Learning as a guest. Your progress lasts until you close this tab. Save it free
Lock Down Your Accounts: Passkeys, Two-Step Login and After a Breach
- Warm-up
- Story
- Learn
- Play
- Quiz
- Remember
- Try it
- Finish
About this lesson
About 15 minutes · 5 quiz questions
The big idea: Most account takeovers start with a reused or stolen password. A password manager, passkeys and two-step login stop most of them.
Lesson outline
The big idea: Most account takeovers start with a reused or stolen password. A password manager, passkeys and two-step login stop most of them.
The story: One password, three accounts
Marcus learns that a leaked shopping-site password puts Marcus’s email and bank at risk, and a friend, Lee, shows how a passkey works.
- Narrator: Marcus uses the same password for email, the bank and a shopping site.
- Narrator: The shopping site is breached. Thieves take the leaked password and try it everywhere else.
- Lee: That’s why I use a password manager. Every account gets its own password, and I only remember one.
- Narrator: Two-step login adds a second check, like a code from an app. A passkey uses your phone’s lock instead of a password.
- Marcus: Where do I even start?
- Lee: Your email and your phone account. They can reset everything else.
- Narrator: Unique passwords, two-step login and passkeys stop most account takeovers.
What you’ll learn
One password per account
Thieves take passwords leaked from one site and try them on others. A different password for every account stops that. A password manager creates and remembers them, so you only need to remember one strong main password.
Two-step login
Two-step login, or 2FA, asks for a second proof after your password. An authenticator app or a security key is stronger than a text code, because a thief can steal texts with a SIM swap. Turn it on everywhere money lives.
Passkeys, and your email first
A passkey replaces a password with your device’s lock: your face, fingerprint or PIN. It can’t be phished. Lock down your email and phone account first, since they can reset everything else. Ask your phone carrier for an account PIN.
After a breach notice
Change that password, change it anywhere you reused it, turn on two-step login, freeze your credit and watch your statements. Set up emergency access in your password manager for someone you trust.
Key words
- two-step login
- a second proof after your password, like a code from an app
- Also called: two-factor authentication (2FA)
- passkey
- a sign-in that uses your device’s lock instead of a password
- password manager
- an app that creates and remembers a different password for every account
- data breach
- when a company’s customer information is stolen or leaked
Common questions
- What is a SIM swap?
- A thief talks your phone carrier into moving your number to their phone, so your text codes go to them. A carrier PIN helps stop it.
- What if I lose my phone with my passkeys?
- Most passkeys sync to your other devices or your account backup. Keep backup codes somewhere safe when you set up two-step login.
Remember this
Unique passwords, two-step login, passkeys when offered, email first.
Try it: Lock down two accounts today
- Turn on a passkey or two-step login for your email.
- Ask your phone carrier to add an account PIN.
- Add “account security check” to your yearly money check-up list.
No account needed: these steps work on your own email and phone accounts.
Live facts
Numbers that change over time, with when they were last checked and where they come from.
What to do after a data breach
Source: IdentityTheft.gov(opens in a new tab)Two-step login (multifactor authentication)
Source: CISA(opens in a new tab)Simple steps to stay safe online
Source: CISA(opens in a new tab)
Lessons teach how money works. They are not financial advice.