Technology

Locking Down Your Accounts Before a Breach Happens

Locking Down Your Accounts Before a Breach Happens

Photo credit: TrendingExperts.net

Use this checklist to audit your online accounts, spot weak points in your login security, and take action before a hacker does it for you.

Key Takeaways

  • Weak or reused passwords are the single most common entry point for account takeovers.
  • Two-factor authentication significantly reduces the risk of unauthorized access, even if your password leaks.
  • Reviewing active sessions and connected apps regularly closes doors you may have forgotten about.
  • A breach check service can tell you if your credentials have already appeared in a data leak.
  • Recovery options like backup emails and phone numbers are often overlooked but critically important.

Why Audit Your Accounts Before Something Goes Wrong

Most people only think about account security after something bad happens — a suspicious login alert, an inbox full of password-reset emails they didn't request, or worse. By that point, the damage is already underway. A proactive audit takes less than an hour and can close the gaps that attackers commonly exploit.

This checklist walks you through the key areas to review: your passwords, your login protections, your recovery settings, and the third-party apps that have access to your accounts. Work through it top to bottom, or tackle one group at a time. Either way, you'll finish with a clearer picture of where you actually stand — and what to fix first.

For a broader framework of online safety habits, see our comprehensive online safety guide.

Required

Breach check service (e.g., haveibeenpwned.com)

Checks whether your email address or passwords have appeared in publicly known data breaches.

Required

Authenticator app (e.g., any TOTP-compatible app)

Generates time-based one-time codes for two-factor authentication, more secure than SMS-based codes.

Optional

Password manager

Stores and generates unique, strong passwords for every account so you don't have to memorize them.

Required

Account activity/session pages

Built into most major platforms (Google, Apple, Meta, Microsoft) to review recent logins and active devices.

The Account Security Checklist

Work through each group below, checking off items as you go. Items marked must are the highest priority — address these before anything else. Should items provide strong additional protection and are worth completing in the same session. Nice-to-have items are optional enhancements that add meaningful layers for security-conscious users.

Passwords

Check each important account for a unique password — no two accounts should share the same one. Use a password reuse guide to understand the risks if this is new territory. Must
Replace any password shorter than 12 characters or made up of common words and number substitutions (e.g., "P@ssword1"). Must
Run your email address through a reputable breach-checking service (such as haveibeenpwned.com) to see if your credentials have appeared in a known data leak. Must
Consider using a password manager to generate and store strong, unique passwords. Review the trade-offs of password managers before committing to one. Should

Two-Factor Authentication (2FA)

Enable two-factor authentication on your primary email account — this is your digital master key and deserves the strongest protection available. Must
Enable 2FA on financial accounts including banking, investment apps, and payment platforms. Must
Enable 2FA on social media accounts, especially those linked to other apps or used for "Sign in with" logins. Should
Where possible, use an authenticator app (which generates time-based codes) rather than SMS text codes, which are more vulnerable to SIM-swapping attacks. See how 2FA and 2SV differ for context. Should
Save any one-time backup codes provided by 2FA setup in a secure, offline location such as a printed sheet stored safely at home. Nice to have

Recovery Settings

Verify that the backup email address on each account is current and one you still actively control. Must
Confirm that the recovery phone number on file is your current number, not an old one you no longer own. Must
Review security questions where they still exist and replace obvious or guessable answers with nonsense phrases that only you would know. Should

Active Sessions and Connected Apps

Log into each major account and review the list of active sessions — sign out of any device or location you don't recognize or no longer use. Must
Find the list of third-party apps connected to your Google, Apple, Facebook, or Microsoft account and revoke access for any you no longer use or don't recognize. Should
Review which apps can read your email (often listed under account permissions) and remove any you no longer actively use. Should
Check for any "sign in with" authorizations on accounts you haven't used in over a year and consider whether those accounts should simply be deleted. Nice to have

Network and Device Hygiene

Avoid logging into sensitive accounts on public Wi-Fi without a VPN — review the risks of public networks before connecting in coffee shops or airports. Should
Ensure your home router firmware is up to date and that you've changed the default admin password. Our home network security guide covers the full setup. Nice to have

Your Email Account Is the Master Key

If an attacker gains access to your primary email address, they can reset the password to nearly every other account you own. This makes your email account the single highest-priority account to secure — give it a unique, strong password and enable two-factor authentication before anything else. If you use the same password for email as you do for other sites, change it right now.

What to Do If You Find a Problem

If your audit turns up a compromised credential, act quickly but calmly. Change the password on the affected account first, then change it on any other account where you used the same or similar password. Enable two-factor authentication immediately if it isn't already on. Check your account's recent activity log for sign-ins you don't recognize and revoke any active sessions you can't account for.

If a financial account is involved — banking, credit card, or payment apps — contact the provider directly through its official website or app. Don't click links in any emails you receive around the same time, as phishing attempts often follow shortly after a public data breach.

Reusing passwords across accounts is how a single breach at one site turns into a cascade of compromised accounts elsewhere — a technique called credential stuffing. If your audit reveals you've been reusing passwords, prioritizing unique passwords for your email, banking, and primary social accounts first will address the highest-risk exposure.

Phishing Emails Often Arrive After a Breach

When a major data breach makes the news, attackers send phishing emails pretending to be the affected company. These emails urge you to "verify your account" or "reset your password" via a link — which leads to a fake site designed to steal your new credentials. Always navigate directly to the service's website by typing the URL yourself rather than clicking links in emails during or after a breach event.

Technology Editorial Team

Author

Technology Editorial Team

Technology Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.