Wireva

Apple and Google Tools Can Flag Compromised Passwords Before Criminals Use Them

Both iPhone and Android users can check saved logins for exposure in data breaches, weak passwords, and reuse through built-in password managers, but the monitoring settings must be enabled to receive warnings.

Apple and Google now offer built-in tools that scan saved passwords for signs of compromise, giving users a chance to secure exposed logins before criminals can exploit them. The features, available on iPhone through the Passwords app and on Android through Google Password Manager, can identify passwords that have appeared in known data leaks, are weak, or are being reused across multiple accounts.

The warnings are not automatic for every user. On iPhone, Apple provides a setting that allows the device to monitor saved passwords and alert the owner when they appear in known data leaks. That option can be easy to overlook, and without it enabled, users may miss critical alerts about exposed credentials. Apple also flags passwords that are easy to guess or used more than once, and it can help create strong replacement passwords for many accounts.

Google Password Manager offers a similar Password Checkup feature. It identifies passwords that were exposed in a data breach, are weak, or are being used across multiple accounts. On current Pixel phones running Android 17, users can look for the Passwords app, which provides a shortcut to Google Password Manager. If the app is not visible, opening Settings and searching for Password Manager will bring it up. The most consistently documented route for checking passwords saved with Google is through the Chrome browser.

Samsung Galaxy owners have additional options. These phones can save login information with Google Password Manager, Samsung Pass, or another password manager. If passwords are stored with Google, the Chrome route remains the most reliable way to check for security problems. Samsung Pass, which stores and autofills login information using biometric authentication and is integrated with Samsung Wallet on supported devices, does not currently document the same compromised-password checking feature that Google provides through Password Checkup. To review logins stored with Samsung Pass, users can open Samsung Wallet and access Samsung Pass.

Seeing a «compromised» warning can be alarming, but it does not automatically mean someone has already logged into the account. Apple can alert users when a password appears in a known data leak, and Google can warn when a saved password has been published online or otherwise identified as compromised. Security experts advise taking the warning seriously regardless. An exposed password may already be available to criminals even if no unauthorized login has occurred yet.

One major risk is credential stuffing, in which criminals take usernames and passwords obtained from previous breaches and try the same combinations on other services. Reusing a password can turn a single exposed login into a much larger problem, which is why both Apple and Google flag reused credentials. When a password is found to be compromised, the recommended first step is to go directly to the company's official website or app and change the password there, rather than clicking a password-reset link from an unfamiliar email.

For users who want more active breach monitoring and password-health tools, a dedicated password manager can provide additional protection beyond what is built into the phone. The checks themselves take only a minute, but they can close a window of vulnerability that might otherwise go unnoticed until an account is already at risk.

Same event, other desks

Story file →