When a scammer gets into your email account, they can reset every other account you own. When they get into your bank account, the damage is immediate. Most account takeovers are preventable โ€” and most happen because of a handful of very common mistakes.

Mistake 1: Using the same password on multiple sites

When any website gets hacked โ€” and thousands do every year โ€” your email and password combination gets sold on the dark web. Scammers then try that exact combination on Gmail, your bank, Amazon, and social media. If it works anywhere, they're in.

Fix: Use a different password for every account. A password manager (Bitwarden is free, LastPass and 1Password are paid) remembers them all for you. You only need to remember one master password.

Mistake 2: Passwords that are easy to guess

Names, birthdays, pet names, "password123," and common words are tested first by automated hacking tools. A strong password is long (12+ characters) and random โ€” not a word or phrase you'd find in a dictionary.

Fix: Use your password manager to generate random passwords. If you don't have one, a long passphrase of four random words ("correct-horse-battery-staple") is much stronger than a short complex one.

Mistake 3: Not using two-factor authentication

Two-factor authentication (2FA) means that even if someone has your password, they still can't log in without a second code sent to your phone. It stops the vast majority of account takeovers.

Fix: Enable 2FA on your email, bank, and social media accounts. Most accounts have this under Settings โ†’ Security. Text message 2FA is good; an authenticator app (Google Authenticator, Authy) is better.

Mistake 4: Entering your password on a fake site

Phishing emails link to pages that look exactly like your bank or Gmail login. You type your password, and it goes straight to a scammer. The URL is the giveaway โ€” it's never the real site's address.

Fix: Always type bank and email addresses directly into your browser rather than clicking links. Check the URL before entering any password. A password manager also helps โ€” it will only autofill on the real site, not a fake one.

Mistake 5: Never checking if you've been hacked

Free tool

Go to haveibeenpwned.com and enter your email address. It tells you immediately if your email and password appeared in any known data breach. If it has โ€” change your password on every site that uses it.

Got a message that looks like this?

Paste it into ProtectMyCircle and get an instant plain-English verdict โ€” free, no account needed.

Check it now โ€” free