Accounts and passwords
Most of what people call "being hacked" is an account problem rather than a computer problem, and the response is almost entirely free. These six questions cover the order to work in, what breach notices mean, and the two measures that make the largest difference.
I think someone else has been in my account. What first?
Change the password, then immediately sign out of all other sessions, then check the account's recovery settings. Changing the password alone can leave an intruder signed in on their own device.
What usually sits behind it
Access to an account is normally obtained in one of three ways: the password was reused and appeared in a breach somewhere else; it was typed into a convincing imitation of the sign-in page; or it was simple enough to guess. All three are addressed by the same response, which is why you do not need to establish which one happened before acting.
The part people miss is persistence. Someone who gains access often adds a recovery email address, a forwarding rule or an app password, so that they keep access after the password changes. Those settings need checking, and they are the reason the sequence below has more than one step.
What to do first, at no cost
- Change the password to one not used anywhere else, from a device you trust.
- Find the security settings and use the option to sign out of, or revoke, all other sessions and devices.
- Switch on two-factor authentication if it is available and was not already in use.
- Check the recovery email address and recovery phone number, and remove anything you did not add.
- In an email account, check the forwarding rules and filters. A rule that quietly forwards or deletes messages is a common addition.
- Review the list of connected apps and remove any you do not recognise.
- Change the password anywhere else it was reused.
When to ask for official help
If the account was used to contact other people, tell them directly through another channel. If money, identity documents or a business account are involved, report through ReportCyber at cyber.gov.au, and contact your bank where any payment is in question.
Where a paid product may or may not help
Account security is set by the service itself, not by software on your computer. A security product matters here only if the password was taken by something running on the machine, which is the less common route and worth ruling out with a full scan.
I was told my details appeared in a data breach. Does that matter?
It matters in proportion to what was exposed and to whether that password is used anywhere else. An email address alone is a nuisance; a password you reuse is the one that needs action today.
What usually sits behind it
A breach notice means an organisation holding your details lost control of them. What was in the records varies enormously: sometimes only an address and a name, sometimes passwords in a form that can be worked back to the original, sometimes identity documents. The notice should say which, and that detail determines the response.
Australian organisations covered by the Privacy Act 1988 (Cth) have obligations under the Notifiable Data Breaches scheme, which the Office of the Australian Information Commissioner oversees and explains at oaic.gov.au.
| What the notice says was exposed | Reasonable response |
|---|---|
| Email address and name only | Expect more unsolicited and better-targeted messages; no password change needed for that reason alone |
| Password, in any form | Change it at that service and everywhere it was reused, today |
| Card number | Contact your bank and ask about replacing the card; watch the statement |
| Identity documents | Follow the issuing agency's process for replacement, and consider the support services named by Australian agencies |
| Answers to security questions | Change those answers wherever the same ones were used |
What to do first, at no cost
- Read the notice for the specific categories involved rather than assuming the worst or the least.
- Change the password at that service, and anywhere the same password was used.
- Switch on two-factor authentication where the service offers it.
- Be more sceptical of messages referring to that organisation for the next few months, since the breached list is what makes convincing fakes possible.
When to ask for official help
If you are unhappy with how an organisation handled your information, a complaint goes first to the organisation and then to the OAIC at oaic.gov.au.
Where a paid product may or may not help
Some paid security packages include monitoring that tells you when an address appears in a published breach collection. That is a notification service rather than protection; the value depends on whether you would act on the notice.
Is a password manager safer than writing passwords down?
For most people, yes, mainly because it makes unique passwords practical. A notebook kept at home is also a legitimate choice and is far better than reusing one password everywhere.
What usually sits behind the question
The objection to password managers is reasonable on its face: putting everything in one place creates a single point of failure. The counter-argument is about what actually goes wrong in practice. Breaches of individual services are routine, and the damage they cause depends almost entirely on whether the password was reused. A manager makes a different password per service effortless, which removes that chain.
A notebook has a real advantage, which is that it cannot be reached over the internet, and a real disadvantage, which is that it is inconvenient enough that people start reusing passwords again. Choose the one you will actually keep using.
What to do first, at no cost
- Consider the password manager built into your browser or operating system, which costs nothing and is a substantial improvement over reuse.
- Protect the manager itself with a long passphrase you have never used elsewhere, and with two-factor authentication.
- Make sure you can still reach your passwords if the device is lost: check the recovery arrangements before you need them.
- If you prefer paper, keep it somewhere a visitor would not look, and do not label it.
When to ask for official help
The Australian Cyber Security Centre publishes general guidance on passphrases and account protection for individuals at cyber.gov.au, which is a neutral starting point when comparing approaches.
Where a paid product may or may not help
Password managers are sold both separately and as part of larger security packages. Buying one is a reasonable choice; so is using the free one already on the device. The security benefit comes from unique passwords, not from the price of the tool.
What does two-factor authentication actually stop?
It stops someone who has only your password from signing in. That covers the most common case by a wide margin, which is why it is the single most useful free change you can make.
What usually sits behind it
Stolen passwords circulate in bulk and are tested automatically against many services. A second factor breaks that process, because having the password is no longer sufficient. It does not protect against everything: a person who is tricked into reading a code aloud to a caller, or into approving a prompt they did not initiate, has handed over the second factor as well.
The methods differ in strength. A code from an authenticator application is generally considered stronger than one sent by text message, because a text can be redirected if someone takes over the telephone number. A physical security key is stronger again. Any of them is a large improvement on none.
What to do first, at no cost
- Turn it on for the email account first, because that account can reset the others.
- Then for banking, then for any account holding payment details, then for social accounts.
- Prefer an authenticator application over text messages where the service offers both.
- Save the recovery codes the service gives you somewhere you will still have them if the phone is lost.
- Never read a code to someone who contacted you. No legitimate organisation asks for one.
What to watch out for
Repeated approval prompts arriving when you are not signing in are a signal that someone has your password and is hoping you will approve one by reflex. Decline them and change the password rather than dismissing them.
When to ask for official help
If you lose access to a second factor and the recovery codes, only the service itself can restore access, through its own account recovery process. No third party can do this, and anyone offering to is not legitimate.
Where a paid product may or may not help
Two-factor authentication is free and is configured in each service. Nothing needs to be bought for it, and no security product can enable it on your behalf.
I used the same password everywhere. Where do I start?
Start with email, then anything that can move money, then anything holding identity documents. You do not have to fix everything in one sitting, and the order matters more than the speed.
What usually sits behind it
Password reuse is the ordinary result of being asked to remember too many things. The reason it causes disproportionate harm is that accounts are connected: an email account can reset the password of almost everything else, so it sits at the top of a hierarchy whether or not you think of it that way.
Working through a long list is tedious, and the temptation is to do none of it. A tiered approach gets most of the benefit from a fraction of the work.
What to do first, at no cost
- Write down the accounts that matter, in three groups: email, money and identity; accounts with saved payment details; everything else.
- Change the first group this week, each to a different password, and switch on two-factor authentication as you go.
- Change the second group over the following weeks.
- Change the third group as you happen to sign into each one.
- Close accounts you no longer use rather than maintaining them.
When to ask for official help
If you find an account you cannot access during this process, use the service's own recovery route. Guidance on protecting accounts generally is published for individuals at cyber.gov.au.
Where a paid product may or may not help
Nothing in this answer requires a purchase. A password manager, free or paid, makes the third group far less tedious, which is the practical argument for one.
Why does everyone say to secure the email account first?
Because it is the key to the others. Almost every service resets its password by sending a message to your email address, so whoever controls the mailbox can take control of nearly everything else.
What usually sits behind it
This is a structural feature of how online accounts work rather than a flaw in any particular service. The email address is the recovery route, and recovery routes are by design powerful. The consequence is that an email account deserves the strongest password and the strongest second factor you are willing to use, even if the messages inside it seem unimportant.
There is a second reason. A mailbox contains a record of which services you use, where you bank, where you shop and who your family are. That makes it the best possible source of material for a convincing approach later.
What to do first, at no cost
- Give the email account a unique passphrase used nowhere else.
- Switch on two-factor authentication, preferably with an authenticator application.
- Check the forwarding rules and filters for anything you did not create.
- Check the recovery address and phone number, and keep them current.
- Review the connected applications list and remove what you no longer use.
- Keep a secondary address, protected the same way, as a recovery option.
When to ask for official help
If the email account itself has been taken over and recovery fails, the provider's recovery process is the only route. If the loss has consequences beyond the mailbox, report through ReportCyber at cyber.gov.au.
Where a paid product may or may not help
Protection on a desktop computer reduces the chance that a password is captured on that machine, which is one route in among several. Norton AntiVirus Plus is a desktop antivirus product; account settings remain the part of this that only you can change, and they cost nothing.
Visit the Norton AntiVirus Plus websitePaid affiliate link. Mildfactor earns a commission on purchases that follow it, with no change to what you pay.