VOLUME 2 · CHAPTER 2 OF 8

Securing Your Financial Accounts

Why your email and phone number are the keys to every account, how passwords, passkeys and second factors rank, the bank and brokerage settings that stop money leaving, and what federal rules and deposit insurance cover when something gets through.

6 min readStrategies0 worked examplesupdated 2026-10-01

Most money stolen online is not taken by breaking encryption. It is taken by logging in as you: with a reused password, a code read out over the phone, or a phone number moved to a criminal's SIM card. That is good news, because the defences are ordinary settings anyone can switch on in an afternoon. This chapter ranks them by how much protection they add, explains which ones matter most for bank and brokerage accounts, and sets out what the law and deposit insurance do and do not cover if something gets through.

Your email and phone number are the master keys

Almost every financial account lets you reset its password through your email or a text to your phone. Whoever controls those two controls everything behind them. So protect them first, and more strongly than anything else.

  • Email. Give it a long, unique password and the strongest second factor it supports (more on this below). Review the recovery email and phone number it lists, and the devices that are signed in.
  • Phone number. In a SIM swap, a criminal persuades your carrier to move your number to their SIM, then receives your text codes. Every major carrier now offers a port-out PIN or a number lock that blocks transfers until you remove it. Turning it on takes a few minutes in the carrier's app or by phone.

If you only do two things after reading this chapter, secure these two.

Passwords, passkeys and a password manager

A password only protects you if it is unique. When one site is breached, criminals try the same email and password on banks, brokerages and shops, an attack called credential stuffing. Reuse is the weakness, not short length.

A password manager solves this by generating and storing a different long password for every site, so you remember only one strong passphrase. Reputable managers encrypt your vault so that the company itself cannot read it. The trade-off is concentration: the manager becomes a single point of failure, so its master passphrase must be long and unique and its own account protected with a strong second factor. Most security agencies, including the US Cybersecurity and Infrastructure Security Agency, recommend using one.

Passkeys go further. A passkey replaces the password with a cryptographic key stored on your phone or computer and unlocked with your fingerprint, face or device PIN. There is nothing to type, so there is nothing to phish: a fake site cannot receive a passkey meant for the real one. Where your bank or email provider offers passkeys, they are the strongest sign-in available to most people.

Second factors, ranked

A second factor means a stolen password alone is not enough. They are not equally strong:

  1. Security keys and passkeys (strongest). Physical keys and passkeys check the website's real address before they answer, so they resist phishing. Keep a backup key or a second registered device.
  2. Authenticator apps. The app shows a six-digit code that changes every 30 seconds. Much stronger than text messages, though a convincing fake site or caller can still trick you into reading a code out.
  3. Push approvals in a bank's own app. Convenient and usually good, as long as you never approve a request you did not start. Criminals sometimes send repeated prompts hoping you tap "approve" to make them stop.
  4. Text message codes (weakest). Vulnerable to SIM swapping and to callers who ask you to "confirm" the code. Still far better than nothing, and sometimes the only option a bank offers.

One rule covers all of them: no real bank, broker or agency will ever ask you to read them a code. A code is for typing into a site you opened yourself.

Settings that stop money leaving your accounts

Logging in is only half of a theft; the money still has to move. Banks and brokerages offer controls that put friction exactly there, and most people never switch them on.

  • Alerts on every transaction, login, new payee and change of contact details. You learn of a problem in minutes instead of at month end, and reporting speed matters for your liability, as the last section explains.
  • Limits and holds on outgoing transfers. Many banks let you lower daily transfer limits, require extra checks for new payees, or block wires entirely.
  • A trusted contact on brokerage accounts. Firms can contact this person if they suspect fraud or are worried about your wellbeing. The trusted contact cannot trade or move money.
  • Account locks. Some brokerages and the Social Security Administration offer extra verification or a lock on online changes. If you have not yet created your own online accounts with Social Security and the IRS, consider doing so, because an account a criminal opens in your name is harder to undo.
  • Bookmarks. Reach your bank by a saved bookmark or its official app, not a search result or a link in a message. Fake ads for bank sites do appear above real results.

Devices and networks: what actually matters

Much security advice is either too weak or more than most people need. A dedicated banking computer or a VPN for every login adds little for a typical household compared with the basics below, which close the paths that thefts actually use.

  • Keep everything updated. Turn on automatic updates for your phone, computer and browser. Most malware relies on holes that updates have already closed.
  • Install apps only from official stores, and only your bank's own app. Be wary of any request to install screen-sharing or "remote support" software; legitimate banks do not need to see your screen.
  • Lock your devices with a PIN or biometric, and turn on the feature that lets you locate and erase a lost phone.
  • Public Wi-Fi is less dangerous than it was, because banking sites and apps encrypt their traffic. The remaining risk is fake networks and fake login pages, so on shared networks prefer your phone's mobile data for anything financial.
  • Check before you click. Phishing messages copy a bank's logo and tone, then send you to a lookalike site. Chapter 5 covers how to recognise them.

What protects your money if something gets through

Knowing the rules tells you why speed matters and which losses you can recover.

  • Debit cards and bank transfers. Federal Regulation E limits what you can lose to unauthorized electronic transfers. If a card or PIN is lost or stolen and you report it within two business days of noticing, your loss is capped at $50. After that, it can reach $500. If you do not report unauthorized transfers within 60 days after the statement showing them is sent, you can be liable for later transfers without limit. Check accounts often and report quickly.
  • Credit cards. Under Regulation Z your liability for unauthorized use is capped at $50, and most issuers waive even that. This is one reason many people use a credit card rather than a debit card for online shopping.
  • Payments you authorized. If a scammer talks you into sending money yourself, the bank usually treats the payment as authorized, and these protections may not apply. That gap is why chapter 5 exists.
  • Bank failure. FDIC insurance covers up to $250,000 per depositor, per insured bank, per ownership category, if the bank fails. It does not cover fraud losses, and money held through a non-bank app is covered only if the app actually places it at an insured bank and keeps accurate records.
  • Broker failure. SIPC protects up to $500,000 per customer, of which up to $250,000 can be cash, if a member brokerage fails and customer assets are missing. It does not cover market losses or bad investment advice.
YOUR NEXT STEPSDo this now
  1. Turn on a port-out PIN or number lock with your mobile carrier.
  2. Give your main email account a unique passphrase and the strongest second factor it offers, ideally a passkey or security key.
  3. Install a password manager and change the passwords on your bank, brokerage and email first, then work outward.
  4. In each bank and brokerage app, switch on alerts for transactions, logins, new payees and contact changes, and add a trusted contact at your brokerage.
  5. Write down where your accounts are held and their fraud phone numbers, and keep the list somewhere safe offline.

This chapter describes common security practices and federal consumer protections in general terms. It is not personal financial advice, and your bank's own terms and your state's laws may give you more or different protection.

KEY TERMS
Phishing
SOURCES
Saved in this browser. Sign in to keep it on every device.