Here’s what makes this one tricky: Google genuinely sends an email with almost exactly this wording. So does every scammer who has noticed how well it works. The difference comes down to a few details you can check in about thirty seconds — and one rule that keeps you safe either way.
Published 29 July 2026 · ~7 min read · By the Phixo team
An email lands with a jolt of a subject line: “Some of your saved passwords were found online.” Your first instinct is probably right on both counts — yes, this could be real, and yes, it could be a trap. Unlike most phishing themes, this one copies an email Google actually sends, which is precisely why it works so well as a scam. Let’s sort out which one you’re holding.
The rule that keeps you safe either way: never act on this email through its own links. If the warning is real, the exact same alert is waiting for you at passwords.google.com — type that address yourself, sign in as usual, and run Password Checkup there. If nothing shows up, the email was a fake and you’ve lost nothing but thirty seconds.
Google Password Manager — the thing that offers to save your passwords in Chrome and on Android — includes a feature called Password Checkup. It quietly compares your saved passwords against huge databases of credentials leaked in third-party data breaches. When one of your saved passwords shows up in a known breach, Google warns you: inside Chrome, inside your Google Account, and often by email.
The genuine email typically:
One important nuance: the breach usually isn’t Google’s. Some site where you had an account — a shop, a forum, an old app — got breached, the stolen password list ended up circulating online, and Google spotted that one of your saved passwords was in it. The alert is Google doing you a favour.
Look at it from the attacker’s side: this is the perfect phishing template. It’s scary (“your passwords are exposed”), it’s plausible (Google really sends it), and its natural next step is the exact thing phishing wants — getting you to a sign-in page. The fake version copies Google’s layout and wording, swaps the button destination for a lookalike login page, and waits for you to type your Google password into it. One password typed into the wrong box, and the attacker owns the account that resets every other account you have.
The real address ends in accounts.google.com — the registered domain is google.com. Fakes rely on the brand name appearing somewhere in the address: google-account-security.com, security-google.net, accounts-google.com. All of them contain “google”; none of them are google.com. The only part that matters is what comes immediately before the final dot-com (or dot-net, and so on).
Google knows your name — it’s on the account. The real alert uses it. A generic “Dear User” or no greeting at all on a password warning is a strong fake signal.
The real email leads to Password Checkup inside your Google Account — and if you’re already signed in on that device, it won’t demand you re-enter your password on some intermediate page. A fake exists for exactly one purpose: to put a password box in front of you. Any version of “sign in to verify your passwords” on a page you reached from the email is the trap itself.
On desktop, rest your mouse on the button and read the destination in the corner of your browser. Real: an address on google.com. Fake: anything else, however official it sounds. On a phone, press and hold to preview the link — or better, don’t bother, and just use the direct route below.
This is the check that beats all fakes: open a new tab, type passwords.google.com, and run Password Checkup yourself. Real warnings will be right there, listed next to the affected sites. If Checkup shows nothing while the email screams emergency, you have your answer.
Don’t click anything in it. In Gmail, open the three-dot menu on the message and choose Report phishing — that both removes it and helps Google block the campaign for everyone else. If you already clicked and — worse — typed your Google password on the page it opened, treat it as compromised: change it right now at accounts.google.com (typed in yourself), sign out all other sessions, and switch on two-factor authentication. The full recovery sequence is in our password-recovery checklist.
This scam’s whole strategy is looking identical to a real Google email — and to a rushed human, it does. Software doesn’t rush. Phixo checks the details that don’t survive imitation: whether the sender’s registered domain is actually google.com or just contains “google”, whether the message passes the SPF, DKIM and DMARC authentication checks a real Google email always passes, where every link truly points, and whether the language leans on the re-login prompts and generic greetings that credential phishing can’t do without. You get the verdict with the reasons spelled out, before you’ve clicked anything.
Yes. Google Password Manager’s Password Checkup compares your saved passwords against known data breaches, and Google notifies you when there’s a match — including by email with wording very close to “some of your saved passwords were found online”. The email itself is real; the problem is that scammers send lookalike versions, so check the sender before acting.
Yes — that’s Google’s genuine address for account and security notifications, including password alerts. But treat the address as one check, not the whole answer: display names can be dressed up, and scammers register lookalike domains hoping you’ll skim. The safe move is to skip the email’s links entirely and go to your Google Account directly.
Not through the email. Open a new tab, type passwords.google.com, sign in as normal, and run Password Checkup. It lists compromised, reused and weak passwords straight from Google’s own data. If the alert was real, the same warnings will be waiting there; if Checkup is clean, the email was a fake.
Your Google password. The fake copies Google’s design and urgency, but its button leads to a lookalike sign-in page that records what you type. Google’s real alert never needs you to enter your password on a page you reached from the email — the real fix happens inside your Google Account, which you open yourself.
Change your Google password immediately at accounts.google.com, typed into the browser yourself — minutes matter. Sign out all other sessions from your security settings, turn on two-factor authentication, and change that password anywhere you reused it. Then work through the full recovery checklist.
Phixo is a browser extension that checks each email you open in Gmail or Outlook against several signals — sender and domain reputation, email authentication (SPF, DKIM, DMARC), Google Safe Browsing, link mismatches and lookalike domains — plus an AI read of the language, then flags anything suspicious with a plain-English reason before you click. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.