How to Keep Your Online Accounts Secure
Most Americans have online accounts with banks, shops, e-commerce sites, social media, email, and countless others. These accounts are often protected by flimsy passwords and weak security measures that hackers can exploit for identity theft and fraud.
If you’re concerned about your online security, check out our guide for simple measures you can implement across your accounts and devices.
Create Strong Passwords
Complex passwords are essential for account security. Short, weak passwords based on easily guessable information like your birthday or name are targets for hackers using brute force and dictionary attacks. Once a hacker enters your account, they can make unauthorized transactions, post on social media, read sensitive messages, and access other accounts that share the same password.
A strong password should be unique to your account and contain a combination of at least 16 numbers, symbols, and upper and lowercase letters. Dozens of long, memorable passwords can be challenging to keep track of, so a password manager is a good place to store them all if you’re struggling. With a master PIN, you can see all your online passwords and check which ones are vulnerable before the software suggests stronger alternatives.
Enable Multi-Factor Authentication (MFA)
MFA provides an additional layer of protection alongside a strong password. After providing your username and password, MFA asks for another step to prove it’s you attempting to log in. This second factor is usually done through something you own, like a biometric fingerprint scan or a text code sent to your smartphone.
Even if hackers have your password, they won’t have the second factor, whether it’s your phone requiring a facial scan or a prompt in an authentication app. Enabling MFA has been found to prevent 99% of automated hacking attacks, but you’ll still need to watch out for social engineering tactics like phishing.
Be Cautious of Phishing Scams
Phishing involves cybercriminals sending emails, texts, or AI-voiced calls to trick you into revealing your login details. The messages mimic correspondence from legitimate organizations like banks and are designed to promote a sense of fear and urgency, with messages like “action required to avoid account suspension.”
Phishing scams involve links to fake websites and apps that look like your bank or Amazon account, encouraging you to log in or provide credit card numbers. After you’ve entered your details, criminals can use the information to drain your account or take loans that max out your credit.
Before you click on any links, compare the email address to previous correspondence from the organization. Remember that legitimate companies don’t email or text links to update payment information.
Monitor Your Accounts Regularly
You should check your accounts often to spot any unusual activity and act early if something’s wrong by changing your passwords and logging out of all devices. In social media apps like Instagram, for example, you can set notifications to alert you when your account posts a story or logs in from an unusual location.
Turn on notifications for all your bank accounts. They’ll alert you to any spending, no matter how small, to catch fraudulent activity as soon as it occurs. If you notice spending you didn’t authorize, freeze the card and call your bank.

