PanicStation.org
us Technology & digital loss

What to do if…
your password manager stops unlocking and you cannot access your saved logins

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Do not reset, reinstall, wipe app data, or delete devices yet. First try a second device or browser where you may still be signed in, then use only the password manager’s official recovery options. If there are signs someone else got in, protect your email and financial accounts first from a device you trust.

Do not do these things

  • Do not uninstall the password manager, clear app data, factory-reset a device, or delete a browser profile as your first move; you may erase a local vault copy or lose a signed-in session.
  • Do not keep guessing the master password quickly; pause between attempts so you do not make panic mistakes or trigger extra account checks.
  • Do not use third-party “vault recovery” tools, upload vault files, or share recovery keys, secret keys, export files, or codes with strangers.
  • Do not start changing many account passwords from memory; that can create more lockouts.
  • Do not ignore unexpected security alerts, new-device emails, MFA prompts, missing items, or money movement; treat them as possible compromise until checked.

What to do now

  1. Stop making irreversible changes. Keep the device powered, keep any signed-in browser tabs open, and do not remove the app or extension.

  2. Try low-risk unlock checks once or twice.

    • Check Caps Lock, keyboard layout, copied spaces, and whether you are using the right account email.
    • Restart the app or browser once.
    • Check that the device date and time are automatic or correct, especially if time-based MFA codes are failing.
    • If the app supports offline unlock, try once offline and once online.
  3. Look for another access path.

    • Try another phone, tablet, computer, or browser where the vault may still be unlocked or recently signed in.
    • Try the provider’s official web vault, if available.
    • Try a different browser profile with extensions disabled if the browser extension is failing.
    • Check whether a family member, trusted contact, or work admin has an official recovery role for your plan.
  4. Check whether the provider is having a problem. Use the password manager’s official status page, support page, or verified status channel where available before you start account recovery.

  5. Use only official recovery routes that apply to your provider.

    • If the issue is a lost 2FA device, use the provider’s recovery code or lost-two-step-login process.
    • If you set up emergency access or a trusted contact, start that request from the provider’s app or web vault.
    • If it is a family, team, or work vault, ask the family organizer, team admin, or organization admin whether provider-supported account recovery is enabled.
    • If you forgot the master password, read the provider’s official page before resetting anything; some providers cannot decrypt or restore the vault without the correct password, secret key, recovery code, or pre-set recovery option.
  6. Protect the email account tied to the password manager.

    • From a device you trust, change the email password if you think someone else may know it.
    • Turn on two-factor authentication for that email account if it is not already on.
    • Check email forwarding rules, recovery email addresses, phone numbers, recent sign-ins, and connected devices; remove anything you do not recognize.
  7. If there are signs of compromise, handle the highest-risk accounts first.

    • Use a trusted device to check bank, card, payment, email, and phone-provider accounts.
    • Contact your bank or card issuer using the number on the card or the official website if money moved or a payment method was added.
    • Run a current security scan on the device you use for passwords if you saw suspicious prompts, malware warnings, or unknown sign-ins.
    • If someone used your personal information, use IdentityTheft.gov for recovery steps and documentation.

What can wait

  • You do not need to reset every saved password right now.
  • You do not need to choose a new password manager today.
  • You do not need to export, reorganize, or clean up the vault while access is unstable.
  • You can leave low-priority shopping, forum, and newsletter accounts until after email, financial, work, and phone-provider access is stable.

Important reassurance

This is stressful because one locked vault can block many accounts at once. Many lockouts come from fixable causes such as a wrong account email, keyboard issue, app problem, sync delay, expired session, or lost second factor. Slow, small steps protect the access you still have.

Scope note

These are first steps to stabilize access and prevent irreversible mistakes. If official recovery does not work, later decisions may need specialist technical help or a careful account-by-account reset plan, starting with email and financial accounts.

Important note

This is general information, not legal, financial, cybersecurity, or professional technical advice. Password managers differ, and some vaults cannot be decrypted without the correct master password, secret key, recovery code, or pre-set recovery option.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us