How Do I Stop Reusing the Same Password Everywhere?

A shopping account was accessed after I reused the same password from an old email login. I currently keep passwords in a note on my desk and usually sign in from a laptop and phone. How can I switch to unique passwords everywhere without locking myself out or making everyday logins cumbersome?

If you’re worried about getting locked out, don’t change everything in one sitting. Install Bitwarden’s free password manager on your laptop and phone, secure it with one strong master password, then update your email and financial accounts first. Let it generate and save a unique password for each site. Keep the old desk note temporarily as a backup, then destroy it once you’ve confirmed syncing, recovery access, and two-factor authentication work on both devices.

Make a list of every account that used the exposed password, then change those first and use “sign out of all devices” where available. I wouldn’t keep the compromised password as a backup. Store recovery codes separately instead, and turn on app-based two-factor authentication for your email before working through less important accounts.

Don’t replace the reused password with predictable variations like adding a site name or changing one digit. Set up Bitwarden on both your laptop and phone, create one strong master passphrase you can remember, then let it generate and autofill random passwords. You don’t need to fix every account in one sitting: handle important accounts first, then update the rest whenever you log in. Keep the master passphrase and recovery details somewhere secure, not in the same desk note.

Don’t treat this as only a password-change job. Start with the shopping account that was accessed. Change its password from a device you trust, sign out every active session, and inspect the order history, shipping addresses, saved cards, account email, phone number, and recovery settings. Remove anything you do not recognize. If an order or payment looks wrong, contact the store and card issuer promptly.

Next, find every account that may share that old password. Search your email for phrases such as “welcome,” “verify your email,” “password reset,” and “new account.” That usually uncovers forgotten logins. Put the accounts into three rough groups: critical, useful, and disposable. Critical means email, banking, mobile carrier, cloud storage, social accounts, and anywhere with saved payment details. Delete disposable accounts instead of spending time securing services you no longer use.

Then migrate accounts in small batches:

  1. Open the site directly rather than following links in old emails.
  2. Save the account in your password manager.
  3. Generate a different random password for that site.
  4. Confirm the new password works on both your laptop and phone.
  5. Check that the recovery email and phone number are still yours.
  6. Sign out other sessions if the site provides that option.

The recovery settings are easy to overlook. A unique password will not help much if an attacker changed the recovery address or added their own device. For important accounts, enable two-factor authentication or a passkey where supported. Save recovery codes somewhere separate from the password database, preferably on paper in a secure location rather than as a photo on your phone.

I would retire the desk note as you migrate, but do it account by account. Cross out each old entry once the replacement has been tested, and never write the new site passwords there. If you keep a paper backup, it should contain only the password manager’s recovery information or master passphrase, stored somewhere private. After that, the simple rule is that you only memorize the manager password. Every website gets a generated password that you never need to know or reuse.

Expect the first week to be a little annoying. The real improvement is not changing every password overnight. It is creating a routine where you never have to invent or remember another site password.

A common migration mistake is ending up with passwords saved in three places: the new manager, the laptop browser, and the phone’s built-in password store. Then an old login autofills, gets rejected, and you cannot tell which copy is current. Pick one password manager as your source of truth. During the move, label duplicate entries carefully and include the username, since many people use different email addresses on different sites. Once you know the manager works reliably on both devices, disable the other “save password” prompts so they stop collecting stale copies.

Before changing an account, save its address and username in the manager, generate the new password, and make sure the entry actually saved. Then submit the change and test it in a private browser window. That private-window test catches bad saves without requiring you to sign out of a working session first. Some phone apps are poor at autofill, so learn where the manager’s copy button is rather than falling back to an easy password when autofill fails.

Pay attention to accounts created with “Sign in with Google,” Apple, or another provider. Those may not have a separate site password at all. Record the login method in the vault instead of resetting passwords at random and accidentally creating duplicate accounts. The same goes for sites where your username is not your current email address.

The exposed password should be treated as permanently unusable, but keep it written down only long enough to identify which old accounts used it. Do not store it as a vault entry marked “old,” because it can later appear in search results and be reused by mistake. Once the important accounts are changed and you have checked the remaining services, destroy that note.

Finally, verify the password manager’s own login before depending on it. Type the master passphrase several times rather than trusting that you remember it after one setup attempt. Keep an offline emergency record in a genuinely private place, including any required recovery information, but do not put every website password on that sheet. The goal is to have one carefully protected way into the vault, while every account inside it gets a different generated password.