Protecting Your Money Online: Passwords, Passkeys and Two-Factor Sign-In
How to secure bank and money accounts: strong unique passwords, password managers, passkeys, two-factor sign-in, recovery codes and spotting phishing attempts.
Your financial accounts are only as safe as the way you sign in to them. Most account takeovers don’t involve sophisticated hacking. They involve a reused password from a breached website, a convincing fake sign-in page, or a text message code read out to a scammer on the phone.
The good news is that a few changes make you much harder to target. This guide explains passwords, password managers, passkeys and two-factor sign-in in plain terms, and gives you an order of work to secure your money accounts in an afternoon.
Start with your email account
Before your bank, secure your email. Almost every account you own can be reset through your email, so whoever controls your inbox can often take over everything else.
Give your email account the strongest protection you can: a unique password, a passkey if it’s offered, and two-factor sign-in. Then do the same for your phone carrier account, since it’s often used to receive security codes.
Passwords: unique matters more than clever
The biggest password risk isn’t a weak password. It’s the same password used in more than one place. When any website is breached, attackers try those email and password pairs on banks, email providers and shopping sites. This is called credential stuffing, and it works because people reuse passwords.
A good password is:
- Unique: used for one account only.
- Long: length beats complexity. A phrase of four or five random words is both strong and memorable.
- Not personal: no names, birthdays, pets or addresses.
Nobody can remember a unique long password for dozens of accounts. That’s what a password manager is for.
Use a password manager
A password manager stores your passwords in an encrypted vault, generates strong unique ones, and fills them in for you. You remember one strong master password, and the manager remembers the rest.
Options include managers built into your phone or browser and standalone apps. Choose one that works on all your devices, and protect it with a strong master password and two-factor sign-in.
A useful side benefit: a password manager only fills in a password on the real website it was saved for. If it doesn’t offer to fill on a sign-in page, that’s a warning sign you might be on a fake site.
Getting started: you don’t need to change everything at once. Begin with email, banks, credit cards, budgeting apps and retirement accounts. Change the rest as you use them.
Passkeys: the stronger replacement
A passkey is a newer way to sign in that replaces the password altogether. Instead of typing something, you confirm it’s you with your device: a fingerprint, a face scan, or your phone’s PIN.
Behind the scenes, your device holds a private key that never leaves it, and the website holds only a matching public key. That brings real advantages:
- Phishing-resistant. A passkey is tied to the real website. A fake site can’t use it, even if you’re fooled.
- Nothing to steal from the website. A breach of the site doesn’t reveal anything an attacker can sign in with.
- Nothing to reuse or forget.
Passkeys are usually synced across your devices through your phone or computer’s account, or stored in a password manager. Where a bank or app offers passkeys, they’re generally the best choice.
Two-factor sign-in
Two-factor sign-in (also called two-factor authentication, or 2FA) means you need something beyond your password to get in: usually a code or an approval on your phone. Even if someone has your password, they can’t sign in without the second factor.
Not all second factors are equally strong. From strongest to weakest:
- Passkeys or security keys: resistant to phishing.
- Authenticator apps: an app generates a six-digit code that changes every 30 seconds. Good protection, and not tied to your phone number.
- Text message codes: better than nothing, but vulnerable to SIM-swap fraud, where a scammer convinces your carrier to move your number to their phone.
Use the strongest option each account offers. Turn on two-factor sign-in for every financial account where it isn’t already on.
Save your recovery codes
When you set up two-factor sign-in, most services give you a set of one-time recovery codes. These let you in if you lose your phone. Store them somewhere safe and separate from your phone, such as your password manager or a printed copy in a secure place at home. Without them, a lost phone can lock you out for days.
Recognise phishing and scam calls
Even strong sign-in can be undone by handing the keys over. Common warning signs:
- Urgency: “Your account will be closed in 24 hours.”
- Requests for codes: your bank will not call or text to ask you for a sign-in code or one-time passcode. Anyone who asks is almost certainly a scammer.
- Links in messages: sign-in links in texts and emails that look slightly off.
- Requests to move money “to keep it safe”: a classic scam.
When in doubt, hang up or close the message, and contact your bank using the number on the back of your card or by typing its address yourself.
Review your signed-in devices
Most banks and apps show which devices are signed in. Check periodically and sign out any you don’t recognise or no longer use, such as an old phone or a shared computer.
An afternoon’s security plan
Example. Priya spends one Saturday afternoon on this:
- Sets up a password manager on her phone and laptop (20 minutes).
- Secures her email with a passkey and authenticator app; saves the recovery codes (15 minutes).
- Adds a PIN to her phone carrier account to guard against SIM swaps (10 minutes).
- Changes passwords for her bank, two credit cards, retirement account and budgeting app to unique generated ones, adding passkeys where offered and two-factor sign-in everywhere (45 minutes).
- Turns on large-purchase and low-balance alerts so she’ll notice any fraud quickly (10 minutes).
- Reviews signed-in devices and removes an old tablet (5 minutes).
About an hour and three quarters, and her most important accounts are far better protected.
How Kemback handles sign-in
Kemback supports passkeys and two-factor sign-in with an authenticator app, and lets you see and sign out of signed-in devices. It never stores your bank passwords. Alerts for large purchases and unusual spending can also help you spot fraud early. The same principles apply to every financial app you use: unique credentials, the strongest second factor on offer, and a habit of checking what’s signed in.
This article is general information, not financial, tax or legal advice. For decisions about your situation, talk to a qualified professional.
Keep reading
Spending Alerts That Actually Help (and Ones That Just Nag)
Which money alerts are worth turning on, how to set thresholds that fit your budget, and how to avoid alert fatigue so the important warnings still get seen.
Lifestyle Creep: How to Enjoy a Raise Without Losing It
Lifestyle creep quietly absorbs raises. Learn how to spot it and use a simple split rule to enjoy more income while still saving most of it, with examples.
How to Stop Impulse Spending: Practical Habits That Work
Why impulse purchases happen and practical ways to curb them: waiting periods, friction, a fun-money budget, and knowing your triggers, with worked examples.