Google Password Manager can identify saved passwords that appear exposed in a breach or are weak. A Checkup warning is a useful priority signal, but it does not tell you that your specific account was entered. The practical task is to secure the real site and any account sharing that password.
Before you start
Open Chrome on a trusted device and know the legitimate website address for the flagged account. If the warning concerns an account managed by work, use the organization's incident process.Do it step by step
- In Chrome, open More, Passwords and autofill, then Google Password Manager. Choose Checkup and read which saved login is flagged.
- Visit the affected service by typing its known address or using a trusted bookmark, not a link from a warning email. Sign in and change its password to a unique strong one.
- If the same old password was used elsewhere, change those accounts too, starting with email, banking and recovery accounts. A password manager can help find reuse.
- Review recent sessions, recovery details and account activity on the service. Sign out unfamiliar sessions and turn on a supported second factor or passkey.
- Return to Checkup and update the saved credential if needed. Record which sites you fixed, so an old saved entry does not obscure a remaining issue.