Security Hacks for Beginners

How to keep your data secure

By Julie Coorevits

Step 1 · Start here

The Essentials

The 10 protections everyone needs: passwords, 2FA, scams and what to do if you get hacked.

✓ You are here
Step 2 · At your own pace

Level Up

14 more protections for your phone, your family, your home network and your privacy.

Go to Step 2 →
On this page
1 Passwords 2 Multi-Factor Auth 3 Recovery Codes 4 Software Updates 5 Phishing 6 Scam Calls & Texts 7 Voice Cloning 8 QR Code Scams 9 Public Wi-Fi & VPNs 10 If You've Been Hacked
On page 2 · Level Up →
11 Your Phone 12 Encryption 13 Backups 14 Browser Security 15 Online Shopping 16 AI Chatbots 17 Kids & Family 18 Digital Legacy 19 Custom DNS 20 Router & Wi-Fi 21 Smart Home 22 Social Media 23 Privacy Audit 24 Email Aliases

Lock down your accounts

Four fixes that stop the vast majority of hacks. If you only ever do one section, make it this one.

1. Passwords

Use a password manager. Never reuse passwords.

1. What is a good password?

If a hacker gets one password, they try it everywhere. Every account needs its own unique password.

A strong password is:

  • Long: at least 16 characters
  • Random: not a word, name, or birthday
  • Unique: never reused across sites

Nobody can remember 100 unique passwords. That's why you need a password manager.

Recommended password managers:

Bitwarden Free 1Password Apple Passwords Free
📱 iPhone walkthrough
How to set up Apple Passwords on your iPhone Coming soon
Settings → Passwords → enable AutoFill → start saving passwords

2. Safely sharing passwords (Netflix, Spotify, etc.)

  1. Use a password manager's sharing feature. 1Password and Bitwarden both support shared vaults.
  2. Use the service's family plan. Netflix, Spotify and YouTube all offer family plans.
  3. If you must share manually, use a self-destructing link like onetimesecret.com.
❌ Don't
  • ❌ Use your name, birthday, or "password123"
  • ❌ Reuse the same password on multiple sites
  • ❌ Share passwords via text or email
  • ❌ Store passwords on sticky notes or in Notes
✅ Do
  • ✅ Let a password manager generate & save them
  • ✅ Use a unique password per account
  • ✅ Share via a shared vault or self-destructing link
  • ✅ Lock your phone with Face ID / fingerprint / PIN

2. Multi-Factor Authentication (MFA)

Add a second lock to your accounts. Passkeys > authenticator app > SMS.

1. What is it?

MFA adds a second step when logging in. Even if someone steals your password, they can't get in without this second factor. Think of it as a deadbolt on top of your door lock.

2. Three types compared

MethodHow it worksSecurityEase
PasskeysFace, fingerprint, or device PIN. No code to type.BestEasiest
Authenticator app6-digit code that changes every 30 seconds.Very goodGood
SMS codesCode sent via text message.WeakestEasiest

3. Recommended authenticator apps

Google Authenticator Microsoft Authenticator Apple Passwords Authy

Why SMS is the weakest: Attackers can hijack your phone number through "SIM swapping." Authenticator apps and passkeys are tied to your physical device, not your phone number.

4. Where to enable MFA in popular apps

AppWhere to find it
GmailGoogle Account → Security → 2-Step Verification
InstagramSettings → Accounts Center → Password & Security → Two-factor authentication
FacebookSettings → Accounts Center → Password & Security → Two-factor authentication
TikTokProfile → Menu → Settings → Security → 2-step verification
YouTubeManaged via your Google Account (same as Gmail)
📱 iPhone walkthrough
How to enable 2FA on Instagram Coming soon
Settings → Accounts Center → Password & Security → Two-factor authentication

a) Got a new iPhone? How to transfer your authenticator app

If you use Google Authenticator:

1Open Google Authenticator on your old phone.
2Tap the menu (⋯) → "Transfer accounts" → "Export accounts".
3Scan the QR code with Google Authenticator on your new phone.
4Verify all accounts appear, then delete from the old phone.

If you use Apple Passwords, codes sync automatically via iCloud.

b) Personal vs. work authenticator apps

Keep them separate. Your employer can remotely wipe a work authenticator. If your personal codes are in the same app, you could lose access to your own accounts.

Work: Microsoft Authenticator Personal: Google Authenticator

c) Your phone is stolen. What now?

⚠️ If you lose your phone and didn't back up your authenticator, you can get permanently locked out of your accounts. Set up cloud backup now, before it happens.

Before it happens (do this now):

  • Save your recovery codes when you enable MFA.
  • Use an authenticator with cloud backup (Authy, Apple Passwords, or Google Authenticator with sync).
  • Enable Find My iPhone.

After it happens:

  1. Use Find My iPhone to lock and erase the stolen phone.
  2. Use your recovery codes to log in.
  3. Set up MFA again on your new device.
  4. Change passwords for email and banking.
❌ Don't
  • ❌ Rely on just a password
  • ❌ Use SMS as your only second factor
  • ❌ Mix work and personal in one authenticator
✅ Do
  • ✅ Use passkeys wherever available
  • ✅ Use an authenticator app for everything else
  • ✅ Enable cloud backup in your authenticator

3. Recovery Codes

Your emergency backup keys. Save them before you need them.

1. What are recovery codes?

One-time-use backup codes (usually 8-10) that let you log in if you lose your phone or authenticator app. They're your safety net.

2. Where to save them

OptionSafe?
Printed and stored in a safe place at home✅ Yes
In a password manager (1Password, Bitwarden)✅ Yes
In a locked note on your phone + laptop✅ Decent
Screenshot saved only on your phone⚠️ Risky
In your email inbox❌ No. If hacked, exposed
Nowhere ("I'll remember")❌ Never
❌ Don't
  • ❌ Save them in your email inbox
  • ❌ Screenshot and leave in camera roll
  • ❌ Skip saving them ("I'll do it later")
✅ Do
  • ✅ Store in your password manager
  • ✅ Print and keep in a safe or locked drawer
  • ✅ Save immediately when you enable MFA

4. Keep Your Software Updated

Updates patch security holes. Turn on auto-update everywhere.

When you see "update available", that often means a vulnerability has been disclosed and attackers are already scanning for unpatched devices.

📱 iPhone walkthrough
How to turn on automatic updates on iPhone Coming soon
Settings → General → Software Update → Automatic Updates
❌ Don't
  • ❌ Click "Remind me later" for weeks
  • ❌ Keep apps you never use
  • ❌ Run outdated browsers
✅ Do
  • ✅ Turn on automatic updates everywhere
  • ✅ Restart after updates to activate them
  • ✅ Delete unused apps to reduce risk

Learn to spot the scams

What attacks actually look like in real life: fake emails, fake calls, cloned voices and rigged QR codes.

5. Spot a Phishing Attack

Fake messages that steal your login. Learn the red flags.

Phishing = a fake message pretending to be from a trusted company to steal your login or money. It's the #1 way people get hacked.

1. Red flags

  • Urgent language: "Your account will be closed in 24 hours!"
  • Sender email doesn't match the company (e.g. support@appl3-help.com)
  • Links go to weird URLs. Hover before clicking!
  • They ask for your password, credit card, or 2FA code. Real companies never do this

2. What to do

  • Don't click. Go directly to the website by typing it yourself
  • Report phishing emails (Gmail: three dots → "Report phishing")
  • When in doubt, call the company directly
Passkeys protect you from phishing. Even on a fake website, passkeys won't work on the wrong domain, so the login simply fails.

6. Scam Calls & Texts

Fake bank calls, fake deliveries, fake "it's me" texts. Hang up, don't click, call back yourself.

Scammers increasingly call or text instead of emailing, pretending to be your bank, a delivery company, the tax office, or even a relative in trouble.

1. Common scams

They say...Red flag
"This is your bank's fraud team, we need to verify your card"Banks never ask for your PIN, full card number, or 2FA code by phone
"Pay this fine immediately or face arrest"Real authorities don't threaten arrest over the phone
"Click this link to reschedule your delivery"Unexpected delivery texts with links are almost always fake
"It's me, I'm in trouble, send money" (unfamiliar number)Always verify by calling the person back on their known number

2. What to do

  • Hang up, then call the company back using the number on their official website or the back of your card, never a number given to you during the call.
  • Never share codes. One-time codes, PINs, or passwords should never be given over the phone.
  • Slow down. Urgency and fear are the scam working as intended.
Save your bank's real fraud line in your contacts now, before you ever need it.
❌ Don't
  • ❌ Give codes, PINs, or passwords over the phone
  • ❌ Call back a number given to you during the call
  • ❌ Click links in unexpected delivery/bank texts
✅ Do
  • ✅ Hang up and call the official number yourself
  • ✅ Verify "it's me" messages with a phone call
  • ✅ Report scam texts (forward to 7726 / "SPAM" in many countries)

7. AI Voice Cloning & Deepfakes

A few seconds of audio is enough to clone a voice. Agree on a family code word today.

Scammers can now clone a voice from just a few seconds of audio: a TikTok clip, a voicemail greeting, an Instagram story. Then they call a parent or grandparent: "It's me, I'm in trouble, I need money right now." It sounds exactly like the real person, because in a way it is their voice.

1. Common versions

The setupThe tell
"Grandma, I had an accident, don't tell mom, send money"Urgency + secrecy + money is always a scam pattern, whatever the voice sounds like
A "boss" or "CEO" calls asking for an urgent payment or gift cardsReal organizations don't request payments by phone out of the blue
A video call that looks like a loved one or celebrity asking you to investDeepfake video often has odd lighting, lip-sync drift, or excuses to keep it short

2. How to protect your family

  • Agree on a family code word. A word only your family knows. Any urgent "it's me" call must include it. No code word, no money, no exceptions.
  • Hang up and call back on the person's known number. A real relative in trouble won't mind.
  • Verify on a second channel. Text or message the person directly before acting on any voice or video request.
  • Slow down. The entire scam depends on panic. Anyone who won't give you five minutes to verify is not who they claim to be.
Do it now: set a family code word at your next dinner together. It costs nothing and defeats the most convincing scam that exists today.

8. QR Code Scams ("Quishing")

Fake QR codes on parking meters, menus and posters send you to scam sites. Read the link before you tap.

Quishing = phishing via QR code. Scammers print malicious QR codes on stickers and place them over real ones, or put them in emails, because QR codes slip past spam filters that would catch a suspicious link.

1. Where it happens

  • Parking meters & EV chargers: a sticker over the real payment code sends you to a fake payment page
  • Restaurant menus & posters: tampered codes in public places
  • Emails & letters: "scan to verify your account" or fake package notices
  • Unexpected packages: a QR code inside a parcel you never ordered

2. How to stay safe

  • Read the URL preview before tapping. Your camera shows the link. Check the domain looks right (e.g. your city's real parking site, not parking-pay-now.xyz).
  • Look for sticker tampering: peeling edges, a code stuck on top of another, or a code that doesn't match the sign's design.
  • Pay another way when unsure. Use the official app or type the website address yourself.
  • Never download an app from a QR code. Get apps only from the App Store / Google Play.
  • Never enter passwords or card details on a page you reached by scanning something in public.
A QR code is just a link you can't read. Treat every scanned code with the same suspicion as a link in a random email, because that's exactly what it is.

Be careful on public Wi-Fi

Cafés, airports, hotels: how to browse safely away from home.

9. Public Wi-Fi and VPNs

Public Wi-Fi is risky. Use a VPN to encrypt your connection.

Attackers can set up fake Wi-Fi networks and intercept your traffic. A VPN encrypts everything between your device and the internet.

Recommended VPNs

Mullvad ProtonVPN Free tier IVPN
❌ Don't
  • ❌ Use public Wi-Fi without a VPN
  • ❌ Auto-join open networks
  • ❌ Use unknown free VPNs (many sell your data). ProtonVPN's free tier is the safe exception
✅ Do
  • ✅ Use Mullvad, ProtonVPN, or IVPN
  • ✅ Verify Wi-Fi names with staff first
  • ✅ Disable auto-join for public networks

If something goes wrong

Your emergency plan. Read it once now, so you know where it is when you need it.

10. What To Do If You've Been Hacked

Your emergency checklist. Secure your email first. It's the key to everything else.

Don't panic: most account takeovers can be reversed if you act quickly and in the right order.

1. Signs you've been hacked

  • ❌ Your password suddenly stops working
  • ❌ Login alerts from places or devices you don't recognize
  • ❌ Friends receive strange messages "from you"
  • ❌ Password-reset emails you didn't request, or charges you didn't make

2. Recovery checklist, in this order

  1. Secure your email account first. Whoever controls your email can reset every other password. Change its password and sign out of all other sessions.
  2. Check your email settings for tampering. Attackers add forwarding rules or filters to keep spying after you change the password (Gmail: Settings → Forwarding and Filters).
  3. Change passwords on important accounts: bank, then anything using the same or similar password. Make each one new and unique.
  4. Turn on MFA on every account that offers it (see card 2 (Multi-Factor Auth)).
  5. Sign out everywhere. Most services have "log out of all devices" under security settings.
  6. Money involved? Call your bank's fraud line immediately and dispute the charges.
  7. Warn your contacts so they don't fall for messages sent from your account.
Check the damage: use the quick safety check at the bottom of this page to see if your email appears in known data breaches. It tells you which other accounts to prioritize.
❌ Don't
  • ❌ Pay a ransom or reply to blackmail emails
  • ❌ Reuse a variation of the old password
  • ❌ Stop at one account. Assume they tried others
✅ Do
  • ✅ Fix email first, then bank, then the rest
  • ✅ Take screenshots of evidence before deleting
  • ✅ Report identity theft to your local authority
Step 2 · At your own pace

Ready to level up?

14 more protections for your phone, your family, your home network and your privacy, on the next page.

Continue to Step 2: Level Up →

🔎 Quick safety check

📧 Has my email been in a data breach?

Check your email address against known public data breaches (powered by Have I Been Pwned).