A scammer who tricks you in the moment is one threat. A scammer who buys your leaked password from a data breach and logs in without ever speaking to you is another, and no vigilance stops that one. The answer is layers: several independent locks, so that defeating one does not open the house. None is exotic, and the strongest is free.
Passwords: unique matters more than clever
The biggest password danger is not that someone guesses a weak one; it is reuse. When one site is breached — and sites are breached constantly — attackers try the leaked email-and-password pairs on banks, email and shopping sites everywhere, so a single reused password can unlock a dozen accounts at once. A password unique to each site contains the damage to that site.
Remembering a different strong password for every account is impossible, which is the problem a password manager solves: an encrypted vault that generates and stores a long random password for every site, so you memorize one strong master password. Length matters more than symbols, and the manager makes length free.
Two-factor authentication, and why the type matters
Two-factor authentication (2FA) adds a second lock: even with your password, a login also needs a one-time code or an approval, so a stolen password alone is not enough. Not all 2FA is equal:
- SMS codes (texted to your phone) are far better than nothing, but an attacker who talks your carrier into moving your number to their device — a "SIM swap" — receives them.
- Authenticator apps generate codes on the device itself, with no text to intercept.
- Hardware keys (a physical USB or tap device) are the strongest.
Any 2FA beats none, and an app code is meaningfully stronger than an SMS one. Protect the accounts that can reset everything else — email and the bank — with the strongest factor.
The credit freeze: the strongest lock, and it is free
A credit freeze locks your credit report at each of the three nationwide bureaus — Equifax, Experian and TransUnion — so no new lender can pull it. Because a lender will not open a card or loan without checking the report, a thief with your name and Social Security number still cannot open new accounts in your name.
Per the CFPB, a freeze is free by law; a bureau must place it within one business day of an online or phone request and lift it within one hour; it does not affect your credit score; and lenders you already have accounts with can still see your file. When you need new credit, you lift it temporarily. A fraud alert is the lighter option: it asks lenders to verify your identity rather than blocking the pull, lasts up to one year (seven for identity-theft victims who have filed a report at IdentityTheft.gov), and is also free.
| Protection | What it does | Cost | Effect on existing accounts |
|---|---|---|---|
| Credit freeze | Blocks new credit pulls entirely | Free at all three bureaus | None |
| Fraud alert | Asks lenders to verify your identity first | Free; one year, or seven with an identity-theft report | None |
| Credit monitoring | Alerts you after something changes | Often paid | None — it watches, it does not block |
Monitoring: catching what slips through
Locks reduce the odds; monitoring catches the rare thing that gets past them while it is small. Two habits do most of the work: glancing at bank and card statements for charges you do not recognize — a skimmer at a gas pump shows up as a charge you never made — and reading your credit reports for accounts you never opened. The reports are free at AnnualCreditReport.com, the only source authorized by law, at least yearly from each bureau and more often online. A fraudulent charge caught in week one is a quick dispute; a year later it is a tangle. See credit reports and recovery for reading a report and disputing errors.
Email: the master key
One account controls the rest: email. Almost every other login offers "reset my password — we'll email you a link," so whoever controls your inbox can seize nearly everything downstream. Email is the master key, and deserves a unique password and the strongest 2FA you can use.
Unique passwords contain a breach, 2FA survives a stolen password, a freeze survives a leaked Social Security number, and monitoring catches the straggler. Even with every lock in place a scam sometimes succeeds, so the final lesson covers the fast response when fraud does happen.