According to the Passwords app I have 517 of compromised passwords

I've noticed this too late into the day. There really are 517 cases to sort.


Is changing them manually one by one the only way to get his sorted? This could take forever plus a potential of thousands of confirmation emails to receive and click etc.


Is there any way of simplifying this process? Or just ignore and hope for the best?

MacBook Pro 16″

Posted on Jan 25, 2026 2:17 AM

Reply
Question marked as Top-ranking reply

Posted on Jan 25, 2026 2:57 PM

I would recommend that you prioritize first, and then decide how to handle the rest.


First, change the passwords of all of the accounts that could cause you significant harm if taken over (e.g. email accounts, financial accounts, retirement accounts, government accounts, cloud storage accounts, etc.). While you are at it, make sure that you are using password best practices for each new password:


  1. Length is very important, so at least 14 characters
  2. Use a unique password for every account (reusing passwords is likely what got you into this mess)
  3. Unguessable (don't use patterns or any information that would be known from social media)
  4. For any significant account you may need to remember without the use of your password manager (such as if you lost your phone when on travel), use a strong but easy to remember passphrase
  5. For all other accounts you can use a completely random password because your password manager will fill it for you.
  6. Always enable multi-factor authentication and take the time needed to store MFA/2FA recovery codes and information carefully (such as in password protected Notes).
  7. Establish passkeys where available


Then, over time, work to change your less important accounts, never reusing a password.



3 replies
Question marked as Top-ranking reply

Jan 25, 2026 2:57 PM in response to uemit

I would recommend that you prioritize first, and then decide how to handle the rest.


First, change the passwords of all of the accounts that could cause you significant harm if taken over (e.g. email accounts, financial accounts, retirement accounts, government accounts, cloud storage accounts, etc.). While you are at it, make sure that you are using password best practices for each new password:


  1. Length is very important, so at least 14 characters
  2. Use a unique password for every account (reusing passwords is likely what got you into this mess)
  3. Unguessable (don't use patterns or any information that would be known from social media)
  4. For any significant account you may need to remember without the use of your password manager (such as if you lost your phone when on travel), use a strong but easy to remember passphrase
  5. For all other accounts you can use a completely random password because your password manager will fill it for you.
  6. Always enable multi-factor authentication and take the time needed to store MFA/2FA recovery codes and information carefully (such as in password protected Notes).
  7. Establish passkeys where available


Then, over time, work to change your less important accounts, never reusing a password.



Jan 25, 2026 3:30 PM in response to uemit

uemit wrote:

I've noticed this too late into the day. There really are 517 cases to sort.

Is changing them manually one by one the only way to get his sorted? This could take forever plus a potential of thousands of confirmation emails to receive and click etc.

Is there any way of simplifying this process? Or just ignore and hope for the best?


There isn’t a way to simplify fixing this, and the “fun” starts just as soon as a re-used password is compromised somewhere.


First and foremost, ensure two-factor authentication is enabled. That’ll give one last chance to avoid compromise.


Then get going on your most important accounts, and work to the less important. If the site offers passkeys, select that. Use a password manager such as Apple’s iCloud Keychain and Passwords app, and either a passkey, or select a generated password.


What happens with compromised passwords? Weak passwords and password re-use are approximately doom. With rampant credential-stuffing attacks, too.


If you want to see where some of your credentials may have leaked, enter your email address into the haveibeenpwned.com site.

Jan 25, 2026 3:16 PM in response to FishingAddict

I do want to make a separate note about typical causes of any password manager reporting large numbers of compromised passwords to someone:


  1. Reusing passwords for many websites
  2. Using very common passwords that others also use by coincidence (such as a sports team and the year they won a championship)
  3. Using really short and weak passwords that are easily crackable or on lists of the most common passwords


Regardless of the cause, these are all significant problems and point to a lack of security awareness. Thinking that you have nothing to lose on some websites is a very common misconception. A crafty attacker can often leverage the takeover of one or more "insignificant" accounts to eventually gain access to far more important accounts.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

According to the Passwords app I have 517 of compromised passwords

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.