If your phone has ever shown you a warning saying one of your passwords has appeared in a data leak, you have probably done one of two things. Panicked for a second, or swiped it away and got on with your day.
Most people swipe. Which is understandable, because nobody ever explains what the notification actually means.
So here it is, in plain English, along with the one thing worth doing about it.
First, your phone has not been hacked
This is what nearly everyone assumes, and it is not what has happened.
What the notification means is that a company you hold an account with has been breached at some point, and your email address and password have ended up in a leaked list that is now circulating online. It could be an online shop you ordered from once in 2019. It could be a forum you forgot you ever signed up to.
Your phone quietly checks the passwords you have saved against those known leaked lists. It does this privately, it does not send your actual passwords anywhere, and it flags anything that matches.
So the phone is fine. The password is the problem.
Why a leaked password actually matters
On its own, one leaked password from some random website is not much of a threat. The danger is if you have used that same password somewhere else.
What criminals do with these lists is automated. They take millions of leaked email and password combinations and try them at scale against everything: online banking, email providers, Amazon, PayPal. Nobody is sitting there targeting you personally. They are running the list and seeing which doors open.
If you only ever used that password on that one site, it is a shrug. If it is the password you use for everything, it is a genuine problem.
What to do about it
Change the flagged password, properly. Change it on the site it relates to, and anywhere else you have used it. And change it properly, not the same word with a 2 on the end. That fools nobody and it is the first thing an automated attack tries.
Turn on two-factor authentication. Wherever it is offered, and especially on banking and email. It means a leaked password on its own is not enough for anyone to get in.
Let your phone generate and save passwords for you. If it offers, say yes. The reason people reuse passwords is that remembering thirty different ones is impossible, and that is the actual problem being solved.
The one account that matters most
If you do nothing else, sort out your email account.
Everything you own runs through your email. Forgotten your banking password? They send a reset link to your email. The same is true of your Apple or Google account, your shopping accounts, your utilities, all of it.
So if someone gets into your email, they do not need any of your other passwords. They can simply reset them, one at a time.
Your email is the master key. It is also, in our experience, the account people are most likely to have reused a password on years ago and completely forgotten about.
Go to your main email account today. Turn on two-factor authentication, check your backup and recovery methods are up to date, and put a strong, unique password on it.
How to check what has been flagged on your phone
On an iPhone, open the Passwords app and tap Security. On older versions of iOS you will find this under Settings, then Passwords, then Security Recommendations.
On Android, open Google Password Manager and run Password Checkup. On a Samsung you can also search "Password Checkup" in Settings to jump straight there.
Both will give you a list of anything that has been flagged as leaked, reused or simply weak. Fair warning: that list is usually longer than people expect, and it can be a bit sobering the first time you look at it.
Do not try to fix all of it at once. Start with your email, then anything that holds your card details, then work down the list at your own pace.
The short version
A password leak notification is not a sign your phone has been compromised. It is a sign that a password you use has appeared in a breach somewhere, and it only becomes dangerous when that password has been reused.
Ten minutes spent changing a few passwords and turning on two-factor authentication for your email is probably the most useful ten minutes you will spend on your phone this month.
If you are not sure where to find any of these settings, or you would like a hand getting two-factor authentication set up properly, pop into the studio on Hollands Road in Haverhill and we will walk you through it. No charge, and no appointment needed for something like this.
Harrison, Calatech

