Account Security · Global
Passwords & 2FA
Most account takeovers come down to one thing: a stolen or reused password. Three simple habits shut that door — here’s how to set them up, and what to do if you’ve already been caught out.
Updated Aug 2026 · 7 min read
Email · Security alert
“New sign-in to your account from an unrecognised device”
You can be careful about every scam on this site and still lose an account to something quieter: a password that leaked in a data breach years ago, or the same password reused across a dozen sites. Billions of stolen passwords circulate online, and criminals simply try them everywhere.
The fix is three habits — a unique password per account, a password manager to handle them, and two-factor authentication — and they’re far easier to set up than most people expect.
Why Your Passwords Are the Weak Point
Every big breach dumps millions of email-and-password pairs onto the internet. If you reuse a password, one of those leaks hands attackers the key to your email, bank, and social accounts — automatically, at scale. Phishing pages do the same job in real time, capturing whatever you type. Both problems disappear once every account has its own long, unique password that you never type into a page you reached from a link.
1. Use a Password Manager
Trying to invent and remember a different strong password for every site is impossible — so people reuse. A password manager solves that completely:
- It creates and remembers a long, unique password for every account, so one leaked password can’t unlock the rest.
- You only have to remember one strong master password.
- Its autofill won’t enter your password on a lookalike phishing site — a quiet but powerful anti-phishing check.
- Reputable managers use zero-knowledge encryption, so even the provider can’t read your vault.
Choose a reputable manager with zero-knowledge, AES-256 encryption, protect it with a strong master password you use nowhere else, and turn on 2FA for the manager itself. Then let it generate a fresh password for each account as you log in.
Our pick
Need one? pCloud Pass is a solid, privacy-first choice — zero-knowledge, AES-256 encryption, with a free tier to try.
Partner link — it may earn us a commission at no cost to you. Learn how we make money.
2. Turn On Two-Factor Authentication (2FA)
2FA means a stolen password alone isn’t enough to get in — a second step is needed. It’s the single biggest upgrade to your security. Not all 2FA is equal, though; from strongest to weakest:
Passkeys / security keys — strongest
A passkey (Face ID / fingerprint on your device) or a hardware security key can’t be phished, guessed, or reused. Turn these on wherever they’re offered.
Authenticator app — strong
An app (Google Authenticator, Authy, etc.) generates a rolling code on your phone. Far safer than SMS, and works offline.
SMS codes — weak, but better than nothing
A texted code is vulnerable to SIM-swap attacks and phishing, but still beats no 2FA. Use it only where nothing better is offered — and never on your email or bank if an app or passkey is available.
Turn 2FA on for your email first, then your bank, then everything else that offers it.
3. Secure Your Email First
Your primary email is the master key to your whole digital life: password resets for almost every other account run through it. If someone controls your email, they can take over the rest — so give it your strongest, most unique password and the best 2FA you can (an authenticator app or a passkey). Protect email like it’s the front door, because it is.
What to Do After a Scam or Breach
If you’ve entered your password on a fake page, been phished, or heard your details were in a breach, move quickly:
- 1
Change your passwords starting with your email — from a device you trust — and make each new one unique.
- 2
Turn on two-factor authentication (an app or passkey) on every important account, email first.
- 3
Check haveibeenpwned.com to see which of your accounts were exposed, and change any password you’d reused.
- 4
Review recent activity and active sessions in each account, and sign out unknown devices.
- 5
Watch for follow-on “your account was hacked — verify here” messages: those are often scams targeting people who were just breached.
Frequently Asked Questions
Do I really need a different password for every account?
Yes. When passwords are reused, a single breach at one site lets criminals unlock all your other accounts (it’s called “credential stuffing”). A password manager makes unique passwords effortless — you only remember one.
Isn’t a password manager risky — all my passwords in one place?
Reputable managers use zero-knowledge encryption, so even they can’t read your vault, and you protect it with a strong master password plus 2FA. The everyday risk of reusing passwords is far greater than the risk of a well-built manager.
Is SMS two-factor authentication good enough?
It’s better than nothing, but it’s the weakest form — vulnerable to SIM-swap attacks and phishing. Prefer an authenticator app or a passkey/security key, especially for your email and bank.
What are passkeys?
A passkey is a passwordless login tied to your device and unlocked with your face or fingerprint. Because there’s no password to steal, reuse, or phish, passkeys are the strongest option — enable them wherever they’re offered.
Which account should I protect first?
Your primary email. It’s the master key: anyone who controls your email can reset the passwords on almost everything else. Give it a unique password and the strongest 2FA available.
Related reading: how scammers phish your details, what to do after a scam, or browse all our scam guides.
Informational only — not security advice for a specific situation. Sources: NIST digital-identity guidance, the FIDO Alliance on passkeys, Have I Been Pwned, and CISA / NCSC advice on password managers and multi-factor authentication. Verify against primary sources.