Firefox Password Manager - Alerts for breached websites

Revision Information
  • Revision id: 188188
  • Created:
  • Creator: Lamont Gardenhire
  • Comment: Added a new article
  • Reviewed: Yes
  • Reviewed:
  • Reviewed by: Lamont287
  • Is approved? Yes
  • Is current revision? No
  • Ready for localization: Yes
  • Readied for localization:
  • Readied for localization by: Lamont287
Revision Source
Revision Content

Starting in Firefox 70, Firefox Lockwise will show alerts about potentially vulnerable passwords that were exposed in data breaches. If it’s likely that one of your saved logins was exposed in a known data breach, you’ll see this alert with its associated login. Select Learn more about this breach to read details about the breach on Firefox Monitor.

Alerts for breached websites in Firefox Lockwise

How Firefox notifies about website breaches

Firefox checks the date of a known website breach against the date you saved a password for that website. If the website was breached after you saved your password, you’ll see this alert. The database of breached websites is provided by Have I Been Pwnd.

In a future release of the browser, Firefox will also check to see if you’ve reused any of these potentially vulnerable passwords with other logins you’ve saved to Lockwise. The browser does this by creating an encrypted list of your breached passwords, then checking it against all your saved passwords. Firefox does not keep logs of your plaintext passwords or know them.

Note: Firefox never sends your logins or passwords to third-party services or servers. It keeps all data regarding logins and breaches anonymous. Read more about the k-Anonymity technique Firefox uses to protect your data.

Turn off website breach alerts in Lockwise

Disabling the feature also prevents Firefox from checking to see if you’ve reused these potentially vulnerable passwords on any of your other saved logins.

  1. Click the menu button menu button retina and choose Preferences.
  2. Select Privacy & Security and go to the Logins and Passwords section.
  3. Deselect the checkbox for Show alerts about passwords for breached websites.