Most account takeovers do not involve clever hacking. They happen because someone reused a password that leaked in one breach and an attacker tried it elsewhere, or because a convincing fake login page tricked them. Two habits fix most of that: using a password manager, and switching on stronger sign-in methods such as passkeys and two-factor authentication. You can set both up in a single afternoon.
Why reused passwords are the real problem
When a website is breached, lists of email addresses and passwords circulate among criminals, who then try the same combinations on banks, email, shopping and social accounts. This is called credential stuffing. If every account has a unique password, a breach at one company cannot unlock the others. The catch is that nobody can remember dozens of long, random passwords, which is where a password manager comes in.
What a password manager does
A password manager stores your logins in an encrypted vault protected by one strong master password. It generates long random passwords, fills them in for you and warns you about weak or reused ones. Many also store secure notes and two-factor codes. Options include standalone apps, browser-built managers and those built into your phone’s operating system. When you compare them, look for strong encryption, a good reputation and independent security audits, sync across your devices, and a sound account-recovery process.
Set up a password manager in five steps
- Pick a reputable manager and install it on your phone and computer.
- Create a long master password, ideally a passphrase of four or more unrelated words, that you do not use anywhere else.
- Turn on two-factor authentication for the manager itself and save its recovery codes somewhere safe and offline.
- Import existing logins from your browser, then delete the browser-saved copies if you switch fully.
- Change passwords for your most important accounts first: email, banking, cloud storage and your phone account. Use the generator to create each new one.
Your email account deserves special attention. Password-reset links go there, so whoever controls your email can often take over everything else.
Passkeys: sign in without a password
A passkey replaces the password with a cryptographic key pair. The public half is stored by the website; the private half stays on your device or in your password manager and never leaves it. You approve sign-in with your fingerprint, face or device PIN. Because there is no password to type, there is nothing to phish or to leak from the website’s database.
Passkeys are not available everywhere yet, so think of them as an upgrade to switch on where offered, not a replacement for a manager. When a service offers one, creating a passkey is usually a few taps in the account’s security settings. Keep at least one recovery method available in case you lose a device.
Two-factor authentication: which type to choose
| Method | Strength | Notes |
|---|---|---|
| Text message code | Better than nothing | Can be intercepted or diverted by SIM-swap fraud |
| Authenticator app | Good | Codes generated on your device; not dependent on the phone network |
| Security key or passkey | Strongest | Resistant to phishing; keep a backup key |
Use an authenticator app or a security key for email, banking and your password manager. Store recovery codes offline, not in a plain note on your phone.
Spotting phishing and scams
Even with great passwords, you can be tricked into handing over a code or clicking a bad link. Slow down when a message creates urgency. Warning signs include:
- A sender address that looks slightly off from the real one.
- Requests to verify an account, confirm a payment or claim a prize right now.
- Links whose visible text does not match the actual address when you hover over them.
- Requests for codes, gift card numbers or remote access to your device.
When in doubt, do not use the link in the message. Type the website address yourself or open the official app. Gift card requests are a classic scam signal, and it helps to know how legitimate codes are bought and redeemed; see our guide on how to redeem digital gift card codes and our checklist on whether a ticket marketplace is safe.
Check whether your data has leaked
Services such as Have I Been Pwned let you enter your email address to see whether it appeared in known breaches. If it did, change the password for that service and anywhere you reused it.
Keep your devices in shape
- Turn on automatic updates for your phone, computer, browser and apps.
- Use a screen lock on every device.
- Back up important files, ideally with one copy that is disconnected from your computer.
- Only install apps from official stores.
Your one-afternoon security checklist
- Install a password manager and set a strong master password.
- Secure your primary email account first.
- Turn on two-factor authentication for email, banking and social media.
- Enable passkeys where they are offered.
- Save recovery codes offline.
- Run a breach check and replace any exposed passwords.
- Enable automatic updates and a backup.
Security is not about being perfect; it is about making yourself a harder target than the next person. If you have just bought a new device, our laptop buying guide covers what to look for, and you can apply this checklist the day it arrives.
