Your password is no longer considered secure warning: Changing a Password flagged as unsafe
Your Jobtrain password has appeared in a known data breach and needs replacing. How to set a new password and what to tell your team.
Jobtrain checks the password you enter against a public list of passwords exposed in data breaches on other websites. If yours appears on that list, you need to replace it before continuing. This does not mean your Jobtrain site has been breached.
I want to:
- Understand why my password was flagged
- Set a new password and get back into Jobtrain
- Explain the message to someone in my team
- Change the wording our users see
Why am I seeing this message
The password you entered has appeared in a data breach published online. Attackers take passwords exposed in those breaches and try them against other systems, which is why a password on the list is treated as unsafe wherever it is used.
Recruiter, hiring manager and agency accounts cannot continue on a password that is known to be exposed. Candidate accounts are prompted but can choose to continue, which is why a candidate may describe a different experience.
What this message does not mean
- It does not mean your Jobtrain site has been breached
- It does not mean candidate data has been accessed
- It does not mean your account has been used by someone else
The exposure happened on another website. Jobtrain has identified the reuse and stopped it before it could be exploited.
Setting a new password
- Enter a new password on the change password page shown after you sign in.
- Select Change Password and Sign In.
- Sign in again using your new password.
Good to know: Changing your password ends your current session, so you are returned to the login page to sign back in. This is expected.
Your new password goes through the same breach check. If the replacement has also been exposed, you will see the message again and will need to choose something different.
If your account uses two factor authentication
You are asked for your authentication code first, and the password change prompt appears after the code has been accepted. That order is deliberate: it keeps the second factor protecting your account throughout.
Choosing a password that will be accepted
The National Cyber Security Centre (NCSC) recommends passphrases: three or four words combined together. The length makes them hard to guess but far easier to remember than a random string. Do not copy well known examples such as CorrectHorseBatteryStaple or applenemobiro, as those already appear on breach lists.
Things to avoid
- Simple passwords such as Password123 or 123456
- Anything easy to guess about you, such as your date of birth
- Simple character swaps for security. Attackers already try 3 for e and 5 for S
- A password you have used on another website or on another system at work
- Increasing a number at the end by 1 (2025 > 2026 etc), as simple changes like this are tried by attackers.
If you use this password elsewhere
Change it on every other site or system where you have used it, starting with your work email account. An exposed password puts every account using it at risk, and a work email account can usually be used to reset the others.
If the flagged password is also in use on another system that holds personal data, raise it with whoever handles data protection at your organisation.
Explaining the message to your team
Someone in your team who sees this message will usually ask whether Jobtrain has been hacked. A short answer that works:
Jobtrain checks passwords against a public list of passwords leaked from other websites. Yours is on that list, which means it was exposed somewhere else, not here. Set a new password that you have not used anywhere else, and you will be straight back in.
Worth adding for hiring managers and shortlisters who sign in rarely: the prompt appears at sign in, so someone returning after a gap may meet it unexpectedly.
How your passwords are stored
Passwords are encrypted before being saved. Only the encrypted hash is stored, never the password itself, in line with cybersecurity industry best practice. The breach check works on a partial hash, so the password is never sent to the checking service.
FAQs
Can I continue without changing my password?
No. Recruiter, hiring manager and agency accounts need a new password before continuing. Candidate accounts are prompted but may continue.
Does this work the same way for our recruitment agencies?
Yes. Agency logins behave in the same way as client logins and use the same screens.
I have two factor authentication. Which comes first?
Your authentication code. The password change prompt only appears once the code has been accepted.
Do I have to sign in again?
Yes. Changing the password closes the current session and returns you to the login page.
Can we switch the check off for our site?
The check exists to close a security recommendation, so it cannot be switched off on request. Speak to the Jobtrain Support team if it is causing a problem for your users.