Over 99.9 percent of account compromise attacks could be blocked by multi-factor authentication (Microsoft Security Blog). That's the headline. But here's the catch: if you're like most people, you're still using passwords that are too short, reused, or already floating around on the dark web. This guide is for anyone who wants to stop being an easy target. I'm going to walk you through exactly what I'd do, step by step, to lock down your accounts.
1. Start with a Password Manager—No Excuses
If you're not using a password manager, you're making life easy for attackers. Password managers generate and store unique, random passwords for every account, which eliminates the biggest problem: password reuse (CISA). I know, you think you can remember your passwords. But you can't remember 50 unique, random ones. And you shouldn't have to. A password manager is the only realistic way to have a different, strong password for every site.
Here's what I'd do: pick a reputable password manager, install it on your phone and computer, and let it generate long, random passwords for every new account. For existing accounts, change the important ones first—email, banking, cloud. The goal is simple: no password should ever be used twice.
2. Make Your Passwords Long and Random
Length beats complexity. NIST, the federal guideline, says passwords used as the only authentication factor should be at least 15 characters long (NIST SP 800-63B). That's the minimum. I'd aim higher. Use your password manager to generate passwords that are 16 to 20 characters, mixing upper and lower case, numbers, and symbols. Or, if you have to remember a password, use the NCSC's advice: three random, unrelated words, like 'applenemobiro' (NCSC). That's long enough and strong enough, yet easy to remember.
What you should avoid: passwords based on birthdays, sports teams, or pet names. Those are often visible on social media, and attackers use them (NCSC). And don't bother with letter-to-symbol swaps like 'o' to '0'—they add little strength (NCSC).
3. Turn On Multi-Factor Authentication Everywhere
This is the single most important step. Microsoft says enabling MFA can block over 99.9 percent of account compromise attacks (Microsoft Security Blog). If you're not using MFA, you're leaving the door wide open. But not all MFA is equal. Prefer phishing-resistant MFA like authenticator apps, hardware security keys, or passkeys over SMS codes (CISA). SMS codes can be vulnerable to SIM swapping, where attackers trick your carrier into transferring your phone number to their SIM (CISA).
Start with your email, banking, and cloud accounts. If a service offers MFA, turn it on. Use an authenticator app or a hardware key if possible. If you must use SMS, treat it as a last resort.
4. Check If You've Been Pwned—and Rotate Those Passwords
Have you ever had an account breached? Probably. The free service Have I Been Pwned lets you check if your email or username has appeared in a known data breach (Have I Been Pwned). It was created after the Adobe breach, which at the time was the largest single breach of customer accounts, because the same accounts kept showing up exposed, often with the same passwords (Have I Been Pwned).
Here's what I'd do: go to haveibeenpwned.com and check every email address you use. If any show up, change those passwords immediately. Rotate any compromised passwords—and make sure the new ones are unique and strong. Don't reuse the old password anywhere.
5. Beware the Human Factor: Phishing Still Works
Here's the uncomfortable truth: most breaches aren't sophisticated hacks. They're people falling for phishing. Verizon's 2024 Data Breach Investigations Report found that 68% of data breaches involve a non-malicious human element, including people clicking phishing links (Verizon). And phishing is the most-reported crime to the FBI's IC3, with over 193,000 complaints in 2024 (FBI IC3).
Phishing isn't just email anymore. It's smishing (SMS), vishing (voice), and quishing (malicious QR codes) (CISA). The attacker's goal is to create urgency or fear. So pause before you click. Hover over links to see the real URL. Check sender addresses for misspellings. If something feels off, don't act.
6. Keep Everything Updated—and Watch Out for Ransomware
Software updates aren't just about new features; they patch security holes. CISA says to update all software promptly and back up data securely (CISA). But even with updates, you need to be careful. Ransomware—which encrypts your files and demands payment—often enters through phishing or exploited Remote Desktop Protocol (RDP) vulnerabilities (CISA). And attackers increasingly use double extortion, encrypting data and threatening to leak it (CISA).
My advice: enable automatic updates wherever you can. And back up your important files using the 3-2-1 rule: three copies, on two different media, one offsite. If ransomware hits, you can restore without paying. The FBI has helped victims avoid over $800 million in ransom payments since 2022 by providing decryption keys (FBI IC3), but it's better not to be a victim in the first place.
7. What Can Go Wrong If You Ignore This
If you don't do any of this, you're not just risking a minor inconvenience. In 2024, the FBI's IC3 received 859,532 complaints with reported losses of about $16.6 billion—a 33% increase over 2023 (FBI IC3). The average reported loss per complaint was $19,372 (FBI IC3). That's real money. And it's not just your bank account. Identity theft drew over 21,000 complaints in 2024 (FBI IC3). Business Email Compromise alone caused $2.77 billion in losses (FBI IC3).
Consider this scenario: you reuse the same password on your email and your bank. A breach at a random forum exposes that password. Attackers try it on your bank. They get in. They transfer money. You lose thousands. That's not hypothetical—it's how credential-stuffing works (Microsoft Security Blog).
Quick tip: If you're using a password manager, you can also generate a unique password for each site, so even if one site is breached, your other accounts are safe.
What I'd Actually Do
Here's my no-nonsense plan: First, sign up for a password manager and generate a master password that's a passphrase of three random words—long enough to remember, hard to crack. Second, install the password manager on all devices and start changing passwords for your critical accounts: email, banking, cloud. Third, enable MFA on every account that supports it, preferring authenticator apps or hardware keys. Fourth, check Have I Been Pwned for your email addresses and change any compromised passwords. Finally, make a habit of pausing before you click links in emails, and keep your software updated. Do that, and you'll be ahead of most people. Don't wait until you're a statistic.
Sources
- CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
- NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
- NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
- Microsoft Security Blog - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- Have I Been Pwned - https://haveibeenpwned.com/About
- FBI IC3 2024 Internet Crime Report - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!