The way most accounts get broken into isn't clever hacking — it's a password you reused, leaked from some other site's breach, then tried everywhere else. Fix that one habit and you close the biggest hole.
The three rules
- Never reuse passwords across important accounts.
- Longer beats complicated. A passphrase like correct-horse-battery-staple is stronger and easier to type than P@ss1!
- Turn on two-factor authentication everywhere it's offered — especially email and banking.
Use a password manager
You can't remember 100 unique passwords, and you shouldn't try. A password manager generates and stores them, so you only remember one strong master password.
Protect your email first
Your email is the master key — password resets for everything go there. Give it the strongest password and two-factor before anything else.
If you've been in a breach
- Check whether your email appears in known breaches.
- Change the password anywhere you reused it.
- Turn on two-factor on those accounts.
Related
If an account's already been compromised, see what to do when your account is hacked.
Mistakes that quietly undo all your work
You can set up a manager and still leave a back door open. The usual slip-ups aren't obvious, which is exactly why they catch people out.
- Reusing your master password somewhere else. The one password protecting all the others should exist nowhere but your head. If it's also your email login, you've merged your two most important accounts into one weak point.
- A strong password on a weak email. Your email is the master key to everything, because that's where reset links land. Lock it down first, not last.
- Storing 2FA codes in the same manager. Convenient, yes, but if someone gets into the vault they get both factors. Keep them separate where you can.
- Small tweaks on an old password. Adding a 1 or a ! to a leaked password fools nobody. Attackers try those variations first.
A worked example: securing one account properly
Say you're fixing your online banking. Here's the full loop, start to finish, so you can see what "done properly" actually looks like:
- Open your password manager and use its generate button. Take a long random string, not something you thought up.
- Log into the bank, change the password, and let the manager save it. Don't type it in manually anywhere else.
- Turn on two-factor authentication in the bank's security settings. Pick an authenticator app over SMS if it's offered.
- Save the backup or recovery codes it gives you somewhere offline, like a note in a drawer.
- Log out and log back in once to confirm the new password and the second step both work.
How to know it actually worked
When you log in fresh, you should be forced to enter the second factor. If it lets you straight in with just the password, 2FA isn't really on yet. Test it before you move on.
The realistic effort involved
People put this off because they imagine a lost weekend. It isn't. Setting up a manager takes fifteen minutes. After that you don't fix everything at once, you fix accounts as you naturally log into them over a few weeks. The five that matter most, email, bank, main shopping account, primary social account, and your phone or laptop account, are worth a focused hour up front. Free password managers cover most people fine, and paid tiers are usually a few pounds a month if you want family sharing or extras.