The core practices that protect you online
Internet safety comes down to a few concrete habits: using strong passwords you do not reuse, keeping your software updated, recognizing when someone is trying to trick you into giving up information, and knowing what to do if something goes wrong. None of these require special technical knowledge — they are decisions you make the same way you decide to lock your door or check a receipt.
The threats are real but manageable. Criminals online want your passwords, your money, your identity, or access to your accounts. They succeed most often not through hacking but through tricking you into handing these things over. The people trying to steal from you are counting on you not knowing what to watch for.
Key Takeaways
- Create passwords that are at least 12 characters long, mix letters with numbers and symbols, and never use the same password on more than one site.
- Turn on two-factor authentication on any account that holds money or personal information — it stops thieves even if they have your password.
- Phishing emails and texts pretend to be from banks, PayPal, or services you use, and they work by making you click a link or download a file; delete them if you did not expect the message.
- Keep your operating system, browser, and antivirus software up to date, because updates patch the holes criminals use to break in.
- If you think you have been hacked, change your passwords immediately and contact your bank and the affected company's support team.
Creating passwords that actually protect you
A strong password is at least 12 characters long and includes uppercase letters, lowercase letters, numbers, and symbols like ! or #. "Sunshine2024" is not strong because it uses only letters and a predictable number. "Tr0pic@lSunset#42" is strong because it mixes all four types and has no dictionary words.
The second rule is harder for most people: never use the same password on more than one website. When a criminal steals your password from one site, they immediately try it on your email, your bank, and your social media. If you reuse passwords, one breach unlocks everything. Use a password manager — a program like Bitwarden, 1Password, or the password manager built into your browser — to store unique passwords for each site. You only have to remember one master password.
If you cannot remember a password you created, that is a sign it was too complicated to be useful. A password manager solves this. If you do not want to use one, create a system: a base phrase you remember, plus a unique addition for each site. For example, your base might be "BlueMountain$99" and you add the first three letters of the site: "BlueMountain$99Ama" for Amazon, "BlueMountain$99Goo" for Google. This is weaker than a password manager but stronger than reusing the same password everywhere.
Two-factor authentication: the second lock on your door
Two-factor authentication (often called 2FA) means you need two things to log in: your password and a second proof that you are really you. The second proof is usually a code sent to your phone by text or generated by an app like Google Authenticator or Authy.
Turn on two-factor authentication for any account that matters: your email, your bank, PayPal, Amazon, or any service linked to your credit card. If a criminal has your password, they still cannot get in without that second code. Most services let you choose between text message codes (slower but simpler) or an authenticator app (faster and more secure). Either one is far better than nothing.
When you turn on two-factor authentication, the service usually gives you backup codes — a list of one-time codes you can use if you lose access to your phone. Write these down or save them in a safe place separate from your passwords. If you lose your phone and do not have backup codes, you may be locked out of your own account.
Recognizing phishing: the most common way people get hacked
Phishing is a message — usually email or text — that pretends to be from a company you trust and asks you to click a link or download a file. The link takes you to a fake website that looks real, where you type your password or credit card number. The file contains malware that infects your computer.
Phishing messages often claim something is wrong with your account, your payment method, or your security. "Your Amazon account has been compromised — click here to verify your identity." "Your bank detected unusual activity — confirm your information." "PayPal needs to update your payment method — log in now." These messages create panic so you act without thinking.
The safest rule: if you did not ask for the message, do not click the link. Instead, go directly to the company's website by typing the address into your browser (not by clicking a link in the email), log in, and check whether anything is actually wrong. Real companies like Amazon and your bank will never ask you to click a link in an email to verify sensitive information. If you are unsure, call the company's customer service number from their official website.
Phishing text messages work the same way. A text claiming to be from your bank or a delivery service asks you to click a link. Delete it. If you think it might be real, call the company directly using a number you find yourself, not one in the message.
Keeping your software up to date
Software updates patch security holes that criminals use to break into your computer or steal your information. When your operating system (Windows, macOS, or Linux), your browser (Chrome, Firefox, Safari, or Edge), or your antivirus software tells you an update is available, install it as soon as you can. These updates are not optional.
On Windows, go to Settings > Update & Security > Windows Update and click "Check for updates." On macOS, go to System Settings > General > Software Update. Most browsers update automatically, but you can check by opening the menu and looking for an option like "About Chrome" or "About Firefox" — if an update is available, it will install when you restart the browser.
Antivirus software like Windows Defender (built into Windows), Malwarebytes, or Avast also needs updates. These programs work by comparing files on your computer to a database of known malware. If the database is old, the software cannot recognize new threats. Set your antivirus to update automatically if that option is available.
What to do if you think you have been hacked
If you notice something wrong — you cannot log into an account, you see charges you did not make, or someone tells you they received a message from your email — act immediately. The first step is to change your passwords, starting with your email. Your email is the master key to everything else: if a criminal controls your email, they can reset your passwords on every other account.
Change your email password from a different device if possible (a phone or tablet, not the computer you think might be infected). Use a strong new password that you have never used before. Then change the passwords on your bank, PayPal, Amazon, and any other account that holds money or sensitive information.
Contact your bank and any company whose account was compromised. Tell them what happened and ask them to watch for fraud. If you see charges you did not make, report them as fraudulent — your bank can reverse them. If your identity was stolen (someone opened accounts in your name), contact the Federal Trade Commission at IdentityTheft.gov, which will walk you through the steps to report it and protect yourself.
If you think your computer itself is infected with malware, run a full scan with your antivirus software or Malwarebytes. If the scan finds threats, let it remove them. If you are not sure whether your computer is safe, take it to a local computer repair shop and ask them to scan it.
Public Wi-Fi and what it exposes
Public Wi-Fi at coffee shops, airports, and libraries is convenient but risky. Anyone on the same network can see the data you send if it is not encrypted. This means a criminal sitting next to you could see your passwords, emails, or credit card numbers.
The safest approach is to avoid logging into sensitive accounts on public Wi-Fi. Do not check your bank balance, enter your credit card number, or log into email on an airport network. If you must use public Wi-Fi for something important, use a VPN (virtual private network) — a service like ExpressVPN, NordVPN, or Proton VPN that encrypts all the data leaving your device. This makes it unreadable to anyone watching the network.
Many VPNs charge a monthly fee, but some offer free versions with limits. Before you choose one, check whether it keeps logs of your activity — some do, which defeats the purpose. Reputable VPNs like Proton VPN and Mullvad publish transparency reports showing they do not log user activity.
Frequently Asked Questions
What should I do if I get a suspicious email asking me to verify my password?
Delete it. Real companies never ask you to verify your password by email. If you are worried the message might be real, go directly to the company's website by typing the address yourself (do not click the email link) and log in to check your account. If nothing is wrong, the email was phishing.
Is it safe to use the same password if I change it frequently?
No. Changing a password frequently does not protect you if you use the same one everywhere. A criminal who steals it from one site can use it on all your other accounts immediately. Use unique passwords and change them only if you think they have been compromised.
Do I need antivirus software if I use a Mac?
macOS has built-in protections that are stronger than Windows, but malware exists for Macs too. Keep your operating system updated and be cautious about what you download. Many people use Macs without additional antivirus software, but running Malwarebytes occasionally adds an extra layer of protection.
What is the difference between a VPN and a password manager?
A password manager stores your passwords securely and fills them in for you. A VPN encrypts all the data leaving your device so no one on your network can see it. You need both: a password manager to create strong unique passwords, and a VPN to protect yourself on public Wi-Fi.
Can I get hacked just by visiting a website?
It is possible but rare. Most websites are safe. The risk is higher if your software is outdated — criminals exploit known security holes in old browsers and operating systems. Keeping everything updated protects you against this type of attack.