Why email takes priority
Email often receives links for changing passwords on other accounts. Someone with access may read messages, impersonate you and attempt to take over connected services. Your email password therefore needs to be separate, even if you already use an extra sign-in check.
Make passwords you can maintain
- Give every account a long, unique password. Names, dates and small variations on one password are poor patterns.
- Use a password manager to generate and store passwords. On a work device, use a solution approved by your organisation.
- Protect the manager with a strong master password and an additional factor where supported. Check how to regain access if you lose your device.
- Do not save passwords in the browser on a public computer or someone else’s device.
If a service offers a passkey, consider that option using its official instructions. For accounts that use passwords, a unique password and 2FA remain important.
If a password has already been exposed
From a trusted device, open the service’s official app or website. Change the affected password and every account where it was reused, prioritising email and financial services. Review active sign-ins and remove unfamiliar sessions according to the provider’s instructions.
If you cannot sign in or notice unfamiliar changes, follow the account recovery guide. If banking information is exposed or you see a suspicious transaction, contact your bank immediately through an official channel. Do not include passwords or one-time codes in an incident report.
One change to make today
Cannot find the password control? Open the steps for your Google, Microsoft, Apple or other supported account.
Check that your email has a separate password and a second factor enabled. Then work through your other important accounts one at a time.