Account atelier
Verify the destination before entering credentials
Lookalike domains, sponsored search results and direct-message links can imitate a login page. Use a previously verified record of the domain and inspect the full address, not only the padlock or page design. Password managers can help by refusing to autofill on a mismatched domain.
- ACheck the full domain
- BDistrust direct messages
- CUse domain-bound autofill
Account atelier
Use a unique password and strong second factor
A reused password allows a breach elsewhere to become an account takeover. Prefer an authenticator or hardware-backed factor where available and store recovery codes offline. SMS is better than no second factor but can be exposed to SIM-swap attacks, so secure the mobile account as well.
- AUnique password
- BStrong MFA
- CProtect recovery codes
Account atelier
Respond quickly to an unfamiliar session
Change the password from a trusted device, revoke other sessions, review profile and payment changes and preserve alert emails with timestamps. Contact any affected financial provider separately. Do not grant remote access to someone claiming they can recover the account, and do not pay a recovery fee to a social-media contact.
- ARevoke sessions
- BReview changed details
- CReject paid recovery strangers