Make one stolen password less useful.

Stronger sign-ins, protected recovery channels, and careful alert handling can reduce the damage when credentials are exposed or an account is targeted.

A laptop and phone protected by password, passkey, and multifactor authentication symbols

Build security in layers.

Start with the accounts that control money, email, cloud files, and password recovery for other services.

Use a unique credential for every account

A password manager can help create and store long, unique passwords. Where a provider offers passkeys, review how they work before enabling them.

Turn on multifactor authentication

Use the strongest option the service supports and keep backup codes in a secure place. Never approve an unexpected sign-in prompt.

Protect account recovery

Check recovery email addresses and phone numbers, remove unfamiliar devices or sessions, and keep recovery information current.

Respond through a trusted path

If an alert looks suspicious, open the official app or type the known website address yourself instead of using the message link.

How to secure your email account

Protect the account that often controls password resets and security notices for your other services.

Open the email security checklist

Official starting point

NIST account security guidance