How to protect your accounts from being hacked
A practical plan covering passwords, password managers, passkeys, MFA, updates, phishing, and what to do after a suspicious sign-in.
Updated:
Most account takeovers do not begin with someone “breaking encryption.” They begin with a reused password, a phishing page, a malicious app, or access to an email inbox. Good protection uses layers: if one control fails, the next one prevents a complete takeover.
Start with the keys to everything else: secure your primary email, Apple or Google account, phone number, and password manager. They are commonly used to recover access to other services.
What are you protecting against?
Common scenarios include:
- a password leaks from one website and works on another;
- a user enters credentials on a page that imitates a bank, marketplace, or government service;
- a scammer convinces someone to read out an SMS or approve a push request;
- remote-control software is installed on the device;
- an open session remains on a lost or shared device;
- an attacker takes over email and resets other accounts through it;
- an app or browser extension receives excessive permissions.
A VPN alone does not stop these attacks. Passwords, authentication, devices, and recovery each need their own controls.
Step 1: secure email and the device’s main account
Email is often the key to password resets. An Apple or Google account controls backups, apps, synchronization, and device-finding tools.
For each of these accounts:
- Set a unique password that is not used anywhere else.
- Enable multifactor authentication.
- Verify the recovery phone number and email address.
- Store recovery codes somewhere protected outside the phone.
- Review active devices and end unfamiliar sessions.
- Remove old apps and services that still have account access.
If time is limited, secure email first, followed by banking, government, messaging, and social accounts.
Step 2: use a unique password everywhere
Password reuse turns a breach at a small store into access to email or banking. Every service needs a separate password.
Humans cannot remember dozens of random strings, so a password manager is the practical solution. It can generate long values, keep them in an encrypted vault, and fill a password only on the matching domain.
For the manager itself:
- create a long master passphrase used nowhere else;
- enable strong multifactor protection;
- store the emergency or recovery key separately;
- keep the app updated;
- do not save the master password in a note next to the vault.
NIST recommends long passwords, password managers, and checks against lists of known compromised passwords. A strong, unique password does not need to be changed every month without evidence of compromise.
Step 3: enable MFA or a passkey
Multifactor authentication adds another proof of identity to a password. Methods differ in phishing resistance:
- A passkey or FIDO2 hardware key is the strongest widely available option because authentication is bound to the real website.
- An authenticator app avoids mobile-network dependence, although a code can still be entered into a convincing phishing page.
- A contextual or number-matching push is convenient when the user checks the request carefully.
- An SMS code is better than a password alone but depends on the phone number and can be targeted through social engineering or SIM replacement.
If SMS is the only method, enable it. When passkeys or hardware keys are available, prefer them for email, financial, and administrative accounts.
Never approve a sign-in request you did not initiate.
Step 4: recognize phishing
The HTTPS padlock means the connection to the open website is encrypted. It does not prove that the site belongs to a bank or government agency: a scammer can obtain a certificate for a look-alike domain too.
Before entering information:
- inspect the full domain, not just the logo;
- do not open financial or government sign-in pages from messages or ads;
- be suspicious of urgency, threats of closure, or instructions to “move money to safety”;
- never install remote-control software at a caller’s request;
- never disclose codes, even when the caller knows your name or other details;
- when unsure, close the page and open the official app yourself.
A password manager provides an extra clue: if it does not offer the saved login, you may be on a different domain. This does not replace checking manually.
Step 5: update and lock devices
Enable automatic updates for the operating system, browser, and apps. Remove programs and extensions you no longer use; old code and unnecessary permissions increase the attack surface.
On phones and computers:
- use a screen PIN or password rather than a simple pattern;
- use biometrics as a convenient additional unlock method;
- enable storage encryption when it is not on by default;
- configure device finding and remote lock;
- avoid debugging modes and unknown installation sources unless needed;
- review camera, microphone, location, and accessibility permissions.
Backups do not prevent an account takeover. They protect data after theft, device failure, or ransomware. Keep at least one copy separate from the primary device.
Step 6: review active sessions
Every few months, open the security section of important accounts and inspect:
- devices and browsers;
- sign-in history;
- connected apps;
- email forwarding rules;
- recovery addresses and phone numbers;
- payment methods;
- newly registered passkeys and security keys.
End an unfamiliar session, then change the password and review MFA and recovery email. Changing the password without revoking sessions can sometimes leave an attacker with a valid token.
What a VPN does—and does not—protect
A VPN encrypts traffic between the device and the VPN server and changes the public IP seen by websites. That helps on an untrusted local network and limits what the local Wi-Fi operator can observe.
A VPN cannot:
- decide that a convincing website is fake;
- stop you from sending a code to a scammer;
- remove malware from the device;
- replace unique passwords and MFA;
- hide your identity from a service you sign in to;
- recover an account after a takeover.
Treat a VPN as one layer, not as an antivirus for the whole internet.
If an account has already been compromised
Use a trusted, updated device:
- Change the primary email password.
- End all sessions and remove unknown devices.
- Give the affected account a new unique password.
- Restore or reconfigure MFA and remove unknown passkeys or keys.
- Check email forwarding and recovery settings.
- If banking is involved, call the bank using an official number and review transactions immediately.
- Scan the device with built-in security tools and remove remote-control apps.
- Warn contacts if messages may have been sent in your name.
- Replace the same password anywhere else it was reused.
Do not pay someone in a private chat who promises to “recover” the account. Use the service’s official recovery process.
A 20-minute starting plan
- 5 minutes: enable MFA on the primary email account.
- 5 minutes: install a password manager and replace the reused email password.
- 3 minutes: save recovery codes away from the phone.
- 3 minutes: end old email and messenger sessions.
- 2 minutes: enable automatic updates.
- 2 minutes: confirm that remote device lock is configured.
Then migrate the remaining important accounts gradually and enable passkeys or MFA for each one.