Change the reused password when a site emails it to you
A site that emails you the password you chose can read it. Change it on every other site where you used it, email account first.
From people discussing sites that email passwords and how to keep passwords safe, set beside UK and US cyber-security and consumer guidance read in October 2026.
You clicked “forgot password”, and the site sent back the password you chose. That feels helpful. It is also information: the site kept your password in a form it can read. If the email held a reset link or a new temporary password instead, this page is not about you.
If a website emails you your actual password, change that password on every other account where you used it, starting with your email account.
What the email tells you
A site that can send you the password you chose has kept it in a form it can read back. A site that stores passwords properly keeps only a scrambled, one-way version that it cannot turn back into the password, which is why those sites ask you to reset instead. Many people say that a site sending the password itself is a serious security failure, and many say to stop using it. People argue over the right word for it, “unencrypted” or “unhashed”, and the argument is about the label. What it means for you is the same.
It does not mean you were hacked. One person says that anyone who gets into the site’s systems could read every password stored there, and another that attackers then try those same passwords on other sites. That second part is the risk to you, and it only bites if you used that password somewhere else.
Change it everywhere you used it
Many people say each site needs its own password, so that one leak cannot open the others. The UK’s National Cyber Security Centre puts the danger plainly: if you have used the same password across different accounts, criminals only need one to reach all of them. Its guidance for organisations also says users must change a password when it is known or suspected to be compromised, and that forcing regular changes on a calendar carries no real benefit. A site that emails you your password is a reason to treat yours as compromised now.
Start with your email account if you used the password there. The same centre says that someone with access to your email can reset your other account passwords and get into those accounts. One person puts securing the email account ahead of any single site’s password for the same reason. Then change your bank, card and shopping accounts, then the rest.
A small variation may not count as a different password. One person says a password with a pattern, such as the same base with a site’s initials, is better than one password everywhere but can still be guessed. Another puts it more harshly: the gain is too small to matter against automated attacks.
If you used that password only on the site that emailed it, nothing else needs changing. Change it there, to something you use nowhere else. Whether you keep using the site is up to you. Many people say to leave it, and whichever you choose, the email has shown that the site can read your password.
Turn on two-step sign-in for your email and bank where it is offered. The US Federal Trade Commission advises turning it on when an account offers it, and one person says it cuts the risk of a takeover even when the password is known.
Making a different password everywhere affordable
Some people say it is too hard to remember so many, and that this is why they reuse one. Many people say a dedicated password manager is the answer: it creates and fills in a different long password for every site, so you remember one. The US Cybersecurity and Infrastructure Security Agency says that with a password manager you only need to remember one strong password, and are much more likely to use a long, random, unique one on every site. The UK centre says a password manager can create strong passwords for you and remember them, and suggests combining three random words for a password you must remember.
Some cautions. One person says that if your vault is locked by a master password only you hold, losing it can mean losing everything in it. Another says to keep a password you remember for your main email account, as a fallback way back in. Take care where you get a manager from: there is a page here called Get the program from its maker’s own page. Some people raise that a manager is a single point of failure, and others answer that it is still better than reusing passwords. People also disagree about whether a cloud-based manager is enough or an offline one is safer, and this page does not choose. Paper is another route: some people say it cannot be hacked online but can be lost or stolen.
Who this page is not for
If the email held a reset link or a temporary password that you must change, this is the normal way to recover an account and not the problem here. If the email arrived when you first signed up, the site may not be storing your password in a form it can read, but the copy in your inbox is still one more place it sits, so the steps above about reuse still apply. If you never reuse a password, you have nothing else to change, and leaving the site is your choice.
If an email with a password arrived that you did not ask for, or tells you to log in through a link, it may be a scam rather than a careless site. One person says to check an institution’s contact details independently before you share anything sensitive.
If an account has already been taken over, this page does not cover recovering it; the US Federal Trade Commission has a page on recovering a hacked email or social media account, and the resources below cover reporting.
If you run the site that sends the passwords, the UK centre’s guidance is to make sure systems do not store passwords as plain text, even where the information they protect seems unimportant.
Common questions
Does the email mean I was hacked?
No. A site that can send you the password you chose has kept it in a form it can read back, which is a weakness, not a break-in. Nobody has necessarily taken it. What it means is that if someone got into the site’s systems, your password would be readable, and the email now sitting in your inbox is another copy. One person warns that email is not a secure way to send a password, because it can be intercepted, however the site stores it.
Is a reset link or a temporary password the same problem?
No. One person points out that the warning sign is receiving the password you actually chose. A reset link, or a new temporary password you must change, is a normal way to recover an account. Another person says some sites check who you are by other means, such as a code to your phone or security questions, and that this is a different design that does not by itself mean the site holds your password.
How do I make a password I can remember?
The UK’s National Cyber Security Centre suggests combining three random words, and says a password manager can create strong passwords for you and remember them. Some people say a long passphrase of common words holds up better against guessing than a short string of symbols, though a randomly generated password is stronger still. One person adds that even a four-word phrase can be guessed, and that uncommon words or a random symbol placed inside a word help. Some people warn that many sites cap password length and may silently cut a long passphrase short, so check that you can log in with the new password straight away.
Questions this step helps with
Same situation, another step
- Forward the spam text to 7726Online privacy
Who can help
IdentityTheft.gov
If someone used your information, you can tell them what happened and get a personal recovery plan with the steps to take. The site also has sample letters and contact details for the credit bureaus.
ReportFraud.ftc.gov
You can report a scam, a company or an unwanted call, and you get next steps to protect yourself.
In the UK
Full tip: https://findangel.org/tips/change-the-reused-password-when-a-site-emails-it-to-you/ · FindAngel.org — free, always.