The way most accounts get broken into isn't clever hacking — it's a password you reused, leaked from some other site's breach, then tried everywhere else. Fix that one habit and you close the biggest hole.
The three rules
- Never reuse passwords across important accounts.
- Longer beats complicated. A passphrase like correct-horse-battery-staple is stronger and easier to type than P@ss1!
- Turn on two-factor authentication everywhere it's offered — especially email and banking.
Use a password manager
You can't remember 100 unique passwords, and you shouldn't try. A password manager generates and stores them, so you only remember one strong master password.
Protect your email first
Your email is the master key — password resets for everything go there. Give it the strongest password and two-factor before anything else.
If you've been in a breach
- Check whether your email appears in known breaches.
- Change the password anywhere you reused it.
- Turn on two-factor on those accounts.
Related
If an account's already been compromised, see what to do when your account is hacked.