Apple and Google both have built-in tools that check the passwords saved on your phone against known data breaches, and most people never open them. If one of your logins has already surfaced in a leak, your phone likely knows before you do.
On iPhone, the Passwords app automatically flags credentials that are weak, reused across multiple sites, or that have turned up in a known data leak. Apple describes this as secure monitoring of your saved passwords, built directly into iOS. On an iPhone running iOS 27, you can review these warnings directly in the Passwords app, and if a site supports it, switch to a passkey or Sign in with Apple instead of a traditional password. Make sure the underlying monitoring setting is actually turned on in iOS 27 — it’s easy to miss, and it does the quiet work of watching for leaks in the background.
Android users get a similar tool through Google Password Manager’s Password Checkup feature, which flags passwords that are exposed, weak, or reused. On Samsung Galaxy phones running One UI 9 (built on Android 17, which began its broader rollout in September 2026), the most reliable way to run this check is through Chrome if your passwords are saved with Google. If you instead use Samsung Pass, be aware Samsung documents it as a login-storage and autofill tool tied to biometric authentication and Samsung Wallet — it does not currently offer the same breach-checking feature Google provides.
On Pixel phones running Android 17 with the September 2026 update — which began rolling out September 15 — the Passwords app gives you a shortcut into Google Password Manager, though Chrome remains the most consistently documented path for checking compromised credentials. If you can’t find the app, search