Password Data Breach
Explanation of Password Data Breach error message
Why you are seeing this password warning
The message:
“This password has appeared in a data breach and cannot be used. Please choose a different password.”
appears because the password entered has been identified as compromised in a known public data breach.
This does not mean that Clearooms has suffered a data breach.
It means the password being used has previously appeared in a breach of another website or service and is now publicly known within global breach datasets. As a security precaution, Clearooms prevents the use of passwords that are known to be compromised.
It means the password being used has previously appeared in a breach of another website or service and is now publicly known within global breach datasets. As a security precaution, Clearooms prevents the use of passwords that are known to be compromised.
Why Clearooms blocks these passwords:
Clearooms enforces strong passwords and access controls as part of its security framework.
As confirmed in our Security Governance documentation, Clearooms:
As confirmed in our Security Governance documentation, Clearooms:
- Enforces a formal Password Policy
- Uses password managers and strong password controls internally
- Enforces multi-factor authentication (MFA) across remotely accessible services
- Stores Passwords using industry best-practice hashing methods
What this means for the user:
- The password entered is known to attackers from a previous, unrelated breach.
- Even if it was previously used on another website, it is now considered unsafe.
- Clearooms is blocking it to protect the account.
What the user should do
We recommend:
- Create a new, unique password that has not been used elsewhere.
- Use a password manager to generate a strong password (ideally 12–16+ characters).
- Avoid reusing passwords across different services.
- Enable multi-factor authentication (if not already enabled)
Reassurance:
Clearooms is Cyber Essentials and Cyber Essentials Plus certified and operates strict security controls across its platform. This password check is an additional safeguard to protect your organisation’s data.