Clear, practical technology insights
Use care30 minute route

I need to protect online accounts

Build layered account protection so one leaked password, lost device or phishing message does not expose every important service.

Quick answer

The safest way to start

Use a unique password, enable the strongest available multifactor method and verify recovery options while you still control the account.

Quick answer

Use a unique password, enable the strongest available multifactor method and verify recovery options while you still control the account.

Best first action

Use a password manager to generate and store a different long password for each priority account.

What not to do

Do not reuse passwords, store recovery codes in the same account they protect or approve unexpected sign-in prompts.

When to stop

Stop entering credentials if the page, app or recovery request came from an unexpected link. Open the service through a saved bookmark or official app and verify independently.

Expected result

Priority accounts have unique passwords stored in a manager.

1 · Triage

Quick checks before changing anything

Use these checks to narrow the problem and avoid applying an unrelated fix.

Prioritize high-impact accounts

Start with primary email, password manager, financial, cloud storage and social accounts because they can reset or expose other services.

Check password reuse

Identify accounts sharing the same or similar password. Reuse turns one breach into a chain of account takeovers.

Review current recovery methods

Confirm recovery email, phone, trusted devices and backup codes are current and controlled by you.

2 · Stabilize

Safe first actions

Mark actions as you complete them. Progress is stored only in this browser.

3 · Diagnose and resolve

Step-by-step route

Continue only when the result of the current step supports the next one.

  1. 1

    Secure the root accounts

    Protect email and password manager first, then accounts that store money, files or identity information.

    Expected resultAttackers cannot easily reset the rest of your account ecosystem.
  2. 2

    Replace reused credentials

    Change exposed or reused passwords from a trusted device and sign out unknown sessions.

    Expected resultEach service has an independent credential.
  3. 3

    Add phishing-resistant authentication

    Register passkeys or hardware keys where supported and keep a tested backup method.

    Expected resultA stolen password alone is insufficient for login.
  4. 4

    Monitor and maintain

    Enable sign-in alerts, review connected applications and test recovery information periodically.

    Expected resultProtection remains usable when a device or phone number changes.

Stop and escalate when

  • Stop entering credentials if the page, app or recovery request came from an unexpected link. Open the service through a saved bookmark or official app and verify independently.
4 · Verify

How to know the problem is resolved

  • Priority accounts have unique passwords stored in a manager.
  • MFA and recovery methods are enabled and tested.
  • Unknown sessions and unused third-party access have been removed.
5 · Build the skill

Recommended learning route

Open these lessons in order when you need more detail or want to prevent the issue from returning.

Lesson 1

Use strong unique passwords

Understand why password reuse turns one breach into many compromised accounts.

Online Security · Secure Your Accounts
Lesson 2

Set up a password manager

Store and generate passwords while protecting the main vault account.

Online Security · Secure Your Accounts
Lesson 4

Prepare account recovery

Update recovery email, phone and backup codes for important accounts.

Online Security · Backup and Incident Response
Lesson 5

Respond to a suspected compromise

Use a clean device, change credentials, revoke sessions and review account activity.

Online Security · Backup and Incident Response
6 · Practice and reference

TipsMake tools and guides

Related routes

Continue with a connected problem

Common questions

FAQ

Do I need to change every password on a schedule?

Not automatically. Change passwords when they are reused, exposed, weak, shared or suspected compromised. Unique passwords and strong MFA provide more value than routine changes without evidence.

Are passkeys the same as passwords?

No. Passkeys use public-key cryptography and are designed to resist phishing. They still require protected devices, account recovery planning and secure device unlock.