How often should you change passwords

How often should you change passwords

Marcus Reid
April 20, 2026· 7 min read

If you are asking how often should you change passwords, here is the practical answer: most people do not need to rotate every password every 30 or 90 days. What matters more is changing passwords immediately after a real risk event. NIST now emphasizes changing passwords when there is evidence of compromise, suspected theft, weak passwords, or password reuse, instead of forcing frequent changes that often push people toward lazy variations.[1] CISA also puts more weight on strong, long, unique passwords and multifactor authentication than on routine rotation.[2]

Use the digital privacy guide as the wider checklist: it connects this issue to accounts, devices, identifiers, and data-broker exposure.

In other words, password hygiene is not about changing more often. It is about changing quickly when risk appears, and changing in a way that does not repeat the same mistake.

If you already use a password manager, read this alongside Are Password Managers Safe? Yes, But Only If You Do Not Treat Them Like Magic Vaults.

Key Takeaways

  • Blind periodic password changes are no longer the top default recommendation.[1]
  • The real triggers are usually a breach, password reuse, a weak password, a compromised device, or the end of shared access.
  • The accounts to prioritize are often not every account, but your email, banking, cloud storage, and work accounts because they can reset other services.
  • If you change a password by reusing the old pattern, such as only changing the last digit, the security gain is limited.
  • Multifactor authentication and a password manager usually do more than high-frequency password rotation.[2][3]

Why security guidance no longer pushes routine changes for every password

Routine rotation often leads to two bad habits:

  • turning the new password into a variation of the old one;
  • reusing almost the same password everywhere.

NIST's digital identity guidance pushes back on mandatory periodic password changes without a reason, unless there is evidence that the password has been exposed or the account is compromised.[1] The logic is simple: if there is no risk signal, frequent rotation adds cognitive burden without necessarily improving account security.

The 5 moments when you really should change a password

1. You know the account was breached, or it was probably exposed

This is the clearest case and the one you should not postpone. If a platform tells you about a data breach, or your email appears in a known breach lookup service, change that account's password immediately and check whether you reused it anywhere else.[4]

2. You reused the same password across multiple websites

This risk is easy to underestimate. When a low-value website is breached, the damage may not stay there. If you used the same password for email, shopping, or social media, attackers may try credential stuffing against those accounts.[2][4]

3. The password is weak

Weak passwords are not limited to extreme examples like 123456. If your password is short, includes obvious personal details, or follows a "common word plus year" pattern, change it. NIST and CISA both emphasize length and uniqueness more than symbol gymnastics.[1][2]

4. Your device, browser, or account shows signs of compromise

Examples include:

  • malware on the device;
  • suspicious browser extensions;
  • unfamiliar login alerts;
  • clicking a phishing link and entering your credentials.

Do not change only one site in this situation. If your primary email, password manager, or work account was used on the same device, include them in the response plan.

5. You shared a password, and that shared relationship has ended

This happens with streaming services, family cloud storage, shared tools, and project collaboration. Once a password is no longer only yours, you should assume your control over it has dropped. When a relationship ends, a member leaves, or a contractor finishes work, change the password promptly.

What order should you follow when changing passwords?

I recommend sorting accounts by the damage they can cause if taken over:

PriorityAccounts to change firstWhy
HighestPrimary email, password manager, Apple ID / Google accountThese accounts can often reset other services
HighBanking, payments, brokerage, cloud storage, work toolsThey affect money and important files directly
MediumSocial media, shopping, forumsThey can be abused for impersonation, credential stuffing, or social engineering
LaterRarely used websitesLower risk, but still relevant if you reused the password

If you have not built a "protect the core accounts first" habit, read How to Protect Your Email Account: 7 Settings That Matter More Than Changing Addresses.

4 common password changes that do not help much

  • changing only the last digit;
  • adding an exclamation point to the old password;
  • using the same "upgraded new password" on several important sites;
  • changing the password but skipping MFA.

The issue is not that these moves are technically worthless. It is that attackers often try common variations first. Each time you change a password, check three things:

  • Is it unique?
  • Is it long enough?
  • Is MFA enabled?[1][2][3]

My advice: make a fixed "15 minutes after a breach" routine

If you receive a breach notice, or you think you just entered your password on a phishing page, the safest order is usually:

  1. Change your primary email password first.
  2. Change your password manager and cloud accounts.
  3. Give high-value services unique new passwords.
  4. Turn on or repair MFA.
  5. Review recent logins and unfamiliar devices.

This beats changing dozens of minor sites first because it protects the accounts that can unlock everything else.

Summary

  • How often should you change passwords? The better answer is: not constantly without reason, but immediately after high-risk events.[1][2]
  • The high-priority triggers are breach exposure, reuse, weak passwords, compromised devices, and ended sharing.
  • Your primary email, password manager, and reset-capable core accounts should come first.
  • Changing one character, reusing passwords, and skipping MFA can make the whole effort much weaker.

FAQ

Do I have to change passwords every 90 days?

Not necessarily. NIST no longer treats unsupported periodic rotation as the default best practice.[1]

After a breach notification, which password should I change first?

Change your primary email and any important accounts that reused the same password, then move to the rest.

Does changing only the last digit count?

Technically yes, but it usually offers little protection because those variations are common.

If I use two-factor authentication, do I still need to change the password?

Yes. 2FA is a reinforcement, not a replacement. If the password is exposed, change it.[2][3]

If I use a password manager, can I stop thinking about timing?

No. A password manager helps you create unique strong passwords faster, but you still need to recognize risk triggers.

Which accounts should never wait?

Email, password managers, financial accounts, work collaboration tools, and cloud storage.


Disclaimer

This article is for general account security education only and does not constitute mandatory guidance for any specific identity system, enterprise password policy, or compliance program.

As the publisher, AethoVPN notes that when to change passwords remains outside what a VPN can fix.

Sources

  1. NIST, Digital Identity Guidelines SP 800-63B: https://pages.nist.gov/800-63-4/sp800-63b.html
  2. CISA, Use Strong Passwords: https://www.cisa.gov/secure-our-world/use-strong-passwords
  3. CISA, Implementing Phishing-Resistant MFA: https://www.cisa.gov/resources-tools/resources/implementing-phishing-resistant-mfa
  4. Have I Been Pwned: Check if your email address has been exposed in a data breach: https://haveibeenpwned.com/

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

How often should you change passwords | AethoVPN