Financial Safety in the Digital World

Staying Safe with Money Online

A practical guide to avoiding scams, phishing, and identity theft

Nearly every scam works the same way: someone you did not contact creates urgency or fear, then asks you to act before you think. The single most protective habit is to stop, hang up, and check independently. The 15 strategies below are variations on that idea.

First, the big idea

Scammers are professionals. They study what makes people act fast: fear ("your account is frozen"), authority ("this is the IRS"), love ("Grandma, I'm in jail"), or greed ("guaranteed returns"). Research on fraud victims consistently finds that being smart does not protect people. Anyone can be caught when the call arrives at a bad moment, so the defense is a set of habits, not a feeling of being alert.

Three rules cover most situations:

1.    Slow down. Real emergencies survive a ten-minute pause. Scams do not.

2.    Verify independently. Hang up and call the number on your bank card, your statement, or the organization's official website, never the number the caller or message gave you.

3.    Tell someone. Scammers depend on secrecy and shame. A second person's opinion breaks the spell.

Part 1: Recognizing a scam (strategies 1-6)

1. Treat unexpected contact as suspicious. An unsolicited call, text, email, or pop-up that involves money, passwords, or your accounts deserves doubt, however official it looks. You can always end the conversation and reach out yourself.

2. Never trust caller ID or a link in a message. Caller ID and email sender names are easy to fake. Instead, call the number printed on your card or statement, or type the organization's web address yourself.

3. Know what real organizations never do.

•        The IRS, Social Security, and Medicare do not phone to threaten arrest, demand immediate payment, or ask for your number to "verify" it. The IRS starts contact by mail.

•        Your bank will not ask you to move money to a "safe account" or read back a security code.

•        Microsoft, Apple, and your internet provider do not call you about a virus.

•        No government agency, utility, or court accepts gift cards as payment.

4. Know the payment methods scammers prefer. Gift cards, wire transfers, cryptocurrency (including bitcoin ATMs), payment apps like Zelle or Venmo sent to a stranger, and cash handed to a courier are hard or impossible to reverse. If anyone insists on one of these, stop. A credit card is far safer because you can dispute the charge.

5. Agree on a family code word. "Grandparent" scams now use voice-cloning software that can copy a relative's voice from a few seconds of audio. Choose a word or question only your family knows. If a "grandchild" calls in trouble, ask for it, then hang up and call them on their own number.

6. Be skeptical of too-good-to-be-true offers, and of online friends who need money. Guaranteed investment returns, surprise prizes (you cannot win a lottery you never entered), and romantic partners you have never met in person who ask for money are classic patterns. A request to keep it secret is the loudest warning sign of all.

Part 2: Protecting your accounts and devices (strategies 7-10)

7. Use long, unique passwords. A passphrase of four or more random words (for example, "maple dishwasher river lantern") is stronger and easier to remember than a short jumble of symbols. Use a different one for every important account, especially email and banking, because a stolen password from one site is tried on all the others. A password manager is the best tool. If that feels like too much, a paper notebook kept at home is a reasonable alternative; the risk is online attackers, not a burglar.

8. Turn on two-step verification (also called multi-factor authentication). Start with your email and financial accounts. The site sends a code to your phone, or asks you to approve a prompt, whenever someone logs in from a new device. Never read that code to anyone who contacts you; a stranger asking for it is trying to break into your account.

9. Do not click links or open attachments you did not expect. Phishing messages imitate banks, delivery companies, Amazon, and Medicare. If a message says there is a problem, ignore the link and go to the website yourself or open the app. Be especially wary of anything that makes you feel panic.

10. Keep devices updated and be careful on public Wi-Fi.

•        Accept software updates on your phone, tablet, and computer; they fix security holes scammers use.

•        If a pop-up claims your computer is infected or tells you to call a number, close the window or restart the device. Never let a caller take remote control of your computer.

•        Avoid banking or shopping on public Wi-Fi in cafes, hotels, and airports; use your phone's cellular connection instead.

Part 3: Protecting your money and identity (strategies 11-15)

11. Freeze your credit. A credit freeze stops anyone from opening new accounts in your name, and by U.S. law it is free. Place one with each of the three bureaus (Equifax, Experian, TransUnion). You can lift it temporarily whenever you apply for credit. This is the strongest single defense against identity theft.

12. Turn on alerts and review statements. Set up text or email alerts for withdrawals, transfers, and card purchases above an amount you choose. Look over statements monthly. Check your credit reports for free at annualcreditreport.com. Where you can, use a credit card rather than a debit card for online purchases, since your own cash is not at stake while a dispute is resolved.

13. Guard your Social Security and Medicare numbers. Carry your Medicare card only to appointments, not every day. Do not give your Social Security number to anyone who contacted you. Create your own online account at ssa.gov so no one else can set one up in your name, and ask the IRS about an Identity Protection PIN.

14. Secure your mail and paper. Mail theft is a common route to identity theft. Use a locking mailbox or drop outgoing mail at the post office, shred statements and pre-approved credit offers, and consider the free USPS Informed Delivery service, which emails a preview of mail due to arrive.

15. Name a trusted person. Tell a family member, friend, or advisor what these scams look like, and give your bank or brokerage a "trusted contact" they can call if something looks wrong (financial firms are required to ask for one). Agree that you will always show them anything involving urgent money requests before acting. Being targeted is not a failure of judgment; asking for a second opinion is.

If you think you have been scammed

Act quickly, and do not be embarrassed: reporting early is the best chance of getting money back, and it protects others.

1.    Call your bank or card issuer right away using the number on the card. Ask them to stop or recall payments; wire transfers are sometimes recoverable within hours.

2.    Stop all contact with the scammer. Do not pay any "fee" to recover lost money; that is a second scam.

3.    Change passwords on affected accounts, starting with email, from a device you trust. If a stranger had remote access to your computer, ask a trusted person to help check it.

4.    Place a credit freeze or fraud alert with the credit bureaus if personal information was shared.

5.    Report it. Reports help investigators and are often needed for disputes.

One-Page Cheat Sheet (keep by the phone)

STOP. HANG UP. CALL BACK ON A NUMBER YOU TRUST.

•        Real emergencies survive a ten-minute pause.

•        No honest organization demands gift cards, wire transfers, crypto, or secrecy.

•        Never share a code sent to your phone, a password, or a Social Security number with someone who contacted you.

•        Never let a caller control your computer.

•        Do not click links in unexpected messages; go to the site yourself.

My safety checklist

Family code word: ______________________________

Trusted person to call: ______________________________

Bank fraud number (on my card): ______________________________

☐ Credit freeze at:   ☐ Equifax    ☐ Experian    ☐ TransUnion

☐ Two-step verification on:   ☐ Email    ☐ Bank    ☐ Medicare / Social Security account

If it happened: call the bank first, then report at ReportFraud.ftc.gov or call 1‑833‑372‑8311.

Handout: Getting Started with a Password Manager

A password manager remembers your passwords so you only have to remember one. It is the easiest way to follow strategy 7.

Easy options

•        Built-in manager (Apple Passwords or Google Password Manager): free, already on your phone or browser. Best if you stay with one kind of device.

•        1Password: clear layout, works on every device, good emergency-access features. Paid, with family plans.

•        Bitwarden: open-source and independently audited, with a capable free tier.

•        Proton Pass: privacy-focused, with a free tier.

How it works

1.    Create one strong master password: a passphrase of four or more random words.

2.    When you log in to a website, the app offers to save the login. Say yes.

3.    Next time, tap the app's suggestion and it fills in your username and password.

4.    For a new account, tap "suggest password" and the app creates and saves a long random one.

5.    Start with your email, bank, and Medicare or Social Security logins, then add others over time.

How to never get locked out

•        Write the master password on paper and keep it in a safe place at home, apart from your devices.

•        Print and keep the recovery items the app gives you at setup (such as 1Password's Emergency Kit). The company usually cannot reset a lost vault.

•        Turn on fingerprint or face unlock for daily use, but still type the master password now and then so you remember it.

•        Install the app on two devices (phone plus computer or tablet) so there is always a synced copy.

•        Set up emergency access or a legacy contact (offered by 1Password, Bitwarden, Apple, and Google) so a person you trust can get in if you cannot.

•        Keep your email address and phone number on the account up to date.

•        Do not export passwords to a plain spreadsheet; that file is unprotected.

When to change a password

No schedule needed; forced changes produce weaker passwords. Change one only if:

•        A company reports a breach affecting your account.

•        You see suspicious activity, or gave it to a scammer or a fake site.

•        Your manager flags it as weak or exposed, or a device was lost or stolen.

Change your email and bank passwords first.

My master password is written down and stored at: ______________________________

Handout: Is My Password Manager Safe? Your Master Password

A password manager keeps your passwords in an encrypted vault that only your master password can open. If the company is ever breached, thieves get the encrypted vault, not your passwords. Whether they can open it depends almost entirely on your master password.

Choosing a master password

•        Length beats complexity. Use five or six random words. Four is the minimum.

•        Numbers and symbols are not required. Current U.S. government guidance (NIST) favors length over special characters, because people add them in predictable ways (an "@" for "a," or a "!" at the end). If a site insists on one, add a number and a symbol to the end of your long passphrase.

•        Let chance pick the words. Use your password manager's generator, or roll dice with a published word list such as the EFF's. Words you choose yourself, and song lyrics, quotes, birthdays, or pet names, are easy to guess.

•        Make it unique. Never use it anywhere else.

•        Never share it. No real company, bank, or support agent will ever ask for it.

Protecting your vault

•        Choose a manager with independent security audits and a good record of handling problems.

•        Keep irreplaceable secrets, such as cryptocurrency recovery phrases, out of the vault.

•        Beware fake login pages asking for your master password. Open the app or type the web address yourself.

•        Keep your devices updated and locked with a PIN or fingerprint.

•        Turn on two-step verification for your password manager account.

 

Handout: Two-Step Verification Made Easy

Two-step verification (also called two-factor or multi-factor authentication) means a thief who steals your password still cannot get into your account without a second item that only you have, usually your phone. It is strategy 8.

Passkey ("sign in with fingerprint or face")

Unlock with your fingerprint, face, or phone PIN. No password to type.

Very strong; cannot be tricked by a fake website. Easiest option when offered.

Phone prompt

Tap "Yes, it's me" on a notification from the app or your phone.

Strong.

Authenticator app (Microsoft or Google Authenticator)

Type the 6-digit code shown in the app, which changes every 30 seconds.

Strong; works without cell service.

Text-message code

Type the code texted to your phone.

Weakest of the five, but far better than nothing. Use it if it is the only choice.

Physical security key

Plug in or tap a small key.

Strongest. Buy two and keep one in a safe place.

About passkeys: a passkey is a secret digital key stored on your phone, computer, or password manager. Your fingerprint, face, or PIN only unlocks it on your own device. The website never sees or receives your fingerprint or face.

In a large Google study (2019, with NYU and UC San Diego), a text code blocked 96% of bulk phishing and 76% of targeted attacks. Phone prompts blocked 99% and 90%, and no one who used only security keys fell victim to targeted phishing.

Which to pick: go down the list and use the first method the website offers that you are comfortable with. A phone prompt or text code is a fine start.

Turn it on first for: your email, your bank and credit card accounts, your password manager, and your Social Security account (through Login.gov or ID.me). In each site's settings, look for "Security," "Sign-in," or "2-step verification."

Rules that keep it safe

•        Never read a code to anyone who calls or messages you, and never approve a prompt you did not start. If an unexpected prompt appears, tap "No" and change that account's password.

•        When you set it up, save the backup codes. Print them and keep them with your master password. For lower-risk accounts, storing the codes in your password manager is fine; keep paper copies for your email and bank.

•        Add a second method where possible (for example a phone prompt plus backup codes), so losing one phone does not lock you out.

•        Before replacing your phone, set up the new one first and keep the old one until every account works on it.

•        Keep your phone number and email on each account up to date.

Ellen Colodney