Make the account boring to a credential-stuffing attacker.
What to do
- Use a unique password stored in a password manager
- Turn on 2FA — authenticator app over SMS where possible
- Remove cards you don't actively use and use virtual card numbers for the ones you keep
- Set 'require password for purchase' if the marketplace offers it
- Review and revoke third-party app connections (Amazon, eBay, etc.)
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers