Protecting Your Family's Accounts: Strong Passwords and Two-Step Verification
A hijacked email account can open the door to social media, banking, cloud photos and your children's accounts. This guide explains in plain language how to use passwords, two-step verification and passkeys to protect your family's digital accounts.
A family's digital life depends on a few critical accounts: email, the Google or Apple account the phone is linked to, messaging apps, social media and banking. If one of them is taken over, especially email, the effect spreads, because password reset links for the other accounts arrive by email.
The good news: most account takeovers can be prevented with a few basic habits. In this guide we explain these habits step by step, in a way every member of the family can follow.
How accounts get taken over
Most attacks do not involve sophisticated hacking but quite simple methods:
- Trying leaked passwords: Email and password pairs leaked from one site are automatically tried on other sites. If you use the same password in several places, a single leak puts all your accounts at risk.
- Phishing: Fake pages imitating the site of a bank, a delivery company or a social media platform. For details, see our article on SMS and WhatsApp scams.
- Guessable passwords: "123456", birthdays, the names of children or pets.
- Tricking you into handing over a code: Messages like "I sent you a code by mistake, could you forward it to me?" This is often used to steal WhatsApp accounts.
Step 1: A different, long password for every account
The most important quality of a strong password is length. Instead of a complex but short password ("K!8t#"), a long, memorable passphrase is far stronger:
- Weak:
Sarah1985 - Medium:
S@rah_1985! - Strong:
blue-cat-drinking-tea-on-the-balcony-42
When creating a passphrase:
- Use at least 4–5 random words.
- Do not use information about yourself (name, date of birth, address).
- Avoid predictable phrases such as song lyrics or famous quotes.
But the real rule is: a different password for every account. That brings us to the next step.
Step 2: Use a password manager
Memorising dozens of different, long passwords is impossible. A password manager is an app that stores all your passwords in an encrypted vault and fills them in for you, while you only remember one master password.
Options:
- Your device's built-in password manager: The Passwords app (iCloud Keychain) on iPhone, Google Password Manager on Android. They are free and enough for most families.
- Independent password managers: Paid or free apps that work across different operating systems and offer family sharing.
The master password of the password manager should be the strongest password in the family and must never be used anywhere else.
Step 3: Turn on two-step verification
Two-step verification (2FA) asks for a second check in addition to your password. So even if your password is stolen, an attacker cannot get into your account without passing the second step.
Second-step methods, from strongest to weakest:
| Method | Security | Note |
|---|---|---|
| Passkey or physical security key | Very high | The most resistant to phishing |
| Authenticator app (Google Authenticator, Microsoft Authenticator, etc.) | High | Needs neither internet nor a SIM card |
| In-app approval prompt | High | Answer "Is this you signing in?" prompts carefully |
| Code by SMS | Medium | Better than nothing, but vulnerable to SIM swap fraud |
Order of priority
Turn on two-step verification in this order:
- Your main email account (the key to everything else)
- Your Google or Apple account (the one your phone, photos and backups are linked to)
- WhatsApp (Settings → Account → Two-step verification; you set a 6-digit PIN)
- Social media accounts
- Gaming accounts (especially children's accounts that contain purchased content)
Banking apps usually enforce their own extra security layers.
Keep your recovery codes
When you turn on two-step verification, save the recovery codes you are given and keep them somewhere safe (in your password manager, or written on paper and kept somewhere secure at home). If you lose your phone, you can get into your account with these codes.
Step 4: Try passkeys
Passkeys are a new method that is starting to replace passwords. Instead of typing a password, you sign in with your phone's screen lock (fingerprint, face recognition or PIN). Their advantages:
- There is no password to remember.
- They cannot be used on a fake site; a passkey only works on the real one. That makes phishing largely ineffective.
- There is no password that can leak.
Google, Apple, Microsoft and many large services support passkeys. If you see a "Create a passkey" option in your account settings, you can start using it.
Step 5: Never share verification codes
This rule should be repeated again and again to every member of the family, especially children and older relatives:
Never share a verification code you receive by SMS, no matter who asks. Not a bank employee, a courier, a "WhatsApp support team", not even a friend or relative. Real organisations do not ask you for these codes. A request for a code from a "friend" usually means their account has already been taken over.
Step 6: Keep phones secure
- Screen lock: Use a PIN, pattern or biometric lock on every family phone.
- Updates: Do not delay operating system and app updates; they often fix security holes.
- App sources: Only download apps from the official stores (Google Play, the App Store).
- SIM PIN: Makes it harder to use your SIM card in another device if your phone is stolen.
- Lines in your name: Many mobile operators let you check which lines are registered in your name. If you see a line you do not recognise, contact your operator.
Step 7: Manage children's accounts together
- Make sure you also have access to the email address used for your children's accounts.
- Teach children to create their own passwords, but make sure a copy is kept somewhere safe (for example, in a family password manager).
- Turn on two-step verification for gaming accounts; stolen gaming accounts can be a huge disappointment for children and sometimes the start of a scam. For details, see our article on online gaming safety.
- Teach the rule "don't share your password, not even with your best friend".
What to do if an account has been taken over
- Change your password immediately (if you still have access) and sign out of all sessions.
- Start the account recovery process (if you no longer have access). Use the platform's official recovery pages.
- Turn on two-step verification or check its settings; the attacker may have added their own phone.
- Change the password on other accounts where you used the same one.
- Warn your friends. Hijacked accounts are often used to send friends messages asking for money or codes.
- Call your bank if your financial details may be at risk.
A quick checklist for the family
- Is two-step verification on for your main email account?
- Is a two-step verification PIN set on WhatsApp?
- Does every account have a different password?
- Is a password manager being used?
- Are the recovery codes kept somewhere safe?
- Do all phones have a screen lock and the latest updates?
- Does everyone in the family know the rule "verification codes are never shared"?
Conclusion
Account security can look complicated, but at its core it rests on three habits: a different, long password for every account, two-step verification, and never sharing verification codes. These three habits prevent the vast majority of account takeover attacks a family may face.
For a broader framework, have a look at our family safety guide.
Frequently asked questions
What makes a strong password?
The most important quality of a strong password is length. A passphrase of at least 4–5 random words is far more secure than a short, complex password. Avoiding personal information and using a different password for every account are also essential.
What is two-step verification?
Two-step verification is a security layer that asks for a second check alongside your password when you sign in. The second step can be a code from an authenticator app, an approval prompt on your phone, an SMS code or a passkey. It makes it much harder to get into your account even if your password is stolen.
Is two-step verification by SMS safe?
SMS verification is much better than nothing, but it is vulnerable to risks such as SIM swap fraud and being tricked into handing over the code. Where possible, prefer an authenticator app or a passkey.
How can I stop my WhatsApp account being stolen?
Set a 6-digit PIN via Settings, Account, Two-step verification. Never share the verification code WhatsApp sends you, no matter who asks. Even a request for a code from someone you know usually means their account has been taken over.
Are password managers safe?
Reputable password managers store your passwords with strong encryption and are far safer than reusing the same password in several places. What matters is that the master password is strong and unique and that the password manager is protected with two-step verification.
This article is for general information and is not a substitute for medical, legal or other professional advice. In an emergency, call your local emergency number right away (112 in Europe, 911 in the US and Canada).