Skip to content
← All guides

Prevention

Turn on two-factor authentication

The single change that prevents most account takeovers, which accounts to do first, and why not all methods are equal.

2 min read

If you only ever do one thing from this site, do this. A stolen password on its own stops being enough, which removes the most common way accounts are lost.

Fifteen minutes, in this order

  1. Email first

    Your inbox can reset every other account you own, so it is the one worth protecting most. Everything else is secondary to this.

  2. Then banking and anything holding money

    Including payment apps and any cryptocurrency exchange.

  3. Then the accounts that are you in public

    Social media, because losing one means someone impersonating you to people who trust you.

  4. Save your backup codes somewhere real

    Every service offers a set of one-time recovery codes. Print them, or put them in a password manager. Do not store them only in the account they unlock.

Not all second factors are equal

They are all far better than nothing. But there is a clear order:

  • A passkey or hardware key is the strongest. It cannot be phished, because it will not authenticate to a fake site at all.
  • An authenticator app is very good, and free. The codes are generated on your device and never travel anywhere.
  • A push notification that says approve or deny is good, as long as you actually read it rather than tapping approve on reflex.
  • SMS is the weakest, because a phone number can be moved to an attacker's SIM. Still, SMS is enormously better than no second factor, so use it if it is all a service offers.

The limit worth knowing

Two-factor authentication stops someone using a stolen password. It does not stop someone stealing the session after you have already signed in, which is what infostealer malware does. That is why it is possible to have it switched on and still be compromised.

The defences for that are different: keep devices updated, be careful what you install, and sign out of all sessions if anything looks wrong.

What if I lose my phone?

This is what the backup codes are for, which is why saving them properly is part of the setup rather than an optional extra. Most authenticator apps also offer an encrypted cloud backup so your codes move to a new phone. Turn that on when you set it up, not after you lose the device.

Is a password manager worth it as well?

Yes, and possibly more than anything else here. Reused passwords are the single most common cause of account takeover, and nobody can remember a unique one for every service. A password manager makes uniqueness effortless, and most will also warn you when a saved password appears in a known breach.

Need to report this?

Where to report cyber crime in your country, and where to find support.

Get help

This happened to them too

First-hand accounts from people who went through the same thing.

Related guides