Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.
Issue abstract: Is warning message legitimate?
Detailed description: I logged into a website that I often log into and a Norton Password Manager warning message opened stating that my password was compromised and NPM would update it with a new, stronger password. I have never had this happen before and I have been using NPM for many years. I am highly suspicious, of course. I selected Ask me later. On my website account, I did change my password and then entered the new password in NPM manually.
Product & version number: NPM current
OS details: Windows 10, 19045.7291, with extended support
What is the error message you are seeing?
Norton Pass Comp..pdf (56.7 KB)
If you have any supporting screenshots, please add them:
bjm
June 5, 2026, 10:06pm
2
TSimonick:
Is warning message legitimate?
I logged into a website that I often log into and a Norton Password Manager warning message opened stating that my password was compromised and NPM would update it with a new, stronger password. I have never had this happen before and I have been using NPM for many years. I am highly suspicious, of course. I selected Ask me later. On my website account, I did change my password and then entered the new password in NPM manually.
Hello @TSimonick
Did you review Show more ?
======================
That prompt from Norton Password Manager is generally a legitimate security alert — it means Norton believes a password you saved in the vault appeared in a known data breach or leak database.
A few important nuances though:
The “Let us update it with a stronger one” part is Norton offering to:
generate a new strong password,
autofill it on the website,
save the new credential in your vault.
That workflow is normal behavior for modern password managers.
A few things to verify before trusting the prompt:
The dialog appears inside the legitimate Norton Password Manager browser extension or Norton UI.
The website you’re on is the correct official login page.
Your browser address bar is normal (no fake popup tab or suspicious domain).
The extension requesting the change is actually Norton’s official extension.
If everything checks out, the safest approach is usually:
Go directly to the affected site yourself.
Change the password manually (or let Norton generate one).
Use a unique password that is not reused anywhere else.
Enable two-factor authentication if available.
One caution:
If the prompt appeared unexpectedly on a random webpage, especially after redirects, ads, or suspicious browser behavior, do not blindly click “Update now.” Fake “password compromised” popups do exist on malicious sites pretending to be security software.
A real Norton password-change flow usually stays tied to:
the browser extension,
the actual login page,
and your authenticated Norton vault session.
Norton documents these “compromised password” and “update password now” warnings.
Key points from Norton’s own documentation:
“Your vault password is compromised alert” means Norton believes the password has appeared in known breaches or is considered unsafe. (Norton Support )
Norton also says:
And Norton explicitly recommends:
changing the password,
making it unique,
enabling 2FA where possible. (Norton )
One subtle distinction:
Some Norton docs refer specifically to the vault/master password.
Your popup wording sounds more like a website account credential stored in the vault.
But the underlying mechanism is similar: breach detection + password hygiene recommendations.
The wording:
“Let us update it with a stronger one and we’ll save it in your vault”
fits Norton’s documented password-generation/autofill workflow. (Norton )
https://haveibeenpwned.com/
https://haveibeenpwned.com/Passwords
Yes — for most people, it is considered safe to enter an email address into Have I Been Pwned.
It’s a widely respected breach-checking service created by security researcher Troy Hunt and is recommended by many cybersecurity professionals.
Even though the HIBP password checker is widely trusted in the security community, it’s still best practice not to casually type highly sensitive passwords — especially your password-manager vault/master password — into random devices or public/shared computers.
For normal site passwords, though, the service is broadly considered legitimate and widely used.
A few practical points:
An email address is already relatively public information on the internet.
Entering only your email address there is generally low risk.
You should never enter:
your vault/master password,
recovery phrases,
MFA backup codes,
or banking credentials.
For the /Passwords checker specifically, the site uses a privacy-preserving hash method so the full password is not sent in plaintext.
One thing to watch for:
There are fake lookalike domains. The real official site is exactly:
https://haveibeenpwned.com
—not variations like .to, .net, extra words, or typo domains.
AI sourced content may make mistakes
1 Like
Thank you very much for your detailed reply. I learned a lot by reading it.
1 Like