Two settings do most of the work of keeping your account yours. Turn both on.
1. A unique passphrase. Your bank password should be a passphrase of three or four random words, like maple-harbor-quilt-58, and used for nothing else. If another site is ever hacked and you reused your password, criminals will try it on your bank. A unique one stops that cold. Let your phone or browser’s free password manager remember it. CISA advises long, unique, random passwords stored in a password manager.
2. Two-factor authentication (2FA). This adds a second step at login, so even a stolen password is not enough. CISA urges everyone to turn it on, and says any 2FA is better than none. From weakest to strongest:
- A text code (fine to start).
- An authenticator app (stronger).
- A passkey, using your fingerprint or face, which CISA calls “phishing-resistant” because it will not work on a fake site (strongest, use it if offered).
Turn it on: in your bank’s app or site, go to Settings or Security, find Two-step or Two-factor verification, and follow the steps. Save any backup codes somewhere safe.
A quick example. A criminal buys your leaked password and tries to log in. Your phone asks you to approve it. You did not start it, so you tap No. They are locked out. Your password alone was not enough.
What to do:
- Make your bank passphrase unique, used nowhere else.
- Turn on 2FA, and pick a passkey or app if offered.
- Save your backup codes.
General education, not financial advice.