Why your password was flagged as unsafe
Your password has appeared in a known data breach. What this means for your candidate account and how to choose a safe new password.
When you sign in, we check your password against a public list of passwords that have appeared in data breaches on other websites.
If yours is on that list, we let you know and ask you to choose a new one. This does not mean your account here has been broken into.
I want to:
- Understand why my password was flagged
- Choose a new password that will be accepted
- Know whether my account or my application is at risk
Why am I seeing this message
The password you entered has appeared in a data breach published somewhere online. Attackers collect passwords exposed in those breaches and try them on other websites, so any password on the list is no longer safe to use anywhere.
You will see wording similar to this:
What this message does not mean
- It does not mean this website has been breached
- It does not mean your application or your personal details have been seen by anyone else
- It does not mean you have done anything wrong
The password was exposed elsewhere. When a large website suffers a breach, the passwords from that site get published, and every account reusing the same password becomes vulnerable.
What happens next
You are taken to a change password page rather than your usual landing page.
We strongly recommend changing your password there and then, but you can choose to continue with your existing password if you prefer.
Changing your password
- Enter a new password in the fields shown.
- Select Change Password.
- Sign in again using your new password.
Good to know: Changing your password ends your current session, so you are returned to the login page to sign back in. This is expected and takes a few seconds.
Your new password is checked against the same breach list. If the new one has also been exposed, you will see the message again and will need to try something different.
If you choose to continue for now
You can carry on into your account using your existing password. The message will appear again next time you sign in, because the password stays on the breach list. We would encourage you to change it as soon as you can.
How to choose a password that will be acceptedThe National Cyber Security Centre (NCSC) recommends passphrases: three or four words combined together. The length makes them hard to guess but they are much easier to remember than a random string of characters.
Do not copy well known examples such as CorrectHorseBatteryStaple or applenemobiro, because those already appear on breach lists.
Things to avoid
- Simple passwords such as Password123 or 123456
- Anything easy to guess about you, such as your date of birth
- Simple character swaps for security. Attackers already try 3 for e and 5 for S
- A password you have used on another website
Yes. If you use the flagged password on other websites, change it on those sites too. An exposed password puts every account that uses it at risk, not just this one. Your email account is the most important one to change first, because it can usually be used to reset the others.
Are my passwords stored safelyYour password is encrypted before it is saved. Only the encrypted hash is stored, never the password itself, which is in line with cybersecurity industry best practice.
FAQs
Do I have to sign in again after changing my password?
Yes. Changing your password closes your current session and returns you to the login page, so you sign back in with the new one.
Can I keep using my existing password?
Yes, you can choose to continue, although we strongly recommend changing it. You will see the message again on your next sign in.
Will this affect an application I have already submitted?
No. Your applications are unaffected. This is only about the password you use to sign in.
My new password was rejected as well. Why?
The replacement password has also appeared in a breach. Choose something different, ideally a passphrase of three or four words that you have not used anywhere else.