Security
Lock down your accounts in 20 minutes
Most hacks start with a reused password. This checklist closes the biggest gaps fast.
You don't need to be a security expert to be hard to hack. These steps block the vast majority of account takeovers we see.
1. Turn on two-step verification everywhere
Start with email (it resets every other account), then WhatsApp, then social media and banking.
- WhatsApp: Settings → Account → Two-step verification → Turn on. Choose a 6-digit PIN you don't use anywhere else.
- Google / Gmail: myaccount.google.com → Security → 2-Step Verification.
- Instagram / Facebook: Accounts Center → Password and security → Two-factor authentication.
Prefer an authenticator app over SMS codes where you can.
2. Stop reusing passwords
If one site leaks your password, attackers try it everywhere else. A password manager creates and remembers a unique password for every site. Bitwarden has a solid free plan.
3. Check your recovery options
Make sure your recovery email and phone number are current. Outdated recovery info is the main reason people can't get a hacked account back.
4. Review logged-in devices
Most apps list active sessions. Log out of anything you don't recognise.
- WhatsApp: Settings → Linked devices
- Google: Security → Your devices
5. Learn the three signs of phishing
- Urgency: "Your account will be closed in 24 hours"
- A login link you didn't ask for: go to the site directly instead
- Anyone asking for a code: no real company will ever ask you to read back a verification code
Account already compromised? Get in touch. Speed matters.