Enhanced online security measures shift focus from passwords to multi-factor authentication

As fraudsters target online accounts more aggressively, experts stress the importance of password uniqueness and multi-factor authentication to prevent breaches and protect personal data.

Online accounts have become a prime target for fraudsters and intruders as people rely on them for messaging, work, shopping and banking. The basic defences are well known, but security experts say they only work if users apply them consistently and treat account hygiene as a routine habit rather than a one-off task.

The first step is to stop reusing passwords. The US Federal Trade Commission says each account should have its own long, hard-to-guess password, ideally built from a mix of letters, numbers and symbols. Microsoft and Dell both recommend the same approach and warn against using personal details such as dates of birth or other information that can be guessed or found online. Password managers can also help people keep track of unique logins without resorting to weak combinations.

A second layer of protection is two-factor, or two-step, authentication, which requires something in addition to a password before access is granted. Microsoft says that can be a code sent to a phone or email address, while the University of Strathclyde advises enabling multi-factor authentication on important accounts such as email and online banking. Security specialists say this extra step can block many attacks even when a password has been stolen.

Users are also being urged to watch for phishing messages, which often imitate banks, companies or online platforms and try to rush people into handing over credentials. The warning signs include suspicious links, urgent language and requests for verification codes, which should never be shared with anyone, even if they claim to represent a legitimate organisation. It is also sensible to avoid saving passwords on public or untrusted devices, to check which devices are logged into an account and to sign out of sessions that are unfamiliar.

If there are signs of a breach, such as a login from an unknown device, messages sent without permission or changes to account details, the password should be changed immediately from a trusted device. Users should then sign out of all other sessions, review recovery options and turn on two-factor authentication if it is not already active. The FTC says that if a password may have been compromised, it should be replaced without delay, while anyone dealing with linked financial accounts should contact the relevant provider at once and review recent transactions for anything unusual.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.