Change your username and password through your account settings, not through email or phone
The safest way to change either one is to log into the account itself, find the settings or security section, and make the change there. Never respond to an email asking you to confirm a username or password change — that is almost always a phishing attempt designed to steal your login information. The real account owner (the website or service) already knows who you are because you are logged in.
Most services follow the same basic path: log in, go to Settings or Account, look for Security or Profile, and find the username or password option. Some services let you change your username once per year or not at all, so check whether the option exists before you decide on a new one. Password changes are almost always available and can be done as often as you want.
Key Takeaways
- Always change your password by logging into your account directly, never by clicking a link in an email or text message.
- When you change your password, use one that is at least 12 characters long and includes uppercase letters, numbers, and symbols — the longer and more random, the harder it is to guess.
- If you use the same password on multiple sites, change it on the most important ones first: email, banking, and any account linked to payment methods.
- Write down or save your new password in a password manager (like Bitwarden or 1Password) rather than in a notebook or browser autofill, so you do not lose it or leave it visible.
- After you change your password, check your account activity or login history to see if anyone else has been using your account.
Step-by-step: changing your password on common services
The exact steps vary, but the entry point is almost always in Settings. On Gmail, go to myaccount.google.com, click Security on the left, scroll to "How you sign in to Google," and click Password. On Facebook, click the down arrow in the top right, select Settings and Privacy, then Settings, then Security and Login, then click Edit next to Password. On Amazon, go to Your Account, select Login and Security, and click Edit next to Password.
When you enter your new password, the system will ask you to type it twice to make sure you did not make a typo. After you confirm, you will usually be logged out of all your other devices — this is a security feature, not a problem. You will need to log back in on your phone, tablet, or other computers using the new password. If you see a device you do not recognize in the list of active sessions, click the option to sign out of that device.
Some services (like Microsoft Outlook or Apple iCloud) will ask you to verify your identity before letting you change your password — you might need to enter a code sent to your phone or answer a security question. This extra step protects you if someone has already broken into your account. Do it even if it takes a few extra minutes.
Changing your username is harder and less common
Many services do not let you change your username at all once it is created. Twitter (now X) allows one username change per account. Instagram lets you change it as often as you want. Gmail does not let you change your username, though you can add an alias (a second email address that reaches the same inbox). LinkedIn allows one change every 6 months. Check your service's help section before you spend time choosing a new one.
If the service does allow a change, the option is usually in Settings under Profile or Account. You will type in the new username you want, and the system will tell you when ready whether it is already taken. After you change it, your old username becomes available for someone else to claim, so if you have used it for years and it is tied to your reputation or business, think carefully before letting it go.
What to do if you forget your new password right after changing it
If you change your password and then when ready forget it, use the "Forgot Password" link on the login page. The service will send a reset link to your email address (or text a code to your phone, depending on the service). Click the link or enter the code, and you will be able to set a new password. This works even if you just changed it five minutes ago.
This is why saving your new password in a password manager before you log out is important. A password manager like Bitwarden, 1Password, or Dashlane stores your passwords in an encrypted vault that only you can open with a master password. When you change a password, update it in the manager at the same time. If you do not use a password manager, write the new password down on paper and store it somewhere find — a locked drawer, not a sticky note on your monitor.
Changing your password after a breach or suspicious activity
If you receive a notice that a service you use has been breached, or if you see login activity you do not recognize, change your password when ready. Do this from a device you trust (your own computer or phone, not a public computer). If you cannot log in because someone has already changed your password, use the "Forgot Password" link and follow the recovery steps — usually confirming your identity through email or phone.
After you regain access and change your password, check what other accounts use the same password. If you used that password on your email, your bank, or any account linked to a payment method, change those passwords too. Breaches often expose thousands of passwords at once, and attackers test them on other popular services to see what else they can access. Changing your password on just one site is not enough if you reused it elsewhere.
Why a strong password matters more than a unique username
Your username is often public — people see it when you comment, post, or send a message. Your password is private and is what actually protects your account. A strong password is long (at least 12 characters, ideally 16 or more), includes uppercase and lowercase letters, numbers, and symbols, and does not contain words from a dictionary or personal information like your name or birth year.
Weak passwords like "Password123" or "Qwerty456" can be guessed in seconds by automated tools. Strong passwords like "Tr0pic@lSunset#2024$Blue" or "Elephant&Bicycle+Mountain9" take much longer to crack. The longer and more random, the better. If you cannot remember a long random password, that is exactly what a password manager is for — it remembers for you.
Frequently Asked Questions
Can I change my password on my phone, or do I need a computer?
You can change your password on your phone using the service's app or mobile website. The steps are the same as on a computer. After you change it, you will be logged out and will need to log back in with the new password.
What if I change my password and then forget it before I save it anywhere?
Use the "Forgot Password" link on the login page. The service will send a reset link to your email or a code to your phone. You can then set a new password. This works even if you changed it just minutes before.
If I change my password, will I be logged out of my phone or tablet?
Yes, most services log you out of all devices when you change your password. You will need to log back in on each device using the new password. This is a security feature that prevents someone who has stolen your old password from staying logged in.
Should I tell anyone else my new password?
No. Never share your password with anyone, including family members, friends, or customer service representatives. If someone needs access to your account, use the service's built-in sharing or permission features instead — most email, cloud storage, and social media services have ways to give someone access without giving them your password.
What if I use the same password on multiple sites and one of them gets breached?
Change your password on that site when ready, then change it on any other important accounts — email, banking, shopping sites, and anything linked to a payment method. Attackers test stolen passwords on popular services to see what else they can access. Using different passwords on each site prevents one breach from compromising everything.