Locking down your financial accounts
Password hygiene, two-factor traps, freeze-by-default credit, and the 90-minute security overhaul that makes you a hard target.
Your bank and brokerage accounts are only as safe as the weakest link protecting them — and for most people, that link is a reused password from 2014 that's already floating around in a data breach. The good news: financial account security is one of the highest-return afternoons in personal finance. About 90 minutes of setup makes you dramatically harder to rob than the average person, and criminals overwhelmingly prefer easy targets.
Passwords: the non-negotiables
- Use a password manager (1Password, Bitwarden, or your platform's built-in manager). Humans cannot memorize 40 strong unique passwords; software can.
- Every financial account gets a unique, generated password of 16+ characters. Unique is the keyword — reuse is how one breached shopping site becomes a drained brokerage account.
- Your email password matters as much as your bank's, because email is where password resets go. Whoever controls your inbox can eventually control almost everything else.
- Check whether your credentials are already breached at haveibeenpwned.com, and rotate anything that appears.
Two-factor authentication — and its weak flavor
Two-factor authentication (2FA) means logging in requires your password plus a second proof, usually a code. Turn it on for every financial account, no exceptions. But know the hierarchy: app-based codes (Google Authenticator, Authy) and hardware keys (YubiKey) are strong; text-message codes are the weakest form, because criminals can hijack your phone number through a 'SIM swap' — sweet-talking or bribing a carrier employee into porting your number to their device. Where an app option exists, choose it over SMS, and call your cell carrier to add a port-out PIN to your account.
Freeze your credit — today, not someday
A credit freeze blocks anyone from opening new credit in your name, which neutralizes most identity theft. It's free at all three bureaus (Equifax, Experian, TransUnion), takes about ten minutes total online, and you can 'thaw' it in minutes whenever you legitimately apply for credit. There is essentially no downside for the years between credit applications. Freeze your kids' credit too — child identity theft often goes undetected for a decade.
The 90-minute overhaul
- Install a password manager and change passwords on your email, bank, brokerage, and retirement accounts first (15 min each tier).
- Enable app-based 2FA on email and every financial account; print or save the backup codes somewhere safe.
- Call your cell carrier and set a port-out PIN.
- Freeze your credit at all three bureaus and store the PINs in the password manager.
- Turn on account alerts: login notifications, transfers over $100, and new-payee alerts at every bank and brokerage.
- Set a calendar reminder to review authorized devices and linked apps annually, and remove anything you don't recognize.
Ongoing habits that keep you hard to rob
Security decays without maintenance. Keep your phone and computer updated (those updates patch the holes criminals use). Never log into financial accounts from links in emails or texts — type the address or use the official app. Treat any urgent, unexpected contact 'from your bank' as hostile until proven otherwise. And keep one family rule: no financial account changes requested by phone, text, or email get acted on without independently calling the institution back at its published number.
The 2FA hierarchy at a glance
| Method | Strength | Weakness |
|---|---|---|
| Hardware key (YubiKey) | Strongest — phishing-resistant | Costs ~$25–50; can be lost (buy two) |
| Authenticator app codes | Strong | Phishable if you type the code into a fake site |
| Push approval | Good | Approval-fatigue attacks — never approve unprompted |
| SMS text codes | Weakest | SIM-swap and forwarding attacks |
| No 2FA | None | Password breaches are routine; assume yours is out there |
If you only do three things
Perfection is optional; ordering isn't. If the full overhaul feels like too much this week, do exactly three things in this order. First, fix your email: unique password plus app-based 2FA, because email is the master key that resets everything else. Second, fix the account with the most money in it the same way. Third, freeze your credit at the three bureaus. Those three moves close the doors used in the overwhelming majority of real-world account takeovers — the rest of the checklist is valuable, but it's reinforcement, not foundation. Calendar the remainder for next month rather than letting the perfect defeat the adequate.
A closing note on recovery, because even hard targets get hit: know before an incident where your institutions' fraud lines are (saved in the password manager), report unauthorized transfers the day you spot them — reimbursement rights weaken with delay — and file at IdentityTheft.gov for an official recovery plan if identity theft is involved. Speed is the other half of security.
Households should also designate one shared, offline document listing account locations and emergency contacts — not passwords, just the map — so that a spouse or executor can act quickly if the account holder can't.
The bottom line
You can't make yourself unhackable, but you don't need to — you need to be expensive to rob. A password manager, app-based 2FA, a frozen credit file, a carrier PIN, and alert notifications will put you ahead of 95% of the population for about 90 minutes of work and almost no money. Do it this weekend; the criminals are already automated, and your defenses should be too.
Check your understanding
1 of 4Not quite — try again.
Get smarter about money every week
One email, no spam — practical guides and Worth updates. Unsubscribe anytime.
Put this into practice
Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.
Start free trial