Google says data from its new “Password Checkup” Chrome extension shows that 1.5% of all website logins use credentials that have been compromised
Karl Bode / VICE :
Context & Ripple Effects
Six months after Google shipped the Password Checkup Chrome extension, which alerts users when their credentials appear in known breaches, the company is publishing what the tool observed in the wild: 1.5% of all website logins it checked relied on compromised credentials. The finding quantifies a problem Google had already sized indirectly — its earlier study with UC Berkeley counted 3.3 billion credentials stolen via third-party breaches in a single year, on top of phishing and keylogger theft.
The arc here is Google using Chrome as a measurement instrument first and a remediation layer second. It follows the same pattern as its 2015 extension that warned users typing their Google password into the wrong site: put the check where the password is entered, then let the telemetry justify broader intervention.
First-order effects
- Users running the extension who are part of that 1.5% get prompted to reset affected passwords immediately, turning an invisible breach exposure into an actionable queue.
- Websites whose login flows surface in Checkup data gain evidence of how much of their traffic authenticates with already-breached pairs — pressure that lands on their account-security practices without any regulator involved.
Second-order effects
- Browser rivals and password managers face rising user expectations for built-in breach alerting, since Chrome has made a passive password field look negligent by comparison.
- Credential-stuffing attacks lose yield at the margin: every reused-and-flagged password that gets reset shrinks the pool of valid pairs attackers recycle from third-party breaches.
Third-order effects
- If the pattern holds, credential hygiene migrates from user responsibility to platform enforcement — a trajectory Google itself extended by later deploying Duplex to help Chrome users fix compromised passwords automatically, moving from alerting to agent-driven remediation.
- Browsers consolidating this role make them de facto authentication auditors for the web, concentrating both security benefit and sensitive breach-matching data in a handful of browser vendors.
The trend: Browsers are evolving from neutral rendering surfaces into the web's default credential-enforcement layer, progressing from warnings to measurement to automated password repair.