The main carveout to the "stop changing your password all the time" advice is simple: if a password is exposed in a data breach, change it immediately, as PCMag's Eric Griffith wrote in his password advice column.
That exception matters because the broader argument in Griffith's piece is not "never change your password." It is that regularly rotating a password just because a few months have passed is outdated guidance, assuming the password is already strong and unique. But once a breach enters the picture, the situation changes. Griffith puts it plainly: "Unless it's compromised in a data breach, of course. Then change it immediately."
The catch: some services will make you do it anyway
Even if security guidance has shifted away from forced periodic password changes, users may not get much say in the matter. Griffith notes that some employers, banks, and other services still require resets every few months, complete with the familiar prompt to enter a new password.
In other words, the newer advice may help explain best practice, but it does not override company policy or account rules. If your workplace or bank insists on regular password changes, you may still be stuck doing them.
That makes the practical takeaway less dramatic than "never rotate passwords again." A better summary is: don't change a good password on a timer for its own sake, do change it right away after a breach, and expect that some institutions will keep enforcing periodic resets regardless.
For readers, that means the important distinction is between a password that is merely old and one that may be compromised. Age alone is not necessarily the problem. Exposure is.