Most account takeovers are not sophisticated. They exploit a reused password from an unrelated breach, or a one-time code intercepted in transit. A short list of settings, applied consistently, closes both of those doors.
Start with a password manager
Reusing a password is the single largest cause of account takeover, because one breach anywhere exposes every account sharing that password. A password manager makes unique passwords per account practical by generating and storing them, so you only need to remember one strong password: the manager's own.
Look for one with a strong master password requirement, encrypted storage, and a browser extension or app that autofills credentials — autofill also happens to be a mild phishing defense, since a manager will not autofill a password into a look-alike domain.
Turn on two-factor authentication, and choose the stronger option
Two-factor authentication requires a second proof of identity beyond your password. Not all methods offer equal protection:
- Authenticator apps generate a code on your device, not sent over a network, which resists interception.
- Hardware security keys are the strongest option for high-value accounts, requiring a physical device to complete login.
- SMS codes are better than nothing but can be intercepted through SIM-swap fraud, where an attacker convinces your carrier to move your number to their device.
Enable it everywhere it is offered, prioritizing email, banking, and any account with stored payment information. Where SMS is the only option offered, use it rather than skip two-factor entirely, and add a carrier PIN or port-out lock to your mobile account to make SIM-swapping harder.
Protect your email account above all others
Your primary email address is almost always the password-reset destination for every other account. Someone with access to your email can often cascade into your bank, retirement and social accounts one reset link at a time.
Give it your strongest password, app-based two-factor authentication, and periodically check two settings attackers commonly abuse to maintain quiet access: auto-forwarding rules (mail silently copied to an address you do not recognize) and recovery email and phone number (attackers often change these first, since it locks you out while they retain access).
Check what a stranger can reset with
Review the recovery options on your important accounts:
- Is the recovery email address current and one you still control?
- Is the recovery phone number current?
- If security questions are used, are the answers things a stranger could find on social media? Answers do not need to be true, only memorable to you and unguessable to anyone else.
Turn on login alerts
Most major platforms offer a notification for sign-ins from a new device or location. Turn this on for email, banking and social accounts. An alert you did not trigger is often the first sign of a problem, well before any damage compounds — pair this habit with the warning signs in how to know if your identity has been stolen.
Review connected apps and sessions periodically
Accounts accumulate third-party app connections and old logged-in sessions over time — a game that requested your social login years ago, a browser extension with broad permissions, a device you no longer own. Periodically review the "connected apps" or "active sessions" page most major platforms provide, and revoke anything you do not recognize or no longer use.
A realistic order of operations
- Set up a password manager and change your email password first.
- Turn on two-factor authentication on email.
- Update passwords on banking, then anywhere payment details are stored, using the manager to generate unique ones.
- Turn on two-factor authentication everywhere it is offered.
- Review recovery email, phone number and security questions on your most important accounts.
- Turn on login alerts where available.
- Review connected apps and revoke what you do not recognize.
None of this requires technical skill, and none of it costs money. It is the highest-leverage hour most people can spend on their own security, and it is the same foundation the rest of our cybersecurity coverage builds on — including how to protect yourself from identity theft and what to do after a data breach.
Frequently asked questions
Is SMS two-factor authentication safe enough?
It is better than no two-factor authentication, but it can be intercepted through SIM-swap fraud. An authenticator app or hardware key is stronger where the option exists.
What is the most important account to secure first?
Your primary email account, since it is typically the password-reset destination for most other accounts. Securing it with a strong unique password and two-factor authentication limits how far a single compromise can spread.
How often should I change my passwords?
Current guidance from security agencies favors long, unique passwords stored in a manager over frequent mandatory changes, since forced rotation often leads to weaker, predictable passwords. Change a password immediately if it appears in a breach.
What should I do if I get a login alert I did not trigger?
Change that account's password immediately, check for other signs of compromise such as unfamiliar sessions or forwarding rules, and enable two-factor authentication if it is not already on. See how to know if your identity has been stolen for related warning signs.