Skip to main content
Naxterra
June 22, 2025
Question

Password breach report question

  • June 22, 2025
  • 5 replies
  • 506 views

Hi

I saw some recent massive breach news on the websites but I couldn't find a single breach entry on Watchtower reports. Does this really mean my accounts were really never breached or Watchtower is not doing its job?

https://discuss.privacyguides.net/t/16-billion-apple-facebook-google-and-other-passwords-leaked-act-now/28475

https://cybernews.com/security/billions-credentials-exposed-infostealers-data-leak/

https://www.forbes.com/sites/daveywinder/2025/06/20/16-billion-apple-facebook-google-passwords-leaked---change-yours-now/

https://www.forbes.com/sites/daveywinder/2025/05/23/184162718-passwords-and-logins-leaked---apple-facebook-snapchat/

https://www.tomshardware.com/tech-industry/cyber-security/16-billion-accounts-exposed-in-one-of-the-largest-data-breaches-in-history-enormous-data-haul-holds-two-accounts-for-every-human-alive

https://www.tomsguide.com/news/live/16-billion-passwords-data-breach

https://time.com/7296254/passwords-leaked-data-breach/

5 replies

AJCxZ0
June 22, 2025

1Password has a long relationship with Troy Hunt, who runs Have I Been Pwned. Troy is probably the #1 authority on data breaches and reporting in the mainstream press (and sometimes technical press) is often less that accurate and reliable. Troy shared some information about this matter in his latest Weekly Update 457.

In short, don't worry about this news. 1Password will check for your credentials in all the breaches recorded in HIBP and let you know if any have been compromised. You can, of course, check details for yourself. If you find nothing new, then it doesn't mean that you can be certain that your details aren't in some dark web vendor's secret breach dataset, but it does mean that you don't have anything to do... yet.

You can test Watchtower by adding a Login item with compromised data. A safe example is

  username: test
  password: test
  website: http://example.com

This should immediately show several problems in Watchtower including the breached credentials and lower your score a few points.

August 7, 2025

You can test Watchtower by adding a Login item with compromised data.

I did this with a password that Chrome browser and https://haveibeenpwned.com/ say was exposed in 3 breaches. However, Watchtower does not report the 1Password entry that contains the compromised password.

AJCxZ0
August 7, 2025

Whereas I suggested adding an Item with a specific username, password, and website to test, you mention only that you "did this with a password..." with no details of what you did or the password, or what happened when you tried my suggested test.
This makes addressing your reported result practically impossible.

Given the possibility that the password in question was a bad one in that it used private or personal information, then not revealing it is of course the right choice. In that case, it should not be too difficult to find another compromised password which you can share; that is unless they were all that bad.

In any case, please report the results of adding the Item suggested.