How to Protect Your Accounts from Digital Scams
Laptop and phone with a security symbol on a tidy desk
Digital scams do not always require a sophisticated hack. Often, a message simply creates urgency and sends you to a familiar-looking sign-in page. Account security starts with calm, repeatable habits that anyone can use.
Secure your most important email first
Your primary email can reset many other accounts, so give it a long, unique password. A password manager makes unique passwords practical. Never reuse the same password for email, shopping and social networks.
Turn on multi-factor authentication
Use an authenticator app or security key when available, and store recovery codes somewhere safe outside your phone. Text messages are better than no second factor, but they are not the strongest option in every situation.
Pause before you click
- Check the sender and link character by character.
- Do not call a number inside a threatening account message.
- Open the service from its app or type the address yourself.
- Never send a login code to a “support agent” in chat.
Update devices and review sessions
Install operating-system and browser updates, and use a screen lock. Review signed-in devices for email and financial accounts monthly; sign out of devices you no longer own. Remove unused apps and review their permissions.
If you think you were targeted
Change the password from a trusted device, end active sessions and enable multi-factor authentication. Contact your bank using the number on your card—not the number in the message. Save the message and time of the incident, then report it to the platform. Acting quickly limits damage.