01Use a password manager.
For accounts that still require passwords, use a reputable password manager to generate and store long, unique credentials. NIST recommends password managers and says the manager itself should support MFA.
HENDU26 PICK • AFFILIATE
NordPass
A password manager can help you create and store unique passwords instead of reusing credentials across financial accounts.
Explore NordPass →Affiliate disclosure: HENDU26 may earn a commission if you purchase through this link. Your price is not increased by HENDU26.

02Turn on MFA — or passkeys.
Enable multifactor authentication anywhere money or sensitive information lives. When a service supports passkeys, they can reduce phishing risk and eliminate the need to memorize another password.
03Never reuse important passwords.
A breach at one service should not unlock your email, bank, brokerage, rewards, or crypto accounts. Unique credentials contain the damage when one site is compromised.
04Treat unexpected messages as hostile.
Do not use links or attachments in unexpected account-alert messages. If a bank or service appears to contact you, open its known app or type the known website yourself and verify there.
05Turn on account alerts.
Use available alerts for logins, transfers, purchases, password changes, and profile changes. Fast detection matters when someone is trying to move money or take over an account.
06Install security updates.
Keep phones, computers, browsers, apps, and security software current. Updates routinely close flaws that attackers can use to reach accounts or data.
07Know your recovery path.
Keep recovery email addresses and phone numbers current, protect your primary email account especially well, and know how to contact financial providers using contact information you independently trust.