Use a unique password, enable the strongest available multifactor method and verify recovery options while you still control the account.
I need to protect online accounts
Build layered account protection so one leaked password, lost device or phishing message does not expose every important service.
The safest way to start
Use a unique password, enable the strongest available multifactor method and verify recovery options while you still control the account.
Use a password manager to generate and store a different long password for each priority account.
Do not reuse passwords, store recovery codes in the same account they protect or approve unexpected sign-in prompts.
Stop entering credentials if the page, app or recovery request came from an unexpected link. Open the service through a saved bookmark or official app and verify independently.
Priority accounts have unique passwords stored in a manager.
Quick checks before changing anything
Use these checks to narrow the problem and avoid applying an unrelated fix.
Prioritize high-impact accounts
Start with primary email, password manager, financial, cloud storage and social accounts because they can reset or expose other services.
Check password reuse
Identify accounts sharing the same or similar password. Reuse turns one breach into a chain of account takeovers.
Review current recovery methods
Confirm recovery email, phone, trusted devices and backup codes are current and controlled by you.
Safe first actions
Mark actions as you complete them. Progress is stored only in this browser.
Step-by-step route
Continue only when the result of the current step supports the next one.
- 1
Secure the root accounts
Protect email and password manager first, then accounts that store money, files or identity information.
Expected resultAttackers cannot easily reset the rest of your account ecosystem. - 2
Replace reused credentials
Change exposed or reused passwords from a trusted device and sign out unknown sessions.
Expected resultEach service has an independent credential. - 3
Add phishing-resistant authentication
Register passkeys or hardware keys where supported and keep a tested backup method.
Expected resultA stolen password alone is insufficient for login. - 4
Monitor and maintain
Enable sign-in alerts, review connected applications and test recovery information periodically.
Expected resultProtection remains usable when a device or phone number changes.
Stop and escalate when
- Stop entering credentials if the page, app or recovery request came from an unexpected link. Open the service through a saved bookmark or official app and verify independently.
How to know the problem is resolved
- Priority accounts have unique passwords stored in a manager.
- MFA and recovery methods are enabled and tested.
- Unknown sessions and unused third-party access have been removed.
Recommended learning route
Open these lessons in order when you need more detail or want to prevent the issue from returning.
Use strong unique passwords
Understand why password reuse turns one breach into many compromised accounts.
Online Security · Secure Your AccountsSet up a password manager
Store and generate passwords while protecting the main vault account.
Online Security · Secure Your AccountsEnable multi-factor authentication
Prefer authenticator apps or security keys and store recovery codes safely.
Online Security · Secure Your AccountsPrepare account recovery
Update recovery email, phone and backup codes for important accounts.
Online Security · Backup and Incident ResponseRespond to a suspected compromise
Use a clean device, change credentials, revoke sessions and review account activity.
Online Security · Backup and Incident ResponseTipsMake tools and guides
Continue with a connected problem
FAQ
Do I need to change every password on a schedule?
Not automatically. Change passwords when they are reused, exposed, weak, shared or suspected compromised. Unique passwords and strong MFA provide more value than routine changes without evidence.
Are passkeys the same as passwords?
No. Passkeys use public-key cryptography and are designed to resist phishing. They still require protected devices, account recovery planning and secure device unlock.