Every account, post and app leaks a little information about you, and it adds up into a profile that scammers and data brokers love. You can't be invisible, but you can plug the biggest leaks with a few habits.
Lock down the essentials
- Strong, unique passwords and a password manager — see safer passwords.
- Two-factor authentication on email, banking and social accounts.
- Protect your email above all — it's the reset key to everything else.
Share less
- Review privacy settings on social media; lock down who sees your posts.
- Don't post details that answer security questions (birthday, pet's name, hometown).
- Be wary of oversharing your location in real time — post the holiday photos when you're back.
- Only give apps the permissions they truly need.
Reduce your footprint
- Delete old accounts you no longer use.
- Think before entering your details on unfamiliar sites.
- Check whether your email has appeared in known data breaches, and change those passwords.
Related
Clean up what's already out there with cleaning up your digital footprint.
The mistakes that quietly undo everything else
You can have a password manager and two-factor turned on and still get taken apart by one careless habit. The leaks that actually hurt people are rarely dramatic hacks. They are small, repeated slips that hand someone the keys.
- Reusing your main email password anywhere. Your email is the master key — reset any other account and the code lands there. If that one password leaks, everything downstream falls with it.
- Answering security questions honestly. Your mother's maiden name or first school is often findable online. Treat those answers like passwords: make them nonsense you store, not facts anyone can dig up.
- Reading fake messages as real. Scammers copy the exact wording your bank uses. The tell is urgency plus a link. You are always allowed to hang up and ring the number printed on your card instead.
- Screenshotting things with details in shot. A photo of a new card, a boarding pass or a parcel label often has enough numbers or barcodes in the background to work with.
Never approve a login you didn't start
If a two-factor prompt or code turns up out of nowhere, someone already has your password and is trying to get in right now. Deny it and change that password immediately. A code is not a nuisance to tap past — it is an alarm going off.
What to do the moment something leaks
When you find out an account is compromised — a strange login, a reset email you didn't ask for, a mate saying they got a weird message from you — the first hour matters more than anything you did beforehand. Work in this order, because doing it out of sequence usually makes things worse.
- Secure your email first, always. Change that password and check the recovery phone and address haven't been swapped. Everything else can be reset through email, so it goes first.
- Then the money. Change banking and card passwords, and ring the bank if anything looks off. Most will freeze a card in minutes over the phone.
- Change any account sharing that old password. This is why reuse hurts — one leak becomes a scramble across ten logins.
- Turn on two-factor everywhere it was off, so the same break-in can't work twice.
- Warn the people who might get messaged in your name before they click anything.
How to know it actually worked
Locking things down is not a one-off you can forget. A quick check every few months tells you whether it held — and it takes about ten minutes, no cost, no apps to install.
- Open the active sessions or where you're logged in page on your email and main accounts. Anything you don't recognise — a device or city that isn't yours — log it out and change the password.
- Check whether your addresses show up in known data breaches. Most password managers now flag this for you automatically.
- Search your own name in a private browser tab. If a phone number or home address is sitting on a people-finder site, most let you request removal for free — it just takes a fortnight or so to drop off.