Compromised credentials are authentication secrets or recovery information that may be available to an unauthorized person. They include passwords, one-time codes, session tokens, API keys, security-question answers, passkeys on a lost device, and recovery codes.
How credentials become compromised
Phishing pages collect information directly. Data breaches expose stored account records. Malware and malicious browser extensions may steal passwords or sessions. Reuse lets a credential taken from one service unlock another.
An email address alone is an identifier, not a secret, but it can help an attacker target the correct account and combine records from several breaches.
What to do
Replace the exposed password with a unique one and change every reused copy. Revoke sessions, tokens, app passwords, and connected applications that may remain active. Repair recovery information and turn on two-factor authentication.
For API keys or business credentials, rotate the secret and review logs for use before and after rotation. Follow the organizationâs incident process.
Monitoring limits
Breach Report can alert users when credentials associated with registered email addresses appear in known breach data. It cannot see every private breach, phishing event, stolen session, or secret outside its sources.