What to do if…
a password manager shows unexpected vault changes or missing entries
Short answer
Pause vault changes and use one device you reasonably trust to review the password-manager account. Secure access through the provider’s official app or website, then review available recovery options before restoring anything.
Do not do these things
- Don’t bulk-change or delete vault items yet. This may remove useful recovery options.
- Don’t uninstall the app, wipe a device, or factory-reset anything yet. Local data may still be useful.
- Don’t repeatedly sign in, force sync, or try recovery actions across several devices. This may make recovery harder.
- Don’t use support links from unexpected emails, texts, pop-ups, or messages. Use the provider’s official app or type its website address yourself.
- Don’t share screenshots containing passwords, recovery codes, one-time codes, or full account identifiers.
What to do now
-
Pause changes on other devices.
Close the password manager on your other devices. If one device keeps showing unexpected changes, temporarily take that device offline while you review the account. -
Review the password-manager account from one device you reasonably trust.
- Open the provider’s official app or type its website address yourself.
- Check the available device, session, login, or security-activity pages for anything you do not recognize.
- Use any available option to sign out unfamiliar sessions.
- Change the master password or account password if compromise seems possible and the provider’s official instructions support doing so.
- Turn on multifactor authentication (MFA), or confirm that it is still enabled, if the provider offers it.
- Check that any listed recovery email address and phone number are still correct.
- Replace recovery codes if the provider offers that option and you believe old codes may have been exposed.
- Contact official provider support if the correct order is unclear or you are worried about being locked out.
-
Record what you can see without exposing secrets.
Note when you first noticed the problem, which entries are missing or changed, any alerts, and any unfamiliar devices or sessions. Redact passwords, recovery codes, one-time codes, and full account identifiers before saving or sharing screenshots. -
Review recovery options before using them.
Look for trash, deleted items, item history, previous versions, restore options, sync-conflict notices, or account rollback tools. If a restore could overwrite current data, ask official provider support before continuing. -
Check whether another authorized person changed a shared vault.
For a family, work, or shared vault, check whether another member or administrator made the changes. Review any available activity log before restoring items. -
Secure the connected email account and check the device.
Use a new password and MFA for the email account connected to the password manager if compromise seems possible. Review recent email sign-ins. Update the operating system and browser, and run a reputable security scan if you see signs of device compromise. -
Protect accounts that can unlock other accounts.
If passwords may have been exposed, start with your primary email, financial accounts, mobile carrier account, and main Apple, Google, or Microsoft account. Use a device you reasonably trust and enable MFA where available. -
Use the appropriate official reporting route if needed.
Contact your bank, card issuer, or payment provider promptly if you see unauthorized transactions. Use IdentityTheft.gov if you think someone is using your personal information for identity theft. Use IC3 if you believe you have been affected by cyber-enabled crime or fraud.
What can wait
- You do not need to decide whether to switch password managers right now.
- You do not need to rotate every password at once. Start with accounts that can reset or unlock other accounts.
- You do not need to wipe or factory-reset a device while recovery options are still being checked.
Important reassurance
Missing entries or unexpected vault changes do not automatically mean that every password has been exposed. Pausing changes, securing account access, and reviewing recovery options can preserve your choices while you work out what happened.
Scope note
These are first steps only. Later decisions may need help from the password-manager provider, an IT professional, a financial provider, or a specialist incident-response service.
Important note
This is general information, not legal, medical, financial, therapeutic, security, or other professional advice.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.