If you have signed in to StoreFeeder and been taken to a page headed Your password is not unique instead of straight to your dashboard, the password you use for StoreFeeder has been found in a public list of passwords exposed in previous data breaches. This guide explains what the message means, what your options are, and how to change your password.
What does this message mean?
It means your password has appeared somewhere in a public database of passwords leaked in past data breaches. It does not mean your StoreFeeder account has been breached, and it does not mean anyone has accessed your data.
Passwords collected from breaches at other companies are published and shared openly. Attackers work through those lists first when trying to break into accounts, because so many people reuse the same password across several sites. If your password is on one of those lists, it is a weak password no matter how complex it looks.
Why is StoreFeeder telling me this?
When you sign in, StoreFeeder now checks your password against Have I Been Pwned, an independent service that maintains the public record of breached passwords. If your password is found there, we show you this page so you can decide whether to change it.
Does StoreFeeder send my password to a third party?
No. Your password is never sent anywhere. The check works on a short, one-way fragment of a hash of your password, so neither StoreFeeder nor Have I Been Pwned can see, store or reconstruct the password itself.
What are my options?
You have two, and both are shown on the page:
- Change my password: takes you to the Change Password screen. Once you have set a new password, you carry on into StoreFeeder as normal. You will not be asked to sign in again.
- Skip for now: signs you in and takes you to your dashboard, exactly as before. The message will appear again the next time you sign in, until you change your password.
You are never locked out of your account. This is a recommendation, not a restriction.
How do I change the entered password to something else?
- On the Your password is not unique page, click Change my password.
- Enter your current password, then your new password twice.
- Click Submit.
- You will receive a confirmation email, and you will be returned to the part of StoreFeeder you were signing in to.
If you would rather come back to it later, you can change your password at any time from your user menu. If you have clicked Change my password but want to go back without changing it, use the Back link you will still be signed in.
Your new password must meet StoreFeeder’s password rules and cannot be a password you have used recently. It also cannot be a password that appears in the breach data if you choose one that does, it will be rejected and you will be asked to pick a different one.
Does this change how I sign in?
No. Everything else about signing in works exactly as it did before:
- If you use two-factor authentication, you will enter your authentication code first, as usual. The password message appears afterwards.
- Remember this device for 30 days still works in the same way.
- Password resets, account switching and signing out are unchanged.
Which users does this apply to?
All StoreFeeder users. Anyone whose password appears in the breach data will see the message, whichever account or permission level they use.
What should I use instead?
We strongly recommend changing your password if you see this message. When choosing a new one:
- Make it long, length matters more than symbols.
- Make it unique to StoreFeeder. Never reuse a password from another site.
- Avoid variations of an old password (for example adding a number or a
!to the end); if the original is in the breach data, the variation is one of the first things an attacker will try. - Consider using a password manager so you do not have to remember it.
If you use a shared or team login, change it once and let everyone who uses it know the new password or, better, ask your account administrator to set up individual logins.
If you see this message and are unable to change your password, or you are concerned that your account may have been accessed by someone else, contact StoreFeeder support straight away.
Comments
0 comments
Please sign in to leave a comment.