Every account, post and app leaks a little information about you, and it adds up into a profile that scammers and data brokers love. You can't be invisible, but you can plug the biggest leaks with a few habits.

Lock down the essentials

  • Strong, unique passwords and a password manager — see safer passwords.
  • Two-factor authentication on email, banking and social accounts.
  • Protect your email above all — it's the reset key to everything else.

Share less

  • Review privacy settings on social media; lock down who sees your posts.
  • Don't post details that answer security questions (birthday, pet's name, hometown).
  • Be wary of oversharing your location in real time — post the holiday photos when you're back.
  • Only give apps the permissions they truly need.

Reduce your footprint

  • Delete old accounts you no longer use.
  • Think before entering your details on unfamiliar sites.
  • Check whether your email has appeared in known data breaches, and change those passwords.
💡

Related

Clean up what's already out there with cleaning up your digital footprint.

The mistakes that quietly undo everything else

You can have a password manager and two-factor turned on and still get taken apart by one careless habit. The leaks that actually hurt people are rarely dramatic hacks. They are small, repeated slips that hand someone the keys.

  • Reusing your main email password anywhere. Your email is the master key — reset any other account and the code lands there. If that one password leaks, everything downstream falls with it.
  • Answering security questions honestly. Your mother's maiden name or first school is often findable online. Treat those answers like passwords: make them nonsense you store, not facts anyone can dig up.
  • Reading fake messages as real. Scammers copy the exact wording your bank uses. The tell is urgency plus a link. You are always allowed to hang up and ring the number printed on your card instead.
  • Screenshotting things with details in shot. A photo of a new card, a boarding pass or a parcel label often has enough numbers or barcodes in the background to work with.

Never approve a login you didn't start

If a two-factor prompt or code turns up out of nowhere, someone already has your password and is trying to get in right now. Deny it and change that password immediately. A code is not a nuisance to tap past — it is an alarm going off.

What to do the moment something leaks

When you find out an account is compromised — a strange login, a reset email you didn't ask for, a mate saying they got a weird message from you — the first hour matters more than anything you did beforehand. Work in this order, because doing it out of sequence usually makes things worse.

  1. Secure your email first, always. Change that password and check the recovery phone and address haven't been swapped. Everything else can be reset through email, so it goes first.
  2. Then the money. Change banking and card passwords, and ring the bank if anything looks off. Most will freeze a card in minutes over the phone.
  3. Change any account sharing that old password. This is why reuse hurts — one leak becomes a scramble across ten logins.
  4. Turn on two-factor everywhere it was off, so the same break-in can't work twice.
  5. Warn the people who might get messaged in your name before they click anything.

How to know it actually worked

Locking things down is not a one-off you can forget. A quick check every few months tells you whether it held — and it takes about ten minutes, no cost, no apps to install.

  • Open the active sessions or where you're logged in page on your email and main accounts. Anything you don't recognise — a device or city that isn't yours — log it out and change the password.
  • Check whether your addresses show up in known data breaches. Most password managers now flag this for you automatically.
  • Search your own name in a private browser tab. If a phone number or home address is sitting on a people-finder site, most let you request removal for free — it just takes a fortnight or so to drop off.

Checklist

Written by Ashutosh Sharma

Frequently asked questions

How do I check if my details have already been leaked in a data breach?
Use a reputable breach-checking service or the built-in monitor in most password managers, which flags leaked accounts automatically. Enter your email and it lists which sites were involved. If your email shows up, change the password on those accounts — and anywhere else you reused the same one — straight away.
Is it safe to use public Wi-Fi if I'm careful?
Mostly, yes, because banking and shopping sites are encrypted anyway. The real risk is fake networks named to look official. Avoid logging into anything sensitive on Wi-Fi you can't verify, and if you use it often, a trustworthy VPN adds a sensible layer. Your phone's mobile data is usually safer than a random hotspot.
Should I pay for a service that removes my info from the internet?
You can do most of it yourself for free by requesting removal from people-finder sites one at a time, which typically takes a couple of weeks each to take effect. Paid services just automate the chasing and re-checking. They're worth it only if your details are widely spread or you genuinely won't do it manually.
What's the single most important thing to protect first?
Your primary email account. It's the reset point for almost everything else, so if someone controls it, they can walk into your bank, shopping and social accounts one by one. Give it your strongest unique password and two-factor authentication before you touch anything else — it's the lock that protects all the other locks.
Someone has my phone number — how worried should I be?
A number alone is fairly low-risk, mostly meaning more spam and scam calls. The danger is a scammer using it plus other details to impersonate you to your mobile provider and hijack the line, which defeats text-based codes. Ask your provider to add a PIN or port-out lock to your account, and switch important logins to an authenticator app rather than SMS.

People also ask