Most of the damage from a typical data breach comes from one habit: reusing passwords. When a site is breached, attackers try the same email and password on banks, email providers and shopping sites. Two tools stop that almost completely: a password manager, so every account gets its own strong password, and two-factor authentication, so a password alone is not enough to log in.

You do not need to be technical, and you do not need to do every account today. This guide gives you an order that protects the most important accounts first.

Why reused passwords are the real risk

The FTC explains that scammers buy usernames and passwords stolen in data breaches and use them to log in, both on the breached site and on other sites where people used the same login. If every account has a different password, a breach at one site stays at that one site.

You can see whether a password you use has appeared in a known breach with the free Pwned Passwords feature of Have I Been Pwned, or with the password checkup built into many browsers and password managers, such as Google Password Checkup. If a password shows up, stop using it everywhere.

What makes a password strong

CISA, the federal cybersecurity agency, recommends passwords that are:

  • Long: at least 16 characters.
  • Random: either a random mix of letters, numbers and symbols, or a passphrase of several unrelated words.
  • Unique: a different password for every account.

Nobody can remember dozens of passwords like that, which is why CISA's own advice is to use a password manager.

How a password manager works

A password manager is an app that creates, stores and fills in your passwords. You remember one strong main password (sometimes called a master password), and the app remembers the rest. Most work across your phone and computer and can warn you about reused or breached passwords.

Options include the managers built into your phone or browser (for example from Apple, Google or Microsoft) and standalone apps, some free and some paid. For most people, the best password manager is the one they will actually use every day. Look for these basics:

  • It works on every device you use.
  • It supports two-factor authentication for the manager itself.
  • It can generate long random passwords and flag reused or breached ones.
  • It has a clear recovery process if you forget your main password. Write that recovery information down and keep it somewhere safe at home.

Set it up in this order

  1. Pick a password manager and create a strong main password. A passphrase of five or more unrelated words is easier to remember than a random string. Never reuse it anywhere.
  2. Turn on two-factor for the password manager.
  3. Your main email account. Change the password to a new generated one and turn on two-factor. Email is the key to password resets for everything else.
  4. Banking, cards and payment apps. New passwords, two-factor, and transaction alerts while you are there.
  5. Your mobile carrier account. Add a PIN or passcode if your carrier offers one. This makes it harder for someone to move your number to a new SIM.
  6. Any account named in a breach you found.
  7. Everything else, gradually. Each time you log in to an old account, let the manager replace the password. Within a few weeks most accounts are done.

Two-factor authentication, explained

Two-factor authentication adds a second step after your password. Even if someone has your password, they cannot get in without the second factor. The FTC calls it the best way to protect your accounts, and CISA recommends turning it on for every account that offers it. You usually find it under Settings, then Security, labeled two-factor authentication, two-step verification or multifactor authentication.

MethodHow it worksNotes
Passkey or security keyYour phone, computer or a small USB or NFC key confirms it is youThe strongest option against phishing, where available
Authenticator appAn app on your phone shows a new code every 30 secondsA strong, free option for most accounts
Text message or email codeA one-time code is sent to youMuch better than nothing; use an app or passkey where offered

When you turn on two-factor, most sites give you backup codes. Save them in your password manager or print them. They are how you get back in if you lose your phone.

Never share a one-time code

A common trick after a breach is a call or text from someone pretending to be your bank, carrier or a tech company, asking you to read back a code that was just sent to you. That code is the second factor. A real company will not ask you for it. Hang up and contact the company through its app or the number on your card. CISA's guide to recognizing phishing has more examples.

What this does not cover

Strong passwords and two-factor protect your online accounts. They do not protect information that was already exposed, like your Social Security number or date of birth. For that, the free tools are a credit freeze and fraud alert and regular checks of your credit reports. Our data breach checklist puts all of these steps together.