Credit cards usually provide stronger dispute handling than debit cards. Report identity theft and build a recovery plan at IdentityTheft.gov.
One reused password is the thing most likely to ruin your week.
You reused one password for fifteen years. Let's fix the thing most likely to actually ruin your week. You don't need to be a hacker to be safe - you need to stop doing the two or three things that get normal people wrecked. Reusing one password everywhere is the big one, because when any site gets breached (and they do, constantly), that one password unlocks your whole life.
Passwords, the easy way
- Use a password manager - it invents and remembers a different strong password for every site, and you memorize just one master password. This single change fixes most of the problem.
- Turn on two-factor (2FA) - that second code from an app or text means a stolen password alone isn't enough. Put it on your email, bank, and main accounts at least.
- Guard your email hardest - it's the master key; whoever controls your email can reset the password on everything else.
Spotting a phishing scam
Phishing is a fake message pretending to be your bank, a delivery service, or a game, trying to panic you into clicking or logging in. The tells: urgency ("your account will be closed!"), a link that goes to a slightly-wrong address, and a request for info a real company already has. No legitimate company will ever ask for your password or your 2FA code. When in doubt, don't click the link - go to the site directly.
One power move
Lock down the recovery path. Save backup codes somewhere offline, review account-recovery details, and learn your country's official identity-theft and credit-file protections before you need them.
The official source where you live
Services and numbers change over time. If one of these is wrong or missing for your country, telling us is worth more than anything else on this page.
Credit-card disputes and consumer rights are split between federal and provincial rules. Report fraud to your financial institution and the Canadian Anti-Fraud Centre.
Card purchases may have chargeback or statutory protection depending on how and how much you paid. Report fraud to your bank and the UK's official fraud-reporting route.
Use card or platform protections and report scams to your bank and Scamwatch. Do not send money by gift card, crypto, or transfer to an unverified seller.
Use protected payment options, keep evidence, and report online scams through Netsafe, your bank, and Police where appropriate.
Card and consumer protections come from Irish and EU rules. Contact your bank quickly after fraud and report scams to Gardaí where appropriate.
Payment-dispute and identity-theft protections differ by country. Use a protected payment method, keep receipts, and follow your national cyber-safety agency after fraud.
The questions people actually ask
What is the single most important security fix?
Stop reusing passwords. One breach at one forgotten site is how attackers get into everything else, and reuse is what turns a small leak into a total loss.
Do I need a password manager?
It is the only realistic way to have a different strong password everywhere. You remember one, it remembers the rest, and it fills them only on the genuine site - which quietly defeats most phishing.
What is two-factor authentication and where should I turn it on?
A second proof beyond the password. Turn it on for your email first, because whoever controls your email can reset every other account you own, then your bank and your main gaming and social accounts.
Is SMS two-factor good enough?
It is far better than nothing and worse than an app. SIM-swap attacks target text messages specifically, so an authenticator app or a hardware key is a real upgrade where it is offered.
What do I do after a breach?
Change that password everywhere it was reused, starting with email and banking, and turn on two-factor while you are in there. Check whether the account offers a session log and sign out everything you do not recognize.
If this one found you
Shopping Online Without Getting Scammed
The internet is a great mall and a great con. A few habits keep you on the safe side.
Doxxing: When Your Real Info Gets Put on Blast
Your name, address, or workplace posted for strangers to see. Here's what to do in the first hour, and after.
Sextortion: The Scam That Moves Fast and Feeds on Panic
It usually starts with a compliment and ends with a threat within the hour. Speed is the whole trick - so is knowing what to do before it happens.
Nobody is born knowing any of this
School skipped it, and everyone else is quietly working it out too. The rest of the guides are free, plain-language, and take about five minutes each.