What it means
Bitwarden's exposed-password report compares saved passwords with known leaked strings. A hit means that password should be replaced, even if it was exposed from another service or appears in an old breach collection. It does not prove someone successfully signed in to the exact account named in your vault. Account activity logs and service notices answer that separate question.
A real-world example
A saved password for a shopping site matches a leaked string. The shopper rotates it and checks recent orders, but finds no evidence that their specific store account was used by an attacker.
What to do
Visit the service through a verified route, set a unique replacement, update the vault item and inspect sessions. Search for the same old password elsewhere in the vault and rotate those accounts too.
The distinction that matters
A clean report is limited by the breach data available at the time. The exposed-password check is designed to compare hashes without sending the full password, but neither that design nor a negative result guarantees no one knows a credential. Use unique passwords and stronger authentication regardless. If the provider reports an actual account incident, follow its incident notice and review account changes, payment methods and recovery addresses. Do not assume a password rotation alone reverses actions that occurred before the change.
Bitwarden report interpretation