Money Tools & AdvisorsBeginner5 min read

Locking down your financial accounts

Password hygiene, two-factor traps, freeze-by-default credit, and the 90-minute security overhaul that makes you a hard target.

Your bank and brokerage accounts are only as safe as the weakest link protecting them — and for most people, that link is a reused password from 2014 that's already floating around in a data breach. The good news: financial account security is one of the highest-return afternoons in personal finance. About 90 minutes of setup makes you dramatically harder to rob than the average person, and criminals overwhelmingly prefer easy targets.

Passwords: the non-negotiables

  • Use a password manager (1Password, Bitwarden, or your platform's built-in manager). Humans cannot memorize 40 strong unique passwords; software can.
  • Every financial account gets a unique, generated password of 16+ characters. Unique is the keyword — reuse is how one breached shopping site becomes a drained brokerage account.
  • Your email password matters as much as your bank's, because email is where password resets go. Whoever controls your inbox can eventually control almost everything else.
  • Check whether your credentials are already breached at haveibeenpwned.com, and rotate anything that appears.

Two-factor authentication — and its weak flavor

Two-factor authentication (2FA) means logging in requires your password plus a second proof, usually a code. Turn it on for every financial account, no exceptions. But know the hierarchy: app-based codes (Google Authenticator, Authy) and hardware keys (YubiKey) are strong; text-message codes are the weakest form, because criminals can hijack your phone number through a 'SIM swap' — sweet-talking or bribing a carrier employee into porting your number to their device. Where an app option exists, choose it over SMS, and call your cell carrier to add a port-out PIN to your account.

Nobody legitimate will ever ask for your code
The most common account takeover today doesn't hack anything — it just calls you, pretends to be your bank's fraud department, and asks you to 'read back the verification code we just sent.' That code is the scammer logging into YOUR account in real time. Banks never call and ask for codes. Hang up and call the number on your card.

Freeze your credit — today, not someday

A credit freeze blocks anyone from opening new credit in your name, which neutralizes most identity theft. It's free at all three bureaus (Equifax, Experian, TransUnion), takes about ten minutes total online, and you can 'thaw' it in minutes whenever you legitimately apply for credit. There is essentially no downside for the years between credit applications. Freeze your kids' credit too — child identity theft often goes undetected for a decade.

What a takeover actually costs
Consider a real-world pattern: a scammer SIM-swaps a victim's phone number on a Friday evening, resets the email password via text code, then resets the brokerage password from the email. Over the weekend they wire out $47,000 in three transfers. The victim spends six months and roughly $2,500 in legal and notary fees fighting for reimbursement — and recovery isn't guaranteed, because wires the customer's credentials 'authorized' fall into a gray zone. The full prevention stack — password manager ($0–36/year), app-based 2FA (free), carrier PIN (free), credit freeze (free) — costs less than $40 a year.

The 90-minute overhaul

  1. Install a password manager and change passwords on your email, bank, brokerage, and retirement accounts first (15 min each tier).
  2. Enable app-based 2FA on email and every financial account; print or save the backup codes somewhere safe.
  3. Call your cell carrier and set a port-out PIN.
  4. Freeze your credit at all three bureaus and store the PINs in the password manager.
  5. Turn on account alerts: login notifications, transfers over $100, and new-payee alerts at every bank and brokerage.
  6. Set a calendar reminder to review authorized devices and linked apps annually, and remove anything you don't recognize.

Ongoing habits that keep you hard to rob

Security decays without maintenance. Keep your phone and computer updated (those updates patch the holes criminals use). Never log into financial accounts from links in emails or texts — type the address or use the official app. Treat any urgent, unexpected contact 'from your bank' as hostile until proven otherwise. And keep one family rule: no financial account changes requested by phone, text, or email get acted on without independently calling the institution back at its published number.

The 2FA hierarchy at a glance

MethodStrengthWeakness
Hardware key (YubiKey)Strongest — phishing-resistantCosts ~$25–50; can be lost (buy two)
Authenticator app codesStrongPhishable if you type the code into a fake site
Push approvalGoodApproval-fatigue attacks — never approve unprompted
SMS text codesWeakestSIM-swap and forwarding attacks
No 2FANonePassword breaches are routine; assume yours is out there
Second factors, strongest to weakest

If you only do three things

Perfection is optional; ordering isn't. If the full overhaul feels like too much this week, do exactly three things in this order. First, fix your email: unique password plus app-based 2FA, because email is the master key that resets everything else. Second, fix the account with the most money in it the same way. Third, freeze your credit at the three bureaus. Those three moves close the doors used in the overwhelming majority of real-world account takeovers — the rest of the checklist is valuable, but it's reinforcement, not foundation. Calendar the remainder for next month rather than letting the perfect defeat the adequate.

A closing note on recovery, because even hard targets get hit: know before an incident where your institutions' fraud lines are (saved in the password manager), report unauthorized transfers the day you spot them — reimbursement rights weaken with delay — and file at IdentityTheft.gov for an official recovery plan if identity theft is involved. Speed is the other half of security.

Households should also designate one shared, offline document listing account locations and emergency contacts — not passwords, just the map — so that a spouse or executor can act quickly if the account holder can't.

The bottom line

You can't make yourself unhackable, but you don't need to — you need to be expensive to rob. A password manager, app-based 2FA, a frozen credit file, a carrier PIN, and alert notifications will put you ahead of 95% of the population for about 90 minutes of work and almost no money. Do it this weekend; the criminals are already automated, and your defenses should be too.

Check your understanding

1 of 4
Someone calls claiming to be your bank's fraud department and asks you to 'read back the verification code we just texted you.' What's happening, per the article?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial