Enhanced Password Security in the Customer Portal
InvoiceCloud has strengthened the password-change process in the Customer Portal to provide customers with an additional layer of account protection.
Previously, customers who were already signed in could change their password without re-entering their current password. Now, customers must verify their current password before a new password can be saved, particularly if an active session or unattended device is accessed by someone else.
The Change Password page now includes a required Current Password field. To update a password, customers will:
- Enter their current password.
- Enter a new password. The password must be between 5 – 30 characters in length. They may include a special character, but it is not required.
- Confirm the new password.
- Save the change.

The current password is securely verified by InvoiceCloud. If it is entered incorrectly, the password change is blocked, and the customer receives an error message. Customers must also choose a new password that is different from their current password. (The new password must be between 5 – 30 characters in length, which may include a special character, but it is not required)
This enhancement applies only to customers changing their password while already signed in to the Customer Portal. It does not affect the Forgot Password process. Customers who enter the correct current password can continue updating their password through the same familiar experience, with one additional verification step.