Protect your accounts by using a different password for every service, enabling the strongest available multi-factor authentication (MFA)—preferably a passkey or FIDO2 security key—and verifying unexpected requests through a contact method you already trust. AI can make a fake message, call, or video more convincing, but it does not change the core risk: an attacker can still trick you into giving away a password or sign-in code. No single tool makes an account immune.
What AI changes—and what it does not
AI can help scammers create convincing messages or imitate a person’s voice or appearance using publicly shared audio, video, or photos. The FBI warns that deepfakes can convincingly mimic real people saying or doing things they never did (FBI: Stay Safe Online). That makes appearance, caller ID, polished writing, and familiar-sounding voices poor proof of identity.
The credential-theft mechanism is still straightforward: a scammer may send you to a lookalike sign-in page and capture what you type. NIST explains that a strong password cannot protect you if you enter it on an attacker-controlled page (NIST: How Do I Create a Good Password?). There is no directly attributable figure in these sources showing what share of credential theft is caused by AI, so claims that AI accounts for a particular percentage or increase are not established here.
Secure accounts in the order that matters most
- Start with high-impact accounts. Secure your primary email first, then financial accounts, payment apps, social media, and any service that can reset another account’s password or expose sensitive information. The FTC recommends starting with sensitive accounts and expanding MFA to others (FTC: Use Two-Factor Authentication To Protect Your Accounts).
- Enable the strongest sign-in method each service offers. Choose a passkey or FIDO2 security key where available. If neither is offered, use an authenticator app; if SMS or email codes are the only options, turn them on rather than leaving the account protected by a password alone.
- Replace reused passwords. Use a password manager to generate and store a unique password for every account that still requires one. Choose a manager that supports MFA and protect its own account carefully: it holds access to many credentials. NIST recommends password managers for creating and storing unique passwords (NIST: How Do I Create a Good Password?).
- Review recovery details and alerts. Keep recovery email addresses and phone numbers current. If you receive a sign-in prompt you did not initiate, do not approve it. Open the service directly to check an alert; an alert alone does not prove that an account was compromised.
- Update your devices and apps. Keep your phone, computer, browser, and applications current, and install software only from trusted sources, as the FBI advises in its online safety guidance (FBI: Stay Safe Online).
Choose an authentication method you can recover
MFA adds a separate barrier beyond a password, but the methods offer different protection and have different recovery considerations. Passkeys and FIDO2 keys are designed to resist phishing; other methods can still help when stronger options are unavailable. Compatibility and recovery depend on the service, device, and implementation.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Method | Benefit | Limitation or consideration |
|---|---|---|
| Passkey | NIST says passkeys are unique to each login and cannot be easily stolen through phishing (NIST: How Do I Create a Good Password?). | Availability, synchronization, and recovery depend on the service and device implementation. |
| FIDO2 hardware security key | A physical phishing-resistant option recommended by the FBI; the FTC describes security keys as a strong two-factor method (FBI: Improve Cyber Resiliency; FTC: Use Two-Factor Authentication). | Check that your accounts and devices support the key, protect it from loss, and establish recovery options. A key does not eliminate other account risks. |
| Authenticator app | Codes avoid the SIM-swap and email-account risks associated with SMS and email codes, according to the FTC (FTC: Use Two-Factor Authentication). | A person can still be tricked into entering a code or approving a sign-in. Where available, FBI guidance advises number matching and displaying the domain, and warns against push-only approvals (FBI: Improve Cyber Resiliency). |
| SMS or email code | Better than password-only access when this is the only MFA option a service offers. | SMS codes can be exposed after a SIM swap; email codes rely on the security of the email account receiving them (FTC: Use Two-Factor Authentication). |
How to handle a suspicious message, call, or video
- Do not use an unsolicited sign-in link. Open the official app or type the service’s address yourself, then check for a security notice or password-reset request.
- Confirm unusual requests independently. If someone claiming to be a family member, employer, bank, or provider asks for a password, code, money, or urgent action, contact them using a number or channel you already know—not contact details in the message.
- Never give an unexpected one-time code to someone who contacts you. Scammers may try to use it to access your account, the FTC warns (FTC: Use Two-Factor Authentication).
- Do not treat a voice or video as identity verification. Check unusual claims using a trusted source or official confirmation. Be thoughtful about publicly sharing audio, video, and photos that could be reused to generate impersonations, as the FBI advises (FBI: Stay Safe Online).
- Report suspected internet crime. The FBI directs people to report suspected online crime to the Internet Crime Complaint Center (IC3) or a local FBI field office (FBI: Stay Safe Online).
What to do if you entered your password on a fake site
- Go to the real service directly. Use its official app or type its address into your browser; do not return through the suspicious message.
- Change the exposed password. If you reused it elsewhere, change it on every other service too, using a different password for each. The FTC advises promptly changing a password when information may have been exposed (FTC: Use Two-Factor Authentication).
- Enable or reset MFA. Choose a passkey or security key if supported; otherwise use the strongest method the service provides.
- Check account activity and recovery settings. Review recent sign-ins, confirm recovery email and phone details, and sign out other sessions if the service offers that control.
- Contact affected financial providers through a known channel. If payment or financial details may have been exposed, use a number on a card or an official statement, not one supplied in the suspicious contact.
- Use the provider’s official recovery process if you are locked out. Recovery steps vary by service. Do not trust third-party messages promising to restore access.
Passwords are not the only valuable account data. NIST’s IR 8587, finalized September 15, 2026, addresses how agencies and cloud providers protect identity tokens, access tokens, and assertions used in systems such as single sign-on, federation, and APIs (NIST CSRC: IR 8587). It is organizational guidance, not a household checklist, but it illustrates why account security also depends on providers protecting active sessions—not just passwords.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

