Lock down your accounts
Four fixes that stop the vast majority of hacks. If you only ever do one section, make it this one.
1. Passwords
1. What is a good password?
If a hacker gets one password, they try it everywhere. Every account needs its own unique password.
A strong password is:
- Long: at least 16 characters
- Random: not a word, name, or birthday
- Unique: never reused across sites
Nobody can remember 100 unique passwords. That's why you need a password manager.
Recommended password managers:
2. Safely sharing passwords (Netflix, Spotify, etc.)
- Use a password manager's sharing feature. 1Password and Bitwarden both support shared vaults.
- Use the service's family plan. Netflix, Spotify and YouTube all offer family plans.
- If you must share manually, use a self-destructing link like onetimesecret.com.
- ❌ Use your name, birthday, or "password123"
- ❌ Reuse the same password on multiple sites
- ❌ Share passwords via text or email
- ❌ Store passwords on sticky notes or in Notes
- ✅ Let a password manager generate & save them
- ✅ Use a unique password per account
- ✅ Share via a shared vault or self-destructing link
- ✅ Lock your phone with Face ID / fingerprint / PIN
2. Multi-Factor Authentication (MFA)
1. What is it?
MFA adds a second step when logging in. Even if someone steals your password, they can't get in without this second factor. Think of it as a deadbolt on top of your door lock.
2. Three types compared
| Method | How it works | Security | Ease |
|---|---|---|---|
| Passkeys | Face, fingerprint, or device PIN. No code to type. | Best | Easiest |
| Authenticator app | 6-digit code that changes every 30 seconds. | Very good | Good |
| SMS codes | Code sent via text message. | Weakest | Easiest |
3. Recommended authenticator apps
Why SMS is the weakest: Attackers can hijack your phone number through "SIM swapping." Authenticator apps and passkeys are tied to your physical device, not your phone number.
4. Where to enable MFA in popular apps
| App | Where to find it |
|---|---|
| Gmail | Google Account → Security → 2-Step Verification |
| Settings → Accounts Center → Password & Security → Two-factor authentication | |
| Settings → Accounts Center → Password & Security → Two-factor authentication | |
| TikTok | Profile → Menu → Settings → Security → 2-step verification |
| YouTube | Managed via your Google Account (same as Gmail) |
a) Got a new iPhone? How to transfer your authenticator app
If you use Google Authenticator:
If you use Apple Passwords, codes sync automatically via iCloud.
b) Personal vs. work authenticator apps
Keep them separate. Your employer can remotely wipe a work authenticator. If your personal codes are in the same app, you could lose access to your own accounts.
c) Your phone is stolen. What now?
Before it happens (do this now):
- Save your recovery codes when you enable MFA.
- Use an authenticator with cloud backup (Authy, Apple Passwords, or Google Authenticator with sync).
- Enable Find My iPhone.
After it happens:
- Use Find My iPhone to lock and erase the stolen phone.
- Use your recovery codes to log in.
- Set up MFA again on your new device.
- Change passwords for email and banking.
- ❌ Rely on just a password
- ❌ Use SMS as your only second factor
- ❌ Mix work and personal in one authenticator
- ✅ Use passkeys wherever available
- ✅ Use an authenticator app for everything else
- ✅ Enable cloud backup in your authenticator
3. Recovery Codes
1. What are recovery codes?
One-time-use backup codes (usually 8-10) that let you log in if you lose your phone or authenticator app. They're your safety net.
2. Where to save them
| Option | Safe? |
|---|---|
| Printed and stored in a safe place at home | ✅ Yes |
| In a password manager (1Password, Bitwarden) | ✅ Yes |
| In a locked note on your phone + laptop | ✅ Decent |
| Screenshot saved only on your phone | ⚠️ Risky |
| In your email inbox | ❌ No. If hacked, exposed |
| Nowhere ("I'll remember") | ❌ Never |
- ❌ Save them in your email inbox
- ❌ Screenshot and leave in camera roll
- ❌ Skip saving them ("I'll do it later")
- ✅ Store in your password manager
- ✅ Print and keep in a safe or locked drawer
- ✅ Save immediately when you enable MFA
4. Keep Your Software Updated
When you see "update available", that often means a vulnerability has been disclosed and attackers are already scanning for unpatched devices.
- ❌ Click "Remind me later" for weeks
- ❌ Keep apps you never use
- ❌ Run outdated browsers
- ✅ Turn on automatic updates everywhere
- ✅ Restart after updates to activate them
- ✅ Delete unused apps to reduce risk
Learn to spot the scams
What attacks actually look like in real life: fake emails, fake calls, cloned voices and rigged QR codes.
5. Spot a Phishing Attack
Phishing = a fake message pretending to be from a trusted company to steal your login or money. It's the #1 way people get hacked.
1. Red flags
- ❌ Urgent language: "Your account will be closed in 24 hours!"
- ❌ Sender email doesn't match the company (e.g. support@appl3-help.com)
- ❌ Links go to weird URLs. Hover before clicking!
- ❌ They ask for your password, credit card, or 2FA code. Real companies never do this
2. What to do
- ✅ Don't click. Go directly to the website by typing it yourself
- ✅ Report phishing emails (Gmail: three dots → "Report phishing")
- ✅ When in doubt, call the company directly
6. Scam Calls & Texts
Scammers increasingly call or text instead of emailing, pretending to be your bank, a delivery company, the tax office, or even a relative in trouble.
1. Common scams
| They say... | Red flag |
|---|---|
| "This is your bank's fraud team, we need to verify your card" | Banks never ask for your PIN, full card number, or 2FA code by phone |
| "Pay this fine immediately or face arrest" | Real authorities don't threaten arrest over the phone |
| "Click this link to reschedule your delivery" | Unexpected delivery texts with links are almost always fake |
| "It's me, I'm in trouble, send money" (unfamiliar number) | Always verify by calling the person back on their known number |
2. What to do
- Hang up, then call the company back using the number on their official website or the back of your card, never a number given to you during the call.
- Never share codes. One-time codes, PINs, or passwords should never be given over the phone.
- Slow down. Urgency and fear are the scam working as intended.
- ❌ Give codes, PINs, or passwords over the phone
- ❌ Call back a number given to you during the call
- ❌ Click links in unexpected delivery/bank texts
- ✅ Hang up and call the official number yourself
- ✅ Verify "it's me" messages with a phone call
- ✅ Report scam texts (forward to 7726 / "SPAM" in many countries)
7. AI Voice Cloning & Deepfakes
Scammers can now clone a voice from just a few seconds of audio: a TikTok clip, a voicemail greeting, an Instagram story. Then they call a parent or grandparent: "It's me, I'm in trouble, I need money right now." It sounds exactly like the real person, because in a way it is their voice.
1. Common versions
| The setup | The tell |
|---|---|
| "Grandma, I had an accident, don't tell mom, send money" | Urgency + secrecy + money is always a scam pattern, whatever the voice sounds like |
| A "boss" or "CEO" calls asking for an urgent payment or gift cards | Real organizations don't request payments by phone out of the blue |
| A video call that looks like a loved one or celebrity asking you to invest | Deepfake video often has odd lighting, lip-sync drift, or excuses to keep it short |
2. How to protect your family
- Agree on a family code word. A word only your family knows. Any urgent "it's me" call must include it. No code word, no money, no exceptions.
- Hang up and call back on the person's known number. A real relative in trouble won't mind.
- Verify on a second channel. Text or message the person directly before acting on any voice or video request.
- Slow down. The entire scam depends on panic. Anyone who won't give you five minutes to verify is not who they claim to be.
8. QR Code Scams ("Quishing")
Quishing = phishing via QR code. Scammers print malicious QR codes on stickers and place them over real ones, or put them in emails, because QR codes slip past spam filters that would catch a suspicious link.
1. Where it happens
- ❌ Parking meters & EV chargers: a sticker over the real payment code sends you to a fake payment page
- ❌ Restaurant menus & posters: tampered codes in public places
- ❌ Emails & letters: "scan to verify your account" or fake package notices
- ❌ Unexpected packages: a QR code inside a parcel you never ordered
2. How to stay safe
- Read the URL preview before tapping. Your camera shows the link. Check the domain looks right (e.g. your city's real parking site, not parking-pay-now.xyz).
- Look for sticker tampering: peeling edges, a code stuck on top of another, or a code that doesn't match the sign's design.
- Pay another way when unsure. Use the official app or type the website address yourself.
- Never download an app from a QR code. Get apps only from the App Store / Google Play.
- Never enter passwords or card details on a page you reached by scanning something in public.
Be careful on public Wi-Fi
Cafés, airports, hotels: how to browse safely away from home.
9. Public Wi-Fi and VPNs
Attackers can set up fake Wi-Fi networks and intercept your traffic. A VPN encrypts everything between your device and the internet.
Recommended VPNs
- ❌ Use public Wi-Fi without a VPN
- ❌ Auto-join open networks
- ❌ Use unknown free VPNs (many sell your data). ProtonVPN's free tier is the safe exception
- ✅ Use Mullvad, ProtonVPN, or IVPN
- ✅ Verify Wi-Fi names with staff first
- ✅ Disable auto-join for public networks
If something goes wrong
Your emergency plan. Read it once now, so you know where it is when you need it.
10. What To Do If You've Been Hacked
Don't panic: most account takeovers can be reversed if you act quickly and in the right order.
1. Signs you've been hacked
- ❌ Your password suddenly stops working
- ❌ Login alerts from places or devices you don't recognize
- ❌ Friends receive strange messages "from you"
- ❌ Password-reset emails you didn't request, or charges you didn't make
2. Recovery checklist, in this order
- Secure your email account first. Whoever controls your email can reset every other password. Change its password and sign out of all other sessions.
- Check your email settings for tampering. Attackers add forwarding rules or filters to keep spying after you change the password (Gmail: Settings → Forwarding and Filters).
- Change passwords on important accounts: bank, then anything using the same or similar password. Make each one new and unique.
- Turn on MFA on every account that offers it (see card 2 (Multi-Factor Auth)).
- Sign out everywhere. Most services have "log out of all devices" under security settings.
- Money involved? Call your bank's fraud line immediately and dispute the charges.
- Warn your contacts so they don't fall for messages sent from your account.
- ❌ Pay a ransom or reply to blackmail emails
- ❌ Reuse a variation of the old password
- ❌ Stop at one account. Assume they tried others
- ✅ Fix email first, then bank, then the rest
- ✅ Take screenshots of evidence before deleting
- ✅ Report identity theft to your local authority