DefenseLock the Front Door
The playbook

Lock the Front Door

Harden the basics so account takeover and identity theft cannot get a foothold.

This move is free.No product needed — see Tools only if a paid option genuinely helps.

Most defenses are about the moment a scammer comes at you. This one is the standing baseline that makes you a hard target before anyone knocks. Three locks — multi-factor authentication, a password manager, and a locked-down phone number — take an afternoon to set up and quietly protect everything you own online from account takeover and identity theft.

Lock the doors before anyone knocks

You can't predict which scam will reach you, but you can make sure that when one does, it hits locked doors. The basics below don't depend on you spotting anything in the moment — they work in the background, every day, for every account. That's what makes them the highest-value security you'll ever set up.

Think of it as hardening the foundations: even if a password leaks in a breach, even if you click one bad link on a bad day, these locks are what stop a single mistake from becoming a stolen identity or a drained account.

Turn on MFA — and not the weak kind

Multi-factor authentication (MFA, or 2-factor) adds a second proof beyond your password. CISA's finding is striking: "users who enable MFA are significantly less likely to get hacked," because "even if a malicious cyber actor compromises one factor like your password, they will be unable to meet the second authentication requirement." Turn it on everywhere that matters — email first, since email resets everything else.

Not all MFA is equal, though. Codes texted to your phone can be stolen in a SIM swap, so for your highest-value accounts the FBI recommends "strong multi-factor authentication methods such as biometrics, physical security tokens, or standalone authentication applications." An authenticator app or a hardware key beats an SMS code — use those for your email, bank, and crypto.

Use a password manager

The quiet danger is reuse: when one site is breached, criminals try that same email-and-password pair everywhere else. A password manager kills that by giving every account its own long, random password — so one breach stays contained to one account. CISA notes that with a manager "we only need to remember one strong password — the one for the password manager itself."

It generates, stores, and fills your passwords, which means strong and unique stops being a chore. Protect the manager itself with a strong master password and its own MFA, and you've turned your weakest layer — human-chosen passwords — into one of your strongest.

Lock your phone number

Your mobile number is a master key: it's the recovery route and the 2FA channel for much of your life, which is why criminals hijack it. In a SIM swap, they trick or bribe a carrier into moving your number to their device, then catch your reset links and codes. The FBI logged over $68 million in SIM-swap losses in a single year.

Two moves shut this down. Add a carrier-level PIN or port-freeze to your mobile account so your number can't be moved without it — and move your important accounts off SMS codes onto an app or key. And starve the attack of fuel: the FBI advises against advertising financial assets and to "avoid posting personal information online, such as mobile phone number, address, or other personal identifying information."

Set it up today
  1. Turn on MFA everywhere that matters, starting with your email — it’s the account that can reset all the others.
  2. For email, bank, and crypto, use an authenticator app or a hardware key instead of SMS text codes.
  3. Set up a password manager and let it create a unique, strong password for every account; protect it with a strong master password and MFA.
  4. Add a PIN or port-freeze to your mobile account so your phone number can’t be SIM-swapped to another device.
  5. Stop broadcasting the raw material: keep your phone number, address, and financial details off public profiles and posts.

Frequently asked

Isn’t text-message (SMS) 2FA good enough?

Any MFA is far better than none, so if SMS is all an account offers, use it. But it's the weakest kind: a SIM swap can redirect your texts to a criminal's phone, handing them your codes. For your highest-value accounts — email, bank, crypto — the FBI recommends stronger methods like authenticator apps, hardware security tokens, or biometrics. Use those where the stakes are high.

Is putting all my passwords in one manager safe — isn’t that one basket?

It's much safer than the alternative, which is reusing a handful of passwords everywhere. Reuse is what actually gets people hacked: one breach unlocks the rest. A password manager removes that risk by making every password unique, and CISA recommends them precisely for this. Protect the manager with a strong master password and its own MFA, and the single basket becomes a very well-guarded one.

Why bother locking my phone number specifically?

Because your number is a master recovery key. Many accounts let you reset a password or receive a 2FA code by text, so whoever controls your number can cascade into everything else — that's the whole point of a SIM swap. A carrier PIN or port-freeze blocks the number from being moved, and shifting important accounts off SMS removes the prize even if a swap is attempted.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every move is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›