I have a different password for EVERY site I visit. I use random special characters, numbers, and gibberish words, some in foreign languages. I have them in a file on my computer but that file is password protected. I turn off my network when I am not sitting at the computer.

Remember how well things can be spoofed. People get email from banks and stores all the time that look official because the scammers use the images from the real web pages. Your BROWSER'S password check said this. I don't consider that to be "official". I would love to see a copy of that report. If you have a unique password here, and there has been no activity here that you cannot remember, I don't think you have anything to be concerned about. I got hit once a few years ago before I went to completely unique passwords. From that moment I turned off the password save option on my browser. If it protects me, I can live without autofill and spend the 3 seconds it takes to type in a password. Autofill causes a lot of people problems, as many as those who use the same password everywhere.

The main one is to change your email password often. IF that password is compromised, I can go to a web page, use the "forgot password" link and create web pages as you because they will send the reset link to an email account with a compromised password. The hacker can then see the new password, act on the email, delete it and remove it rom trash and you won't even know it happened.

The key though, as Trevor said, is to use a unique password everywhere. And I will toss in to turn off autofill.