What to do if…
a password manager shows unexpected vault changes or missing entries
Short answer
Stop making changes in the vault. From one trusted device, secure the password-manager account first, then check the service’s recovery options such as trash, item history, vault restore, previous versions, or sync conflicts.
Do not do these things
- Don’t start mass-editing passwords or deleting entries to tidy up; you may overwrite recoverable information.
- Don’t uninstall the password manager or wipe your device yet; you may lose local data or logs that help recovery.
- Don’t keep logging in and out on several devices to force syncing; it can spread a bad sync state.
- Don’t reuse your master, primary, or sign-in password anywhere else.
- Don’t share your password, 2-step verification codes, recovery codes, or emergency access details.
- Don’t use support links from unexpected emails, messages, adverts, or sponsored results; use the app’s help area or type the vendor’s address yourself.
What to do now
-
Freeze the vault state as much as you can.
Stop editing the vault. Close the password manager on other devices. If you are worried that a second device is pushing bad changes, temporarily disconnect that device from the internet while you secure the account from one trusted device. -
Secure the password-manager account from one trusted device.
Open the password manager’s official app or website. Check the account security, devices, sessions, or recent activity page for unfamiliar devices or sign-ins. Change the master, primary, or sign-in password to a new long passphrase, then use the service’s option to sign out other sessions or log out all devices. Turn on 2-step verification if it is not already on. -
Refresh recovery codes only after access is secure.
If the service provides recovery codes or emergency access settings, review them after changing the password and signing out other sessions. Generate new recovery codes if the service allows this, and store them somewhere separate from the affected vault. -
Make a quick record before trying recovery.
Write down or screenshot the date and time you noticed the issue, what is missing, any “vault updated” or “sync conflict” messages, recent device or session entries, and any security alerts. This can help the vendor support team understand what changed. -
Check built-in recovery inside the password manager.
Look for trash, archived items, item history, vault restore, previous versions, sync conflicts, or deleted-item recovery. If it is a shared, family, or work vault, check whether another member made a change and whether the service has an admin log or activity history. -
Secure the email account used for the password manager.
Change the email password if compromise is possible. Turn on 2-step verification. Check recent sign-ins, recovery email addresses, recovery phone numbers, filters, and forwarding rules, because email access can be used to reset other accounts. -
Check the device you are using before broad password resets.
Install pending operating system, browser, and app updates. Remove unknown browser extensions or apps. If you see repeated pop-ups, unexpected remote-access tools, or device-management prompts you did not set up, stop using that device for sensitive logins and get hands-on IT help. -
Protect the highest-impact accounts first.
If account compromise is possible, change passwords and turn on 2-step verification for your email, banking, main Apple, Google or Microsoft account, and any account that can reset other passwords. Include your mobile network account if it receives password-reset codes. -
Ask the password-manager vendor for account and vault help.
Use the vendor’s official support route and ask about unexpected vault version changes, restore points, deleted-item recovery, sync conflicts, shared-vault activity, and account access logs. -
Report fraud or cyber crime only if there has been fraud, money loss, or a crime.
In England, Wales and Northern Ireland, use Report Fraud. If you live in Scotland, report via 101. If money has left an account, contact your bank’s fraud team using the number in your banking app, on your card, or on the bank’s official website.
What can wait
- You do not need to decide today whether to switch password managers.
- You do not need to change every saved password immediately; secure the password manager, email, and most sensitive accounts first.
- You do not need to factory-reset devices unless there are stronger signs of compromise and simpler steps have not made the situation safe.
- You do not need to reconstruct the whole vault before contacting the vendor if restore or history tools may still be available.
Important reassurance
Missing entries or unexpected changes can come from a sync conflict, a shared-vault edit, a device restore, an update problem, or account compromise, and these can look similar at first. Freezing changes, securing access, and checking recovery options gives you a better chance of getting entries back and limiting damage.
Scope note
These are first steps only. Later decisions, such as deep malware checks, business incident response, fraud recovery, or changing password managers, may need specialist help from the vendor, IT support, your bank, or an appropriate cyber-security professional.
Important note
This is general information, not legal, medical, financial, therapeutic, technical, cyber-security, or professional advice. If you believe a crime is in progress, you are at immediate risk, or you have lost money, use official reporting routes and your bank’s fraud channels promptly.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.