Home » How to » How to Secure Every Account You Own in One Afternoon

How to Secure Every Account You Own in One Afternoon

A phone, laptop and handwritten security checklist on a kitchen table in afternoon light.

Almost every account you own trusts two things to prove it is you: your phone number and your email inbox. Lock those down first and the rest of this job gets easy. This is how to secure online accounts in 2026, in one afternoon, in the order that actually stops a takeover.

The short version

Fraud losses reported to the FTC reached $15.9 billion in 2025, and a third of people in a recent survey said they received a breach notice in the past year. This article walks through a four-hour process to lock down your accounts in the order that best stops a takeover, starting with your phone number and email because those two control everything else.

  1. Lock your phone number first by turning on your carrier’s free SIM and port-out lock, because if someone moves your number to their device they can receive your login codes and reset your accounts without you knowing.
  2. Add a passkey to your main email account, since a passkey uses your phone’s face scan or fingerprint instead of a typed password, meaning a fake login page cannot steal it.
  3. Run your password manager’s built-in checkup and fix compromised passwords before reused ones, because a compromised password is already on a stolen list and puts any account using it at immediate risk.
  4. Freeze your credit for free at all three bureaus, Equifax, Experian, and TransUnion, because a freeze stops someone from opening new accounts in your name even if they already have your personal information.
  5. The article warns that tighter security makes lockouts more likely, so you must print your backup codes and store them somewhere physical like with your passport, because without a backup the person most likely to be locked out is you.

Summary drafted with AI and checked by the editor.

Americans reported $15.9 billion in fraud losses to the FTC in 2025, across 3 million reports. That is up from just over $12 billion the year before, according to the agency’s congressional testimony on March 25, 2026. And in a FIDO Alliance survey of 11,000 people in 10 countries published May 7, 2026, a third said they had received a breach or compromise notice in the past year.

You need about four hours, your phone, a laptop, and a pen and paper. Paper matters. You will be writing down backup codes, and those should not live only on the device you are protecting.

How to secure online accounts in 2026: the order matters

Good habits help. The order you do them in matters more.

Think of your accounts as a chain. Your phone number receives the texted codes. Your email receives every “reset your password” link. Your password manager holds the keys to everything else. If someone takes your number, they can often reset your email. If they take your email, they can reset your bank.

So you work from the top of the chain down:

  1. Your phone number (30 minutes)
  2. Your main email account (45 minutes)
  3. Your password manager (45 minutes)
  4. Your money: bank, cards, payment apps, credit files (60 minutes)
  5. Everything else, most important first (60 minutes)

Securing your bank while your email still uses a reused password is putting a deadbolt on the front door and leaving the back door open.

Before you start, make a quick list of accounts. Search your inbox for “welcome to” and “verify your email.” You will find accounts you forgot you had. Write down the ones that touch money, health, work or your contacts.

Step 1: Lock your phone number so nobody can move it

A SIM swap is when someone convinces your carrier to move your number to a SIM card they control. A port-out is the same trick, done by moving your number to a different carrier. Either way, your texted login codes start going to them.

All three major US carriers now offer free locks. Turn yours on today.

  • Verizon: Two separate locks. SIM Protection blocks SIM changes, and Number Lock blocks moving your number to another carrier. In the My Verizon app, go to Account, then Edit Profile and Settings, then the Security menu.
  • AT&T: Wireless Account Lock, free and available to all customers since July 1, 2025. It blocks SIM and eSIM swaps, number transfers, new lines and billing changes. In the AT&T app, tap the person icon, then Wireless account lock.
  • T-Mobile: In the T-Life app, turn on two features: SIM Protection, which blocks SIM changes, and Account Takeover Protection, which blocks moving your number to another carrier.

On a smaller or prepaid carrier, call and ask for an account PIN or port-out PIN. CISA’s December 2024 mobile guidance recommends a carrier PIN for exactly this reason.

The downside: a lock you set is a lock you have to remember to lift. When you upgrade your phone or switch to eSIM, you will need to turn it off first. Verizon, for example, makes you wait 15 minutes after you disable SIM Protection before the change can go through. Plan your next upgrade around it.

Insights by TechCity, every Sunday.

Tech explained for people who use it.

Step 2: Make your email the hardest account you own

Your main inbox is the master key. Give it 45 minutes.

Add a passkey. A passkey replaces your password with your phone’s face scan, fingerprint or screen lock. Nothing gets typed, so there is nothing to steal on a fake login page. Google has made passkeys the default for personal accounts since October 2023, and you can add one under Security in your Google Account. Microsoft accounts, which cover Outlook and Hotmail, support passkeys as well. Here is how passkeys actually work if you want the detail.

Print your backup codes. Google and most email providers give you a set of one-time codes for when your phone is lost. Print them or write them down. Keep them with your passport or birth certificate, not in your phone’s notes app.

Check your recovery email and phone. This is the hole most people miss. If your recovery email is an old college or work address you no longer control, whoever gets that address can get into your main inbox. Update it to an account you check.

Check for forwarding rules. When attackers get into an inbox, they often set up a quiet rule that copies your mail to them, then leave. You would never notice. In Gmail on a computer, open Settings, then See all settings, and check two tabs: “Forwarding and POP/IMAP” and “Filters and Blocked Addresses.” In Outlook, open Settings, then Mail, and check both Forwarding and Rules. Delete anything you did not set up.

Sign out devices you don’t recognize. Both Google and Apple show every phone, tablet and computer signed into your account. If you see a device you sold two years ago, remove it.

Then consider removing text messages as a backup. Once you have a passkey and printed backup codes, turning off SMS as a sign-in option closes the gap your phone lock just narrowed. CISA’s guidance is blunt about it: text codes are not encrypted and are not phishing-resistant. If that feels like too much today, leave it on. A strong email with SMS as a fallback is still far better than where you started.

Step 3: Put every password in one vault, then fix the worst ones

You cannot remember 100 unique passwords. Nobody can. A password manager remembers them for you, fills them in, and warns you when one shows up in a breach.

The one already on your phone is a fine choice. iPhone users have the Passwords app. Android and Chrome users have Google Password Manager. If you want one that works the same across iPhone, Android and Windows, a standalone manager like Bitwarden, 1Password or Proton Pass does that. If you are still deciding whether to trust one, here is how password managers keep you safe.

One change to know about: Microsoft Authenticator stopped storing and filling passwords on August 1, 2025. Passwords saved there were kept in your Microsoft account and can be found in the Edge browser. Move them into whichever manager you are using now.

Next, run the checkup. The Passwords app has a Security section, and Google Password Manager has Password Checkup. Both sort your logins into compromised, reused and weak. Fix them in that order:

  1. Compromised first. These are already in a stolen list somewhere. Change them now, starting with anything tied to money.
  2. Reused second. One leaked site can open every other site that shares that password.
  3. Weak last. Let the manager generate a new one as you log in to each site over the next few weeks.

For the one password you do have to remember, the manager’s own, length beats complexity. NIST’s updated digital identity rules, finalized in August 2025, set 15 characters as the minimum when a password is the only thing protecting an account. They also tell services to stop forcing symbol rules and scheduled password changes. Four or five random words strung together is long, easy to type and hard to guess. Change it when it leaks, not on a calendar.

Want to know what has already leaked? Put each of your email addresses into Have I Been Pwned, a free breach lookup. It tells you which breaches each address appeared in, so you know which accounts to change first.

Step 4: Protect your money, including accounts you haven’t opened yet

Give this an hour. Go through your bank, credit cards, payment apps like PayPal, Venmo and Cash App, any brokerage or retirement account, and Amazon or wherever your card is saved.

For each one, use the strongest sign-in it offers, in this order:

  1. A passkey, if the site offers one
  2. An authenticator app, which generates a six-digit code that changes every 30 seconds
  3. Text message codes, only if nothing better exists

Then turn on transaction alerts. Set them as low as the app allows, ideally every purchase. An alert costs nothing and tells you within seconds when something is wrong, instead of when the statement shows up.

Freeze your credit at all three bureaus. A password protects accounts you have. A credit freeze protects accounts someone might try to open in your name. It is free, it stays on until you lift it, and you need to do it separately at Equifax, Experian and TransUnion. Budget about 10 minutes for each. When you apply for a loan or a new card, you lift the freeze for a few days and put it back. The FTC’s credit freeze guide walks through each bureau.

Step 5: Everything else, in order of damage

You have an hour left. Spend it on accounts in order of how much harm they could do in the wrong hands.

Social and messaging accounts come first. A hijacked Facebook, Instagram or WhatsApp account is how scammers message your friends asking for money in your name. Turn on two-step verification on each. On WhatsApp, open Settings, then Account, then Two-step verification, and set a six-digit PIN so nobody can register your number on a new phone.

Check what you signed into with Google or Apple. Those “Sign in with Google” and “Sign in with Apple” buttons create connections that outlive your interest in the app. In your Google Account, look under Security for your connections to third-party apps. On iPhone, look under Sign-In and Security in your Apple Account settings. Remove anything you do not use.

Delete what you don’t need. That fitness app from 2019 and the store you bought one thing from both still have your email, maybe your address and your card. Every old account is one more breach waiting to include you. If you will not use it again, close it.

Everything else (streaming, shopping, utilities, games) just needs a unique password from your manager. You can do these as you log in over the next month.

What this costs you, honestly

Stronger security has a price, and it is mostly convenience.

Lockout becomes the bigger risk. The tighter you lock an account, the more a lost or broken phone hurts. That is why backup codes go on paper and why a second passkey device or a hardware security key is worth adding to your email. Without a backup, the person most likely to be locked out of your account is you.

Passkeys tie you to where they are saved. A passkey made in Apple’s Passwords app syncs across Apple devices. One made in Google Password Manager follows your Google account. If you switch from iPhone to Android, check that your passkeys came with you before you wipe the old phone.

Your account is only as strong as its weakest sign-in option. Many sites quietly leave text codes or a security question switched on after you add a passkey. Look for those and turn them off where you can.

Authenticator apps can still be phished. CISA rates them better than text messages but below passkeys and hardware keys, because a convincing fake login page can still trick you into typing the code. Use them where passkeys aren’t offered, and never type a code into a page you reached from a text or email link. It also helps to know how to spot a phishing email before you tap anything.

Is it still worth it? Yes. Our pick: passkeys on your email and money accounts, an authenticator app wherever passkeys are not offered, and text codes only as a last resort.

Do this for someone else, too

If you are the person your family calls about technology, block out a second afternoon and do this together. One person reads the steps, the other taps through on their own phone, so they know where every setting lives. For the conversation itself, here is how to teach parents internet safety without talking down to them.

Two settings matter most for families. Apple lets you name an Account Recovery Contact who can help you get back in if you are locked out. You will find it in Settings, then your name, then Sign-In & Security, then Recovery Contacts. Apple also lets you name a Legacy Contact who can access your data after you die. Google’s Inactive Account Manager decides what happens to your account if you stop using it. Five minutes on each now spares your family a much harder job later.

If you only have 30 minutes today

Do two things. Turn on your carrier’s SIM and port-out lock, then add a passkey to your main email and print the backup codes. That covers the top of the chain.

Then put a 15-minute check on your calendar every three months: run your password manager’s checkup, look at the devices signed into your email, and check for forwarding rules you did not make. When you want to go further, our complete online security checklist covers backups and device encryption too. Security never really finishes. After today, though, keeping it is the easy part.

Share

WhatsApp X LinkedIn Email

Insights by TechCity, every Sunday.

Tech explained for people who use it.

Olawale Adeyina Avatar