You probably know the routine: one familiar password for important accounts, another for shopping, and a third with an extra number or symbol when a website demands something different. It feels manageable—until a breach at one service puts several accounts at risk.
The solution is not to memorize dozens of complicated replacements. It is to stop making your memory responsible for every login.
A password is not automatically unsafe because it is five years old. Reuse, predictability, and exposure are the more important issues. The practical path forward is to use passkeys where available, a password manager for passwords you still need, and multifactor authentication to strengthen password-based access.
Why Reusing Three Passwords Creates More Than Three Risks
When attackers obtain a username and password from one service, they can test that combination elsewhere. This attack is called credential stuffing. Password reuse turns an isolated breach into an opportunity to access unrelated accounts.
Imagine that your shopping account and primary email share a password. If that credential is stolen from the retailer, an attacker might use it to enter your inbox. From there, password-reset messages could provide access to other services. Your email is not just another account; it is often a recovery channel for your digital life.
Small variations offer little reassurance. Adding a year, changing capitalization, or replacing a letter with a symbol does not create a reliably independent password. The Federal Trade Commission recommends changing reused and similar passwords when a password is exposed.
Should you change passwords just because they are old?
Not necessarily. NIST’s digital identity guidance rejects mandatory periodic password changes while requiring changes when there is evidence of compromise. A long, unique password does not become weak simply because its birthday passes.
Replace passwords that are reused, predictable, exposed, or similar to a compromised password. For work accounts, follow your organization’s procedures rather than bypassing its requirements.
The goal is not constant password rotation. It is preventing one stolen credential from opening multiple doors.
Start With the Accounts That Can Unlock Everything Else
You do not need to fix every account in one sitting. Start with the accounts whose loss would cause the greatest damage:
- Primary email: Protect the inbox that receives password-reset messages.
- Password manager and credential-sync accounts: These protect access to your other credentials.
- Financial and sensitive accounts: Prioritize banking, payments, healthcare, and important personal records.
- Work and school accounts: Follow approved security and recovery procedures.
- Remaining accounts: Continue through shopping, social media, subscriptions, and older services.
This is a practical starting order, not an inflexible rule. An actively compromised account needs immediate attention.
Choose a Password Manager You Will Actually Use
A password manager generates and stores unique passwords, removing the need to remember each one. The UK’s National Cyber Security Centre recommends password managers as a practical way to improve account security.
Choose an approach that fits how you work:
- Built-in browser or device manager: Convenient, but confirm that credentials are accessible across your devices and browsers.
- Third-party manager: Useful across mixed platforms; compare compatibility, cost, sharing controls, and recovery options.
- Local-only manager: Keeps the database off a synchronization service, but makes backups and multi-device access more your responsibility.
Before committing, examine encryption, security updates, MFA support, recovery procedures, and export options. The NCSC’s password-manager buying guide explains these considerations.
Is keeping everything in one place risky?
Yes, a vault concentrates valuable information. That tradeoff deserves attention, not dismissal. NCSC nevertheless concludes that the benefits outweigh the risks.
Protect the vault with a strong, unique primary password and MFA where supported. Understand recovery before you need it. Keep essential recovery material somewhere secure that remains accessible if you cannot open the vault.
Be careful when migrating: password exports may be unencrypted. Do not leave them in Downloads, email, or cloud storage after the transfer.
Replace Reused Passwords With Generated Ones
For accounts that still require passwords, use long, random, unique credentials. CISA recommends at least 16 characters and a different password for every account.
Use this repeatable workflow:
- Open the service’s legitimate app or website directly.
- Find its password-change settings.
- Generate a password in your manager that meets the service’s requirements.
- Submit the change to the service and update the matching vault entry.
- Confirm that the saved credential works.
Editing a password-manager entry does not change the password at the website. Both must match. This simple distinction prevents frustrating lockouts during a cleanup.
For a password you must memorize, such as your vault’s primary password, consider a long passphrase made from randomly selected, unrelated words. Avoid quotations, personal facts, and published examples. A familiar phrase is easier to remember, but it may also be easier to predict.
Add MFA—and Prefer Phishing-Resistant Options
Multifactor authentication adds another kind of proof beyond a password. The FTC recommends enabling it, particularly for sensitive accounts.
The available methods are not equally protective:
- FIDO security keys and passkeys: Support phishing-resistant authentication because authentication is bound to the legitimate service.
- Authenticator-app codes: Avoid phone-number takeover risks associated with text messages, but manually entered codes can still be phished.
- Text-message codes: Better than no second factor when that is the only option, but vulnerable to attacks such as SIM swapping.
Look for “two-factor authentication,” “two-step verification,” or “multifactor authentication” in security settings. Save recovery codes securely, and never approve an unexpected sign-in prompt.
MFA is an additional layer, not permission to reuse passwords. It also does not eliminate risks from malware, stolen sessions, or weak account-recovery processes.
Use Passkeys Where Available, With a Recovery Plan
A passkey uses cryptographic keys instead of a password you type. You typically authorize its use with your device’s fingerprint reader, face recognition, or PIN. The FIDO Alliance explains that passkeys are unique to each service and designed to resist phishing.
For example, a counterfeit login page can trick you into entering a password. A passkey is designed not to authenticate you to that imitation site.
Understand where your passkeys live:
- Synced passkeys can become available across devices through a provider. Protect that provider account and understand its recovery process.
- Device-bound passkeys remain on a particular device or security key. Plan for loss or failure, including a backup authenticator where supported.
Only create passkeys on devices you control and trust. Google warns that someone able to unlock your device may be able to access your account. Its guidance also notes that adding a passkey does not automatically remove password sign-in.
Keep any remaining password unique. Test the new sign-in method and confirm recovery options before removing an existing method.
If a Password Has Already Leaked, Act Beyond the Reset
Replace the exposed password and every reused or similar version elsewhere. Do not simply add another digit.
If someone accessed the account, use the provider’s official recovery process from a trusted device. Following the FTC’s account-recovery guidance, also:
- Sign out other sessions using the service’s controls.
- Review MFA and recovery email addresses and phone numbers.
- Remove email-forwarding rules you did not create.
- Warn contacts if the account sent fraudulent messages.
If malware is suspected, update security software, scan, and remove detected threats before proceeding with recovery. Report work-account incidents promptly through your organization’s security process.
Your Password-Cleanup Checklist
- ☐ Identify reused, similar, weak, and exposed passwords.
- ☐ Secure primary email and other high-impact accounts first.
- ☐ Choose a password manager and understand its recovery process.
- ☐ Protect the vault and credential-sync accounts.
- ☐ Generate a different strong password for each account.
- ☐ Enable MFA for password-based sign-ins.
- ☐ Add passkeys where supported.
- ☐ Test recovery options for a lost phone or security key.
- ☐ Respond promptly to security alerts.
- ☐ Schedule another cleanup session—not automatic password rotation.
Retire the Habit, Not Just the Passwords
Replacing three old passwords with three new ones preserves the underlying problem. Better security comes from a system that makes uniqueness easy and limits the damage from any single compromise.
Start today with your primary email. Give it a unique credential, enable the strongest authentication available, and verify recovery. Then repeat that process for your next most important account. You do not need a better memory. You need a safer routine.