QUICK SUMMARY
Use a long, unique password for every account, store passwords in a reputable password manager, and enable multifactor authentication. Length and uniqueness matter more than making one short password complicated.
A strong approach
- Let a password manager generate and store a different password for each account.
- When you must remember one, use a long passphrase made from several unrelated words.
- Never reuse an important password for email, banking, shopping, or social media.
- Turn on multifactor authentication, preferably with an authenticator app or security key when available.
Why reuse is dangerous
If one website is breached, attackers often try the stolen email-and-password combination on other services. A unique password limits the damage to one account.
What to do after a suspected breach
Change the affected password, change it anywhere it was reused, sign out other sessions, review recovery information, and watch for unexpected login or reset messages.
Sources
See CISA Secure Our World and CISA guidance on multifactor authentication.