The way most accounts get broken into isn't clever hacking — it's a password you reused, leaked from some other site's breach, then tried everywhere else. Fix that one habit and you close the biggest hole.

The three rules

  1. Never reuse passwords across important accounts.
  2. Longer beats complicated. A passphrase like correct-horse-battery-staple is stronger and easier to type than P@ss1!
  3. Turn on two-factor authentication everywhere it's offered — especially email and banking.

Use a password manager

You can't remember 100 unique passwords, and you shouldn't try. A password manager generates and stores them, so you only remember one strong master password.

💡

Protect your email first

Your email is the master key — password resets for everything go there. Give it the strongest password and two-factor before anything else.

If you've been in a breach

  • Check whether your email appears in known breaches.
  • Change the password anywhere you reused it.
  • Turn on two-factor on those accounts.
💡

Related

If an account's already been compromised, see what to do when your account is hacked.