Cheat sheets
Everyday checklists
Short step-by-step lists: work through the points and the risk drops noticeably.
Secure an account in 10 minutes
The minimum that stops most common takeovers.
- Change your password to a long one (14+ characters) that is unique for every important site.
- Keep passwords in a password manager — you only have to remember one master password.
- Turn on two-factor authentication, preferably with an app or a key rather than SMS.
- Check your email for breaches and change passwords wherever they were exposed.
- Remove old devices and unfamiliar sign-ins in your account's security settings.
- Give your main email its own password used nowhere else: every other reset goes through it.
- Turn on alerts for sign-ins from a new device.
How to spot a phishing email
Five seconds of attention before you click a link.
- Look at the sender's address, not the name: "Bank" can come from an address that has nothing to do with the bank.
- Hover over a link and compare the real address with what the text says.
- Be wary of urgency and threats: "your account will be blocked in an hour", "final warning".
- Services don't ask you to reply with your password, SMS code or card details.
- A generic "Dear customer" instead of your name and odd mistakes in the text are bad signs.
- Don't open attachments ending in .exe, .scr, .zip, or Office files that say "enable macros".
- If in doubt, go to the service's site yourself by typing the address, not through the link in the email.
- Check a suspicious link first: in emails on our mailbox, each link has a "Check" button next to it.
Before you publish a photo or document
A file says more about you than what's visible on screen.
- Strip EXIF from photos: it can hold your home's GPS coordinates, your phone model and the exact time.
- In Word and PDF documents, check the author, organization and edit history — remove those too.
- In screenshots, hide addresses, numbers, names in lists, tabs and notifications.
- Don't post photos of tickets, barcodes, card numbers or documents — codes can be read from a picture.
- Remember that messengers and social networks often strip metadata themselves, but sending a photo as a file keeps it.
- If you must send a file with personal data, share a link that stops working after a while.
Signing up on a site you don't trust
How to get what you need without leaving extra behind.
- Use a temporary email instead of your main one — then spam and the site's data leak won't reach you.
- Create a separate password: its leak shouldn't open your other accounts.
- Don't give a phone number or documents if the site works without them.
- Pay with a virtual or single-use card with a limited balance.
- If you sign up for a one-time code or file, don't use an address you'll need later — a temporary inbox disappears.
- For anything important (bank, work, government services), don't use a temporary email: you'd lose account recovery.
What to do if your password leaked
The order of steps when a service reports a breach or you find your address in a database.
- Immediately change your password on the site where the leak happened.
- Change the same password everywhere you used it — start with email and banks.
- Turn on two-factor authentication where you don't have it yet.
- End active sessions on all devices in your account settings.
- Review emails about password changes and suspicious sign-ins from the last few days.
- Be more careful with emails and calls: after a breach, scammers know your name and email.
- Stop using one password for different sites.
