One password per account
Websites get hacked all the time. If you use the same password everywhere, a leak at a small web shop opens your email and bank too. Use a different password for every account — and a password manager to remember them.
Password managers
A password manager (built into your phone or browser, or a separate app like Bitwarden or 1Password) creates long random passwords and fills them in only on the real website — which also protects you from fake login pages. You remember one strong master password.
Two-factor authentication (2FA)
Turn on a second step for email, bank, social networks and cloud storage. An authenticator app or a security key is better than SMS. Remember: a stolen password alone is then not enough — unless you give away the code, which is exactly what scammers will ask for.
Passkeys — the future of login
A passkey replaces the password with your phone’s or computer’s unlock (fingerprint, face or PIN). It cannot be guessed, leaked from a website or typed into a fake page. Google, Apple, Microsoft and many banks and shops already support it — turn it on wherever it is offered.
Your email is the master key
- Whoever controls your email can reset almost every other password
- Protect it best: unique password, 2FA or passkey, recovery options up to date
- Check haveibeenpwned.com to see whether your address appeared in leaks
- Update your phone and apps — updates close holes attackers use