A vault report can identify passwords found in known breach data and can also highlight reused or weak passwords. A match means the string is risky; it does not prove your particular account was accessed. The useful response is to change the service password, update the vault item and inspect account activity without putting the old password into more websites.
Before you start
Open Reports from the official Bitwarden web vault. Some health reports require Premium or a paid organization, while Bitwarden's Data Breach report has different availability. Prioritize email, banking and accounts that can reset other accounts.Do it step by step
- Read the exact report type and the affected item. Confirm whether the vault item points to the genuine service; do not click a suspicious saved URI automatically.
- Open that service through a trusted bookmark or independently typed address, sign in and inspect recent account activity, devices and recovery settings before changing the password.
- Generate a new unique password in the manager and set it on the service. Confirm the service says the change succeeded; only then save the new value in the correct vault item.
- Use a private or separate session to test the new password. Remove old sessions and enable stronger two-step verification when the service provides it.
- Search the vault for reuse of the old password. Change every other account that shared it, beginning with the most sensitive. A single password change does not repair credential reuse elsewhere.
- Run the report again after synchronization and compare results. Keep an eye on the service's activity log for misuse that could have occurred before rotation.