The Password Leak Check

Most account takeovers do not start with a scam call; they start with a password that leaked in a breach years ago and was never changed. The parent keeps using it, and one day the bank account is empty. This page is the check that finds leaked passwords, the change order that stops the bleeding, and the fix that makes it stick.

Last reviewed August 2026 Reading time: 6 minutes

do this with the parent's permission

The password leak check

Breaches are routine and stolen password lists circulate for years. A parent with one password for everything is one leak away from losing everything. The check runs in order, and the fix that sticks is a password manager.

  1. Step 1Check the email addressesUse the IdentityTheft.gov data-breach tools and similar breach-check services to see which breaches the parent's email appeared in. Do the main email first: it is the key to every other account.
  2. Step 2Check the passwordsEnter the parent's passwords, not just the email, into the breach checker. A password that shows up anywhere is compromised everywhere it was reused, no exceptions.
  3. Step 3Change the important accounts firstEmail, bank, and anything with saved payment methods, in that order, then turn on two-factor on the email. The passwords and accounts guide has the sequence.
  4. The fix that sticksA password manager ends the reuse problemA manager generates a different password per account, and the parent-friendly guide covers the setup. Family rule: if a breach check shows a password, that password is retired everywhere. If a takeover already happened, the 60-minute response is the recovery path.

Do this with the parent's permission. The check touches the parent's accounts and email; work through it together, the same way the won't-share-passwords guide handles the trust side.

Not the page you need? This page is about checking whether the parent's passwords were exposed in a data breach. If the real problem is that the parent uses the same password everywhere, see the same password everywhere guide for the fix.

Why leaked passwords matter

Breaches are routine and the stolen password lists circulate for years. Scammers test those lists against email addresses and reuse the working ones across sites, a pattern the FTC's identity theft guidance calls out. A parent with one password for everything is one leak away from losing everything.

The check, in order

  1. Check the email addresses. The IdentityTheft.gov data breach tools and similar breach-check services tell the family which breaches a parent's email appeared in. Do this for the main email first; it is the key to every other account.
  2. Check the passwords. Enter the parent's passwords, not just the email, into the breach checker. A password that shows up anywhere is compromised everywhere it was reused.
  3. Change the important accounts first. Email, bank, and anything with saved payment methods, in that order. The passwords and accounts guide has the sequence.
  4. Turn on two-factor on the email. The two-factor guide shows the settings; the email account with two-factor is the one account a scammer cannot quietly reset.

The fix that sticks

A password manager ends the reuse problem by generating a different password per account, and the password manager guide is written for parents who have never used one. The family rule: if a breach check shows a password, that password is retired everywhere, no exceptions.

If the takeover already happened

The accounts compromised workflow is the recovery path, and the identity theft response guide covers credit freezes and fraud alerts when money or personal data was involved. The family password vault closes the loop so the parent is never alone with this again.

Related guides

Sources & verification

This page is checked against the standards in our editorial policy. Reviewed August 2026:

Found an error? Report it: we log and correct material mistakes publicly.

Found an error? Report it.