Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

There is no authoritative confirmation of one breach in which Google, Apple and Meta lost 18 billion passwords. The alarming figure appears to have been repeated in connection with large collections of stolen credentials and other account data, but a count of records is not a count of unique people, valid passwords or accounts taken over. Don’t panic or click links in a sensational warning. Check your accounts through official settings, change reused or exposed passwords, and review active sessions.

What does “18 billion passwords” mean?

A credential collection can combine data from unrelated website breaches, phishing, infostealer malware and criminal-market compilations. It may include duplicate records, old passwords, usernames, login URLs, browser cookies or session identifiers—not just current passwords. One 2025 report discussed roughly 19 billion passwords circulating in criminal markets, while separate coverage described large collections of cookies and identifiers. Neither establishes that Google, Apple or Meta suffered a direct breach. A 2026 report also described a database with roughly 24 billion records, but the number of unique people affected was unclear. These are different claims and datasets; they should not be collapsed into a verified “18 billion passwords from three platforms” event. (reporting discussed in a Reddit thread; Black Arrow Cyber Consulting briefing)

A company’s name appearing in a list may mean that an address associated with its service was included, or that a stolen credential was used to sign in there. It does not by itself show that the company’s own systems were breached. A third-party site, a phishing page, an infected device or password reuse could be the source.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is also important to distinguish passwords from session cookies. A stolen cookie may let an attacker reuse an already-authenticated session without knowing the password. If you suspect account theft, changing the password is important, but you should also sign out other sessions and revoke suspicious app access.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Do these things first

  1. Ignore links in the warning. Open the service’s official app or type its address yourself. Do not submit a password to a random “leak checker.”
  2. Secure your primary email account. Email is often the route used to reset other accounts. Review recent activity, devices, recovery details and forwarding settings.
  3. Change reused or exposed passwords. Use a different, long password for every account. Change the password anywhere you reused the same one, especially for email, banking, work, health and cloud storage.
  4. Turn on stronger sign-in protection. Use a passkey or hardware security key where supported; an authenticator app is another good choice. Use SMS if stronger options are unavailable.
  5. Review sessions and connected apps. Sign out unfamiliar devices, remove apps you do not recognize, and regenerate backup codes if they may have been exposed.
  6. Check for changes you did not make. Look for unfamiliar recovery information, email forwarding rules, payment methods, messages, posts or account settings.
  7. Update your devices and browsers. If malware is plausible, stop changing passwords on that device and use a separate, trusted device instead.

Do not change every password solely because a headline says “18 billion.” Prioritize passwords known to be reused or exposed, accounts with suspicious activity, and the email account that can reset others.

Google account checklist

Open Google Account security or run the Security Checkup. Review recent security activity, devices, recovery phone and email, and third-party apps with account access. Remove anything unfamiliar. If you use Gmail, inspect forwarding and filters for rules you did not create, and check whether someone has delegated access.

Google Password Manager at passwords.google.com can flag saved passwords that Google identifies as compromised, weak or reused. That check concerns credentials saved in your vault; it is not proof that Google itself was breached, and it cannot show every password you may have used elsewhere.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

If your Google password was reused or you see suspicious activity, change it from a trusted device, then review devices and sessions again. Enable two-step verification or a passkey. If you cannot sign in, use Google’s account recovery page.

Apple Account checklist

On recent Apple operating systems, look in the Passwords app for Security Recommendations or compromised-password warnings. Labels and locations vary by release. Apple’s password security guide explains the available controls.

At account.apple.com, check the devices and trusted phone numbers associated with your Apple Account. Remove unfamiliar devices, change a reused or exposed password, and confirm two-factor authentication is enabled. Also review recovery options and relevant iCloud settings. Apple’s Platform Security guide describes its security features.

Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

If you are locked out, use Apple’s account recovery flow. Do not trust unsolicited messages or people who claim they can recover an account for a fee.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Facebook and Instagram checklist

Use Meta’s official Accounts Center and open Password and security. Review Where you’re logged in, login alerts, two-factor authentication, connected accounts and apps. Sign out sessions you do not recognize and remove access you no longer need. Menu wording can vary between the app and website.

If you cannot access an account or believe it was taken over, go directly to Facebook’s hacked-account page or Instagram’s recovery page.

Checking whether your email appeared in a known breach

Have I Been Pwned lets you check whether an email address appears in breach datasets it tracks. Its Pwned Passwords service checks passwords against known exposed-password data. A match does not prove that your current password still works, that your account was accessed, or that the platform named in a record was breached. No match does not prove that your details are absent from every private or unreported collection.

Never type a current password into an unfamiliar leak-checking site. If a password check is needed, use a reputable service’s privacy-preserving method or a local password-manager check.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you suspect malware or a stolen session

Infostealer malware can take passwords, browser cookies, tokens or saved credentials from a device. Changing passwords on an infected device can expose the new ones immediately. If you suspect infection, use a separate clean device to change important passwords, revoke sessions and remove suspicious app access. Update the affected device and run reputable security software; if you cannot rule out compromise, consider professional help or a system reset. Contact financial institutions through their official channels if banking or payment information may have been stolen.

Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

Be wary of fake CAPTCHA or “browser verification” pages that tell you to paste commands into Terminal, PowerShell or a run dialog. A recent macOS malware campaign used fake verification steps to steal credentials, cookies and Keychain data. A website should not ask you to run a command to prove you are human. (MacRumors coverage)

If you receive an unexpected MFA approval prompt or code, do not approve it or share the code. Repeated prompts can be an attempt to pressure you into authorizing a login. Change your password from a trusted device, revoke sessions and switch to a passkey or security key if available.

Passkeys and password managers: what you need, and what you don’t

A password manager helps create and store unique passwords, reducing the harm caused by password reuse. Google Password Manager and Apple Passwords are integrated options that suit many people who mainly use one ecosystem. Independent managers can be useful for mixed-device households, family sharing or broader cross-platform features, but add another important account to protect. Set up recovery options carefully and know how you would regain access if you lost a device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Passkeys can reduce phishing and password-reuse risks because they are not ordinary passwords typed into a site. Their availability and recovery experience vary by service and device, and the Google, Apple or vault account that stores or syncs them still needs protection. Neither a password manager nor MFA prevents every risk from malware, stolen sessions or social engineering.

You do not need to buy a password manager to respond to this headline. The immediate priorities are unique passwords, stronger sign-in protection, session review and checking the devices you use.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.