How did my password get on the dark web? The 7 ways it happens
You get an alert from Google, your iPhone or a credit app: your password was found in a data breach. The first question is always the same: how did my password get on the dark web when nobody broke into my account and I never gave it to anyone?
In almost every case the answer is one of seven routes, and most of them do not involve you making a mistake. This guide explains each one, what the warning on your screen really means, how to check which of your passwords are out there, and what to do about it today.
What "on the dark web" actually means
The phrase sounds like one hidden website where your password is on display. It is not one place. Stolen logins are traded in several kinds of places at once:
- Criminal forums and markets, some of them reachable only through the Tor browser, where a fresh database is sold to a few buyers first.
- Telegram channels and ordinary file-sharing sites, where older data is reposted for free.
- Combolists: huge text files of email-and-password pairs, stitched together from many separate leaks.
So when a service says your password is "on the dark web", it means the password appears in a collection of leaked data that the service has a copy of. It does not mean someone is looking at your account right now.
How do passwords end up on the dark web? The 7 ways
1. A website you signed up to was breached
This is the classic route. An attacker gets into a company's systems and copies its user table: email addresses, usernames and passwords for every customer. You did nothing wrong, and you usually hear about it months later, if at all.
How bad it is depends on how the company stored the passwords:
- Plain text. The password is readable as it is. Rare today, but it still happens.
- Weak or unsalted hashes. The password was scrambled with an old method. Attackers run billions of guesses a second against these, and short or common passwords are recovered within hours.
- Strong, salted hashes. Each guess is slow by design. A long, unusual password may never be recovered. "Password123" still falls on the first day.
That is why two people in the same breach can have different outcomes. The leak exposed both, and only the weak password became usable.
2. Malware on your own device stole your saved passwords
This route has grown the most, and it is the one the usual advice skips. A type of malware called an infostealer runs once on a computer, copies every password saved in the browser, along with cookies and autofill data, sends the lot to its operator and often deletes itself. The stolen bundle is called a "log", and logs are sold in bulk.
People pick these up from:
- cracked software, game cheats, mods and "free" versions of paid apps;
- fake updates and fake download buttons;
- pages that show a fake CAPTCHA and ask you to paste a command into your computer to "prove you are human";
- email attachments that are not what they claim to be.
The scale is large. The security company SpyCloud says it recovered data from 13.2 million infostealer infections in 2025, and that about 40% of them were on machines that had antivirus or similar protection installed. An infostealer leak is also worse than a breach in one respect: the passwords are stolen in plain text, straight from the browser, with the exact site each one belongs to.
3. You typed it into a phishing page
A message says your account is locked, a parcel is waiting, or someone signed in from a new device. The link opens a copy of the real login page. Whatever you type goes to the attacker, who may use it immediately or add it to a list for sale. Modern phishing kits also capture the one-time code you enter and the session that follows.
If you are not sure whether a message is real, our guide to spotting phishing emails shows what to check before you click.
4. You reused one password, and a different site leaked it
This is how a breach at a small forum turns into a problem for your email or bank. Attackers take the email-and-password pairs from one leak and try them automatically on hundreds of other sites. It is called credential stuffing, and it works only because people reuse passwords.
If you got a dark web alert for an account you are sure was never breached, this is usually the explanation: the same password was leaked somewhere else.
5. A company you never dealt with directly lost it
The site you use may be secure while one of its suppliers is not: a support tool, a marketing platform, a payment or analytics provider. Databases are also left open on the internet by mistake, with no password at all. Verizon's 2026 Data Breach Investigations Report found a third party involved in close to half of the breaches it studied, a sharp rise on the year before.
6. A shared computer, a fake app or a bad browser extension
Signing in on a public or borrowed computer leaves your password wherever that machine sends it. Fake versions of popular apps and browser extensions that ask to "read and change all your data on all websites" can do the same job as an infostealer, quietly and for months.
7. An old leak was repackaged into a new one
Stolen data never goes away. Old breaches and malware logs are merged, cleaned up and released again under a new name. The headline about 16 billion leaked passwords in June 2025 was this kind of event. Researchers at Cybernews found 30 exposed datasets holding about 16 billion records in total. It was not one new attack on Apple, Google or Facebook. It was years of earlier theft, mostly from infostealers, gathered in one place, with many duplicates.
This is why you can get a "new" alert about a password you stopped using years ago.
Which route was it? What the clues tell you
| What you notice | Most likely route | What it means for you |
|---|---|---|
| The alert names one company and a date | That company was breached | Change that password, and any account that shared it |
| Many unrelated accounts are flagged at once | Infostealer on your device | Clean the device first, then change passwords from a different one |
| The flagged password is one you use in several places | Reuse and credential stuffing | Every account with that password needs a new, different one |
| The password is one you stopped using long ago | An old leak recirculating | Nothing to do if it is truly retired everywhere |
| You entered it on a page reached from a link | Phishing | Change it now and sign out of all sessions |
What happens to a password after it is stolen
A stolen password usually passes through the same stages, though the speed varies a great deal.
- Private use or sale. The thief uses the best accounts or sells the data to a small number of buyers.
- Cracking. If the passwords were hashed, buyers recover as many as they can. Weak ones fall first.
- Wider sharing. Once the data has been used, it is resold cheaply or posted for free.
- Combolists and stuffing. Your email and password land in merged lists that bots try on banks, shops, streaming services and email providers.
Stolen logins also open the door to bigger attacks. In Verizon's 2026 report, 73% of ransomware victims had an infostealer infection or a credential leak in the year before the attack. A single leaked work password is often where it starts.
"Password found in a data breach": what the warning means
The warnings on your phone and browser all work the same way. Your saved passwords are compared with large collections of leaked ones, in a way that does not reveal your password to anyone.
- Google and Chrome. Password Checkup flags a saved password as compromised when the same username and password appear in a known leak. Chrome can also warn you at the moment you sign in.
- iPhone and Mac. The Passwords app lists Security Recommendations and says a password "has appeared in a data leak".
- Credit and banking apps. Monitoring features in apps like these search leaked data for your email address and report what was found with it.
What the warning means: this password is known outside your control and should be changed. What it does not mean: that someone has signed in to the account. Check the account's recent activity to answer that. Our list of signs an email account has been hacked shows where to look.
One change to know about: Google shut down its separate "dark web report" on 16 February 2026, saying the feature did not give people useful next steps. Password Checkup and Security Checkup are still there and are the tools Google now points to.
How to check if your password is on the dark web
You do not need to visit the dark web, and you should not try. These free checks cover what most people need.
- Search your email address on Have I Been Pwned. It lists the known breaches your address appears in and what was exposed in each. You can also sign up to be emailed about new ones. We walk through the results in how to check if your email was leaked in a data breach.
- Run Google Password Checkup if you save passwords in Chrome or your Google account. It sorts them into compromised, reused and weak.
- Open the security report in your password manager. Apple Passwords, Bitwarden, 1Password and others have one.
- Check a single password with Pwned Passwords. It tells you how many times that exact password appears in leaks. Only the first five characters of a scrambled version of the password leave your device, so the service never sees the password itself.
No tool sees everything. Data that is still being sold privately has not reached these services yet. A clean result is good news, not a guarantee.
What to do if your email and password are found on the dark web
- If several accounts were flagged together, deal with the device first. Run a full scan with your security software, remove browser extensions you do not recognise, and uninstall anything cracked or pirated. Then change passwords from a different, clean device. Changing them on an infected computer hands the new ones over too.
- Change the leaked password on the account it belongs to, and on every other account where you used the same one.
- Start with your email account. Whoever controls your inbox can reset every other password. If you are already locked out, see how to recover a hacked Gmail account.
- Turn on two-step verification, or a passkey where the site offers one. With it, a leaked password alone is not enough.
- Sign out of all devices in the account's security settings. Infostealers take session cookies as well as passwords, and signing out everywhere cancels them.
- Look for changes you did not make: forwarding rules, recovery email and phone number, connected apps, saved cards.
- Watch your bank and card statements for the next few weeks if the account was linked to payments.
Can you remove your password from the dark web?
No, and anyone selling that service is selling something they cannot deliver. Leaked data is copied thousands of times within days. The realistic goal is different: make the leaked password worthless. A password that has been changed, is not used anywhere else and sits behind two-step verification can stay on a list forever without harming you.
How to keep your next password off the dark web
- Use a different password for every account. A password manager makes this practical. A breach then exposes one account, not all of them.
- Prefer passkeys where they are offered. There is no password to steal or phish.
- Keep two-step verification on for email, banking and anything holding payment details.
- Do not install cracked software, cheats or "free" premium apps. This is the main way infostealers reach home computers.
- Never paste a command into your computer because a web page told you to. No real CAPTCHA asks for that.
- Review your browser extensions twice a year and remove the ones you no longer use.
- Give out your real email address less. Every sign-up is one more database that can leak. For a site you will use once, a throwaway address means a later breach there exposes nothing you care about. It protects the address, not the password, and it is the wrong choice for any account you want to keep. See when a temporary email is and isn't the right tool and temporary email compared with a Gmail alias.
Common questions
How did my password get on the dark web if I was never hacked?
Most of the time you were not hacked: a website you signed up to was. When a company's user database is stolen, every password in it leaves with it, and you played no part in that. The other common route is malware on a computer or phone that copied the passwords saved in your browser.
Is my account hacked if my password is on the dark web?
Not necessarily. It means the password is known to other people, so anyone can try it. If you have changed it since the leak, or the account has two-step verification, the leaked password alone does not open the account. Treat it as a warning to change that password everywhere you used it, and check the account's recent activity.
How do I check if my password is on the dark web?
Search your email address on Have I Been Pwned to see which breaches it appears in, and run Google Password Checkup, or the security check in your own password manager, to compare your saved passwords against known leaks. All of these are free. None of them can see every private criminal market, so a clean result lowers the risk but does not prove a password is safe.
Can I remove my password from the dark web?
No. Once a password has been copied and shared it cannot be pulled back, and no service can delete it for you. What you can do is make it worthless: change it, never use it again anywhere, and turn on two-step verification.
How did 16 billion passwords get leaked?
They were not stolen in one attack. In June 2025 researchers at Cybernews reported finding 30 exposed datasets holding about 16 billion login records in total. The records were collected over years, mostly by password-stealing malware and from older breaches, and many are duplicates, so the number of people affected is far smaller and cannot be counted.
Do I need to pay for dark web monitoring?
For most people, no. Free tools cover the main need: Have I Been Pwned emails you when your address appears in a new breach, and Google, Apple and most password managers warn you about leaked saved passwords. Paid monitoring adds things like Social Security number alerts and insurance, which matter more for identity theft than for passwords.