rotation. The idea was that a stolen password would stop working before it did much harm.

In practice, it backfired. Forced to invent new passwords, people take shortcuts, like adding a number or turning "Summer2026!" into "Autumn2026!" next time.

Attackers know these patterns. When researchers at the University of North Carolina studied real accounts that required regular changes, they could often guess the new password from the old one within seconds.

Forced changes also push people toward sticky notes and reused passwords. A weak password changed often is still a weak password.

In 2017, the National Institute of Standards and Technology (NIST), whose password guidelines many organizations follow, began advising against scheduled changes. Its current digital identity guidelines, updated in 2025, still say organizations should not require them.

Instead, organizations should force a change when there's evidence a password has been compromised, meaning someone other than you may know it. The same guidelines favor long passwords over forced symbol rules. Microsoft and the UK's National Cyber Security Centre give similar advice.

A strong, unique password that nobody else knows doesn't wear out. Change it when something happens, not when the calendar says so.

So should you change passwords regularly? Not personal ones that are strong and unique. If your job or school still makes you change your password every 90 days, follow the rule, but let a password manager create a fresh random password each time instead of tweaking the old one.

When you should change a password right away

Real events are a far better trigger than the calendar.

A breach alert or a compromised-password warning

If a company tells you it had a data breach, or your phone or browser warns that a saved password showed up in a leak, change that password now. Then change it anywhere else you used it. Attackers try leaked passwords on other sites, which is called credential stuffing.

Not sure what the alert is telling you? Here's what a compromised password warning means on iPhone and Google. For a complete plan, use our step-by-step data breach checklist.

You were tricked, or you see signs someone got in

Change the password right away if:

  • You typed it into a page you later realized was fake.
  • You gave it to someone who turned out to be a scammer.
  • You get sign-in alerts or password-reset emails you didn't ask for.
  • Your email account was hacked.

If your email is involved, fix it first. Whoever controls your inbox can reset almost every other account, so change that password and sign out any devices you don't recognize.

You shared it, or someone left the household

If you gave a password to a babysitter, roommate, contractor, or former partner, assume they still know it. Change it when the arrangement ends.

After a separation or when someone moves out, change the passwords for important accounts in one sitting, starting with email and banking. Our checklist for changing passwords after a divorce or breakup walks through the order.

Removing someone from a shared password vault stops future access, but they may remember or have copied what they saw. Change those passwords too.

A lost or stolen phone or laptop counts as well. Sign it out of your accounts remotely, then change the passwords saved on it, especially if it had no screen lock.

The exception: PINs and codes other people know

Regular changes still make sense for one group: codes that several people know. You can't tell who has remembered, written down, or passed along the number.

Think about:

  • Front door, garage, and gate keypad codes
  • Smart lock codes you gave a cleaner, dog walker, or relatives
  • Your alarm system code
  • A key lockbox code for a caregiver or neighbor
  • The Wi-Fi password guests have used

Online accounts often add extra checks, like confirming a sign-in from a new device. A door code is just a number, and anyone who knows it can walk in.

For these, change the code whenever someone's access ends, and also once or twice a year. If your smart lock allows it, give each person their own code, so you can delete one without changing everyone's. Our guide on how often to change your door code and home PINs goes deeper.

Wi-Fi has a real tradeoff: a new password means reconnecting every device. A guest network, which many routers offer, lets you change just the guest password.

What about bank card PINs?

Bank PINs sit in the middle. If only you know yours and you cover the keypad, there's no need to change it on a timer.

Change it if someone may have seen it, if you shared it with a relative or caregiver, or if your bank flags unusual activity. For the new one, skip obvious choices like 1234 or a birth year.

If the card is lost or stolen, call your bank right away to lock or replace it. Be wary of any call or text that claims to be your bank and asks for your PIN. A real bank won't ask, so hang up and call the number on the back of your card.

What to do instead of regular changes

Breaches aren't always discovered right away, so you need habits that protect you before you hear about one.

  1. Use a different password for every account. Reuse is what turns one leak into many hacked accounts.
  2. Make each password long and random. A password manager can create and remember them. For the few you must type, four random words are strong and easier to remember.
  3. Turn on two-step sign-in. It asks for a second proof, like a code from an authenticator app (a phone app that shows a new code every 30 seconds), so a leaked password alone isn't enough to get in.
  4. Use passkeys where offered. A passkey lets you sign in with Face ID, a fingerprint, or your screen lock instead of a password, so there's nothing for a site to leak or a fake site to steal. See our plain-English guide to passkeys.
  5. Check for weak, reused, and exposed passwords. Fix those first. You can also look up your email address on Have I Been Pwned, a free site that tracks known breaches.

A password manager can do this for you. Pinzen's password health check flags weak, reused, and exposed passwords. To spot exposed ones, it uses Have I Been Pwned without sending your password: only 5 characters of a hash (a scrambled fingerprint of the password) leave your browser for that lookup.

Setting reminders for the codes that do need rotating

Few people remember when the garage code last changed, so a simple routine helps.

  1. List the codes other people know. Door, garage, alarm, smart lock, Wi-Fi, and any PIN you've told a family member.
  2. Note who has each one. They'll need the new code.
  3. Pick a rhythm. Once a year suits most homes, or every six months if lots of people know the code.
  4. Keep the new code in one safe place. A password manager beats a note on the fridge or an old text thread.
  5. Set a reminder. Use your calendar, or the app where you keep the code.

Pinzen stores PINs for banks, cards, doors, and devices, and it offers rotation reminders for PINs. You can create a free vault to keep your household codes in one place. Seeing them together makes it easy to spot the ones you've never changed.

Whatever tool you use, the goal is the same: change what's at risk, when it's at risk, and leave strong passwords alone.

Frequently asked questions

How often should you update your passwords?

There's no set schedule for a strong, unique password only you know. Update it after a breach, a compromised-password warning, a scam, or any sign someone else got in, or when someone who knew it no longer needs it. Replace weak or reused passwords now, and change shared door and alarm codes once or twice a year.

Does NIST still recommend changing passwords every 90 days?

No. NIST has advised against scheduled password changes since 2017, and its current guidelines say organizations should not require them but should force a change when there's evidence a password has been compromised. Some employers and schools still have their own expiration policies, so follow those for work or school accounts.

Should I change my password if I haven't been hacked?

Only if there's a reason. Replace any password that's weak, short, or reused, even if nothing has gone wrong, because it's easy to guess or try elsewhere. A strong, unique password you've never shared can stay as it is, especially with two-step sign-in turned on.

How often should I change my bank PIN?

There's no need to change it on a timer if only you know it. Change it if someone may have seen it or you shared it with a helper, and call your bank if the card is lost or stolen. For a routine, a yearly reminder works, and Pinzen's PIN rotation reminders can help.

Keep your family's passwords in one safe place

Pinzen is free to start. Sign up with Face ID, save your Recovery Kit, and share only what you choose.

Create a free vault

Keep reading

Breaches and Hacked AccountsI Gave a Scammer My Password: What to Do in the Next Hour8 min readBreaches and Hacked AccountsIs Have I Been Pwned Safe? How Password Checks Stay Private7 min readBreaches and Hacked AccountsMy Email Was in a Data Breach: What It Means and What to Do8 min read
Pinzen

A private place for the passwords your household depends on.

ProductFeaturesFamily use casesGuidesPlatformsPricing
ResourcesFAQSecurityHelp & supportShare your story
LegalPrivacy policyTerms of use© 2026 Pinzen