Start with the basics: passwords, updates, and what to share

Online privacy starts with three things you control right now: a strong password on every account, keeping your device software current, and thinking before you post or click. A strong password is at least 12 characters long and mixes uppercase and lowercase letters, numbers, and symbols — something like "BlueMoon#42Oak" rather than "password123" or your grandchild's name. Write passwords down in a notebook you keep in a locked drawer at home, or use a password manager like Bitwarden or 1Password that stores them encrypted on your device.

Updates matter more than most people realize. When your computer, phone, or tablet shows an update notification, install it as soon as you can — these patches close security holes that scammers actively exploit. Set your device to update automatically so you do not have to remember. Never ignore a software update warning, and never click "remind me later" and then forget.

Before you post anything online — a photo, a comment, a location, a birthday — ask yourself: would I want a stranger to know this? Scammers piece together small details from social media to impersonate you or convince your family you are in trouble. Avoid posting your full birth date, your address, your phone number, or where you are right now.

Key Takeaways

  • Use a password of at least 12 characters mixing letters, numbers, and symbols on every account, and store passwords in a locked notebook or password manager.
  • Install software updates the moment your device offers them, and turn on automatic updates so you never miss a security patch.
  • Do not post your full birth date, address, phone number, or current location on social media or in online profiles.
  • Scammers use email and text messages that look like they come from your bank or a familiar company — call the official number on your statement instead of clicking any link in the message.
  • Turn on two-factor authentication on email and banking accounts so that even if someone steals your password, they cannot log in without a code sent to your phone.

Recognize phishing: emails and texts that pretend to be from companies you trust

Phishing is a message — usually email or text — that looks like it comes from your bank, PayPal, Amazon, or another company you use, but actually comes from a scammer. The message often says your account is locked, your payment failed, or you need to confirm your identity. It includes a link that looks official but leads to a fake website designed to steal your password or credit card number.

The safest rule: never click a link in an unsolicited email or text, even if it looks real. Instead, open your web browser, type the company's website address yourself, or call the phone number on your statement or card. A real company will never ask you to confirm your password, Social Security number, or credit card details by email or text. If you are unsure, hang up and call the official customer service number — it takes two minutes and could save you thousands.

Watch for small signs that a message is fake: misspelled words, an email address that does not match the company name (like "paypa1-security@gmail.com" instead of a PayPal domain), or a message that creates panic or urgency. Scammers use fear to make you act without thinking.

Turn on two-factor authentication for email and banking

Two-factor authentication (often called 2FA) means that even if someone guesses or steals your password, they cannot log into your account without a second piece of information — usually a code sent to your phone. It is one of the strongest protections you can use.

Start with your email account, because email is the key to everything else: if someone takes over your email, they can reset your passwords for banking, social media, and shopping sites. Most email providers (Gmail, Outlook, Yahoo) offer two-factor authentication in their security settings. You choose whether to receive codes by text message or through an authenticator app like Google Authenticator or Microsoft Authenticator. Text message is simpler if you are new to this.

Next, turn on two-factor authentication for your bank and any financial accounts. Your bank's website has a security or settings section where you can enable it. After you log in with your password, you will be asked to enter a code sent to your phone — this takes 30 seconds and happens only once per device, so you will not have to do it every single time you check your balance.

Understand what information websites collect and how to limit it

Every website you visit collects information about you: what you click, how long you stay, what you search for. This data is sold to advertisers, which is why you see ads for things you looked at weeks ago. You cannot stop this entirely, but you can reduce it.

In your web browser settings, look for privacy or security options. Most browsers (Chrome, Firefox, Safari, Edge) let you delete your browsing history, cookies, and cached data regularly — do this once a month. You can also turn on "Do Not Track" mode, which tells websites you prefer not to be tracked, though not all websites honor it. Some browsers have a "private browsing" mode that does not save your history at all; use this when you are on a shared computer or a public Wi-Fi network.

Be cautious about what you allow websites to access. When a website asks permission to use your location, camera, or contacts, think about whether it actually needs that information. A weather app needs your location; a news site does not. You can change these permissions anytime in your device settings.

Protect yourself on public Wi-Fi and shared computers

Public Wi-Fi at a coffee shop or library is convenient but risky: anyone on the same network can see what you send if the connection is not encrypted. Never log into your bank account, email, or shopping sites on public Wi-Fi unless you are using a VPN (virtual private network), which encrypts your data so others cannot see it. Free VPNs exist, but paid ones like ExpressVPN or NordVPN are more reliable; they cost a few dollars a month.

If you use a shared computer — at a library, a family member's house, or a community center — never save your passwords in the browser. Log out completely when you finish, and clear your browsing history before you leave. Better yet, use private browsing mode so nothing is saved automatically.

On your own device at home, make sure your Wi-Fi network is password-protected. If you do not remember setting up your home Wi-Fi password, contact your internet provider and ask them to help you change it to something strong and unique.

Spot and avoid common scams targeting older adults

Scammers have scripts they use over and over. Knowing the pattern helps you spot them. A tech support scam starts with a pop-up or email saying your device has a virus and you need to call a number when ready. Do not call. Close the browser tab or restart your computer. Real security warnings come from your device itself, not from a website.

A grandparent scam comes as a text or email from someone claiming to be your grandchild in an emergency — they need money wired right away for bail, a hospital bill, or a plane ticket home. Scammers count on panic. Before you send money, call your grandchild's phone number directly or contact another family member. A real grandchild will not ask you to wire money or buy gift cards.

Romance scams and lottery scams follow similar patterns: someone you do not know well builds trust over weeks or months, then asks for money or personal information. If someone you met online asks for money, stop communicating and block them. You have not lost a relationship; you have avoided a scam.

Keep your devices and accounts organized so you can monitor them

Write down the names and passwords of your important accounts — email, bank, insurance, Social Security — and keep the list in a locked drawer or a password manager. Include the customer service phone number for each. This way, if something goes wrong, you know exactly what accounts to check and whom to call.

Check your bank and credit card statements every month, either online or by mail. Look for charges you do not recognize. If you see something wrong, call your bank when ready — they can reverse fraudulent charges and issue you a new card. Many banks also offer free credit monitoring; ask yours whether you have it.

Consider placing a credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) if you are concerned about identity theft. A credit freeze prevents anyone, including you, from opening new accounts in your name without unfreezing it first. It is free and takes about 15 minutes per bureau. You can do it online at each bureau's website or by phone.

Frequently Asked Questions

What should I do if I think I have been scammed?

Stop communicating with the scammer when ready and do not send more money. If money was sent by wire transfer or gift card, contact the service right away — they may be able to stop the transfer. Report the scam to the Federal Trade Commission at reportfraud.ftc.gov. If your bank account or credit card was used, call your bank and ask them to monitor your account and issue a new card.

Is it safe to use the same password for multiple accounts?

No. If a scammer gets one password, they can try it on your email, bank, and shopping accounts. Use a different password for each account, especially for email and banking. A password manager makes this easier by storing all your passwords securely in one place.

Do I really need a password manager, or can I just write passwords down?

Writing passwords in a notebook kept in a locked drawer at home is safe. A password manager is safer because it encrypts your passwords and you only have to remember one master password. If you are comfortable with a notebook, that works — just keep it private and do not write down which password goes with which account on the same page.

What is the difference between a virus and malware?

A virus is a type of malware — malware is the umbrella term for any harmful software. Both can steal your information or damage your device. Protection is the same: keep your software updated, do not click suspicious links, and use antivirus software like Windows Defender (built into Windows) or Malwarebytes.

Should I be worried about my smart home devices like Alexa or Google Home?

Smart speakers are generally safe if you set them up with a strong password and keep them updated. Be aware that they listen for wake words and send audio to the company's servers. You can mute the microphone when you are not using the device, and you can review and delete your voice recordings in the device's app settings.