ChatGPT SearchSep 23, 2026
The biggest gains come from securing your email, financial accounts, phone number, and devices together—because a hacker who gets into your email or phone may be able to reset your bank password.
1. Turn on MFA everywhere important
Enable multifactor authentication (MFA/2FA) for:
- Bank and credit-card accounts
- Investment/retirement accounts
- Payment apps
- Your primary email account
- Your phone/carrier account
- Tax and government accounts
If available, prefer a passkey, security key, or authenticator app over SMS codes. SMS is still useful when it's the only option, but it can be vulnerable to SIM-swap attacks.
2. Use unique passwords
Never reuse your banking password anywhere else. A password manager can generate and store long, unique passwords for you. The FTC recommends long passwords/passphrases and specifically recommends password managers as an option.
Your email password should be particularly strong and unique, because email is often the recovery mechanism for your other accounts.
3. Treat unexpected messages as suspicious
Don't log into your bank through links in unexpected emails or texts—even if the message looks legitimate.
Instead:
- Open your banking app yourself.
- Type the bank's known website address yourself.
- Call the number on the back of your card.
- Never give anyone a verification code you didn't initiate.
Phishing messages commonly impersonate banks, payment services, delivery companies, and other organizations to steal credentials or financial information.
4. Lock down your phone and carrier account
Set a strong phone passcode and enable biometric protection.
For your cellular account, set an account PIN/password and ask your carrier what protections it offers against unauthorized SIM transfers or number changes. This helps reduce the risk of someone taking over your phone number and intercepting SMS authentication codes.
5. Turn on account alerts
For every bank and card that supports them, enable notifications for:
- Purchases
- Transfers
- Withdrawals
- New payees
- Password changes
- New-device logins
- Address or contact-information changes
Fast notification can make a fraudulent transaction much easier to catch.
6. Keep your devices updated
Turn on automatic updates for your phone, computer, browser, and apps. Security updates frequently patch vulnerabilities that criminals could otherwise exploit.
Avoid doing sensitive banking on shared/public computers, and be cautious with unfamiliar Wi-Fi networks.
7. Protect the recovery process
Security questions can be surprisingly weak. Don't use answers that someone could find through social media or public records. If a service permits it, use unique, hard-to-guess answers and treat them like additional passwords.
Also save your MFA recovery codes somewhere secure—not in an easily accessible note on your phone.
8. Monitor your credit and accounts
Regularly review bank and credit-card statements. Consider using the free credit reports available through the official U.S. credit-reporting system and consider a credit freeze if you're concerned about identity theft.
If you think you've already been hacked
Act quickly:
- Contact the bank/card issuer using its official number.
- Change the compromised password from a clean, trusted device.
- Change any other account that reused that password.
- Secure your email account first if it may have been compromised.
- Revoke unfamiliar logged-in devices/sessions.
- Check for unauthorized transfers, new payees, or changed recovery information.
- If your device may contain malware, update security software and scan it before continuing to use it for sensitive activity.
If you only do five things today: use a password manager, make every financial password unique, enable MFA (preferably passkeys/authenticator/security keys), secure your email and phone accounts, and turn on banking transaction alerts.
Avoid doing sensitive banking on shared/public computers, and be cautious with unfamiliar Wi-Fi networks.
7. Protect the recovery process
Security questions can be surprisingly weak. Don't use answers that someone could find through social media or public records. If a service permits it, use unique, hard-to-guess answers and treat them like additional passwords.
Also save your MFA recovery codes somewhere secure—not in an easily accessible note on your phone.
8. Monitor your credit and accounts
Regularly review bank and credit-card statements. Consider using the free credit reports available through the official U.S. credit-reporting system and consider a credit freeze if you're concerned about identity theft.
If you think you've already been hacked
Act quickly:
Sources6
- consumer.ftc.govUse Two-Factor Authentication To Protect Your Accounts | Consumer Advice
- cisa.govImplementing Phishing-Resistant MFA
- consumer.ftc.govProtect Your Personal Information From Hackers and Scammers | Consumer Advice
- cisa.govCyb3R_Sm@rT!: Use a Password Manager to Create and “Remember” Strong Passwords | CISA
- consumer.ftc.govHow To Recognize and Avoid Phishing Scams | Consumer Advice
- consumer.ftc.govWhat To Do if You Were Scammed | Consumer Advice