Are password managers safe?
A password manager is much safer than reusing the same few passwords. Here's how they keep your passwords protected, where the real risks are, and how to choose one.
- Written by
- Digital Life Check editorial team
- Reviewed by
- Not yet independently reviewed
- Last checked
On this page
Quick answer: yes, for most people. A password manager lets you use a different strong password for every account, which is far safer than reusing a few. The National Cyber Security Centre (NCSC) encourages using one. The main risks are a weak master password and phishing, and you can deal with both.
Why they're safer than the alternative
The NCSC explains the problem password managers solve: if you use the same password on several accounts and one is compromised, a criminal can try it on your other accounts too. Nobody can remember dozens of different passwords, so most people reuse them.
A password manager remembers them for you. The NCSC lists what they usually do:
- create a strong, unique password for each account
- fill it in automatically, and only on the correct website, which helps protect you from phishing
- sync your passwords across your devices
- warn you if a password has been breached or leaked
The NCSC says it's safe to save passwords in your device or browser's password manager on your own devices. It advises never saving passwords in the browser on a shared public computer, such as one in a library.
How they protect your passwords
Most password managers keep your passwords in an encrypted store, often called a vault. You unlock it with one master password (the NCSC calls it the primary password), or with your phone's face, fingerprint or PIN.
Many are designed so that the company can't read your passwords. Apple, for example, says passwords in iCloud Keychain are end-to-end encrypted by default. Google offers optional on-device encryption for Google Password Manager, which Google says means only you can see your data. Google also warns that if you lose the key, you could lose your saved passwords.
The NCSC also advises turning on two-step verification for your password manager account, so that even if a criminal knows your master password, they still can't get in. See what two-factor authentication is.
The realistic risks
A weak or reused master password
Your master password protects everything else, so it needs to be strong and used nowhere else. Three random words work well. See how to create a strong password.
Phishing
A fake login page can still trick you into typing your master password. Autofill helps here: if your password manager doesn't offer to fill in a password, check the web address carefully before typing anything.
Malware on your device
The NCSC says passwords stored in your browser are only as secure as your devices and accounts. Keep automatic updates switched on for your phone, computer and browser.
A breach at the provider
This has happened. In 2022, LastPass reported two linked incidents. According to its own notice:
- In August 2022, an attacker got into a development environment and took some source code and technical information. LastPass said no customer data or vaults were accessed then.
- The attacker later used information from that first incident to access a cloud storage service holding backups. They copied customer account details (including names, email addresses, billing addresses, phone numbers and IP addresses) and a backup of customer vault data.
- In those vault backups, website addresses were not encrypted. Usernames, passwords, secure notes and form-fill data were encrypted.
LastPass said it never knows or stores customers' master passwords. It told customers using its default settings that there were no actions they needed to take. For customers whose master password didn't meet those defaults, it advised considering changing the passwords stored in their vault. It also warned that the attacker might target customers with phishing, credential stuffing or other attacks on accounts linked to their vault.
The lesson isn't that password managers are unsafe. It's that the strength of your master password matters, because it's what protects your vault if the encrypted copy is ever stolen.
What to do if your provider is breached
- Read the provider's own notice. Go to its website yourself. Don't follow links in emails about the breach, as criminals send fake ones.
- Change your master password if the notice suggests it, or if yours is short or used anywhere else.
- Turn on two-step verification for the password manager account if it isn't already on.
- Change your most important passwords first: email, then banking, then shopping and social media.
- Watch out for phishing that mentions the breach or your password manager.
- Decide whether to stay. Look at how the provider handled it and what it has changed.
Built-in or standalone?
Built-in password managers come with your device or browser. The NCSC names Apple Passwords, Google Password Manager and Samsung Pass as common defaults. Apple's Passwords app works on iOS 18, iPadOS 18, macOS Sequoia and visionOS 2 or later, and stores passwords, passkeys and verification codes. If you use one type of device and browser, a built-in manager may be all you need.
Standalone (third-party) password managers are apps you install. The NCSC says one of their main benefits is that they can sync passwords across a mix of browsers and devices, such as an iPhone and a Windows laptop.
Passkeys: the next step
A passkey lets you sign in with your device's face, fingerprint or PIN instead of a password. The NCSC recommends choosing passkeys over passwords wherever they're available. It says passkeys resist phishing because they can't be intercepted, reused or stolen like passwords.
Your password manager is usually where passkeys are kept. The NCSC says it creates and protects them, and can sync them to your other trusted devices. For accounts that don't offer passkeys yet, the NCSC's advice is a strong, unique password with two-step verification.
How to choose one
The NCSC says the best password manager is the one that meets your needs and that you find easiest to use. Things to check:
- Does it work on all your devices and browsers?
- Does it support two-step verification for the account itself?
- Does it support passkeys?
- What happens if you forget your master password? The NCSC notes that many offer recovery options such as trusted contacts.
- Free or paid? Check what the free version leaves out, and the renewal price of the paid one.
- Does it warn you about breached or reused passwords?
- Can you share passwords with family, if you need to?
Unsure how strong a password is? Our Password Check runs on your device, so what you type isn't sent anywhere.
Sources
- Managing your passwords — National Cyber Security Centre (opens in a new tab)
- Passkeys: what you need to know — National Cyber Security Centre (opens in a new tab)
- 12-22-2022: Notice of Security Incident — LastPass (opens in a new tab)
- iCloud data security overview — Apple Support (opens in a new tab)
- Use the Passwords app to create, manage and share passwords and passkeys across Apple devices — Apple Support (opens in a new tab)
- Get started with Google Password Manager — Google Account Help (opens in a new tab)
- Get started with on-device encryption — Google Account Help (opens in a new tab)
Last checked: 22 September 2026
Optional · commercial links
Tools that can help
The steps above are free. If you would rather have a tool take care of it, these are the ones we link to.