Prevention
Turn on two-factor authentication
The single change that prevents most account takeovers, which accounts to do first, and why not all methods are equal.
If you only ever do one thing from this site, do this. A stolen password on its own stops being enough, which removes the most common way accounts are lost.
Fifteen minutes, in this order
Email first
Your inbox can reset every other account you own, so it is the one worth protecting most. Everything else is secondary to this.
Then banking and anything holding money
Including payment apps and any cryptocurrency exchange.
Then the accounts that are you in public
Social media, because losing one means someone impersonating you to people who trust you.
Save your backup codes somewhere real
Every service offers a set of one-time recovery codes. Print them, or put them in a password manager. Do not store them only in the account they unlock.
Not all second factors are equal
They are all far better than nothing. But there is a clear order:
- A passkey or hardware key is the strongest. It cannot be phished, because it will not authenticate to a fake site at all.
- An authenticator app is very good, and free. The codes are generated on your device and never travel anywhere.
- A push notification that says approve or deny is good, as long as you actually read it rather than tapping approve on reflex.
- SMS is the weakest, because a phone number can be moved to an attacker's SIM. Still, SMS is enormously better than no second factor, so use it if it is all a service offers.
The limit worth knowing
Two-factor authentication stops someone using a stolen password. It does not stop someone stealing the session after you have already signed in, which is what infostealer malware does. That is why it is possible to have it switched on and still be compromised.
The defences for that are different: keep devices updated, be careful what you install, and sign out of all sessions if anything looks wrong.
What if I lose my phone?
This is what the backup codes are for, which is why saving them properly is part of the setup rather than an optional extra. Most authenticator apps also offer an encrypted cloud backup so your codes move to a new phone. Turn that on when you set it up, not after you lose the device.
Is a password manager worth it as well?
Yes, and possibly more than anything else here. Reused passwords are the single most common cause of account takeover, and nobody can remember a unique one for every service. A password manager makes uniqueness effortless, and most will also warn you when a saved password appears in a known breach.
This happened to them too
First-hand accounts from people who went through the same thing.
A fake alert inside my crypto app cost me $28,000
“I'm still reeling from this, but I need to get the story out there because it’s honestly terrifying how easily it…”
One dodgy download and someone was in my accounts by morning
“I’ll just come out and say it: I’m an idiot. I downloaded a file I knew was dodgy, and the internet gods punished me…”
I pirated a game and my PC started opening PowerShell on its own
“Last week I tried to download a pirated game. Shortly after, my Discord account got hacked but I caught it immediately.…”