Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To secure online shopping accounts, use a different password for every retailer and enable two-factor authentication (also called two-step verification or multifactor authentication) wherever it is offered. A password manager can generate and save unique passwords; for the extra sign-in step, prefer a security key or authenticator app when supported. These steps help protect account access, order history, saved addresses, and payment-related details.

Why online shopping accounts need unique passwords

If you reuse a password, a criminal who obtains it from one service can try the same credentials on other accounts. A distinct password for each store limits that risk: one exposed password does not automatically unlock your other retailer accounts.

NIST recommends using a password manager for accounts that require passwords. A manager can generate and store a different password for each store, so you do not have to memorize them all. If you create a password yourself, NIST advises at least 15 characters; a long passphrase made from random words can be easier to remember. That is guidance for password-required accounts, not a guarantee that every retailer accepts passwords of that length. NIST’s password guidance

How to secure an online shopping account

  1. Use a unique password. Generate a separate password for the retailer in your password manager. If you already reused that password elsewhere, replace it on each affected account with a different one.
  2. Turn on multifactor authentication. Sign in to the retailer’s website or app and open its security, sign-in, or account settings. Look for “two-factor authentication,” “two-step verification,” or “multifactor authentication.” Follow the retailer’s prompts to enroll and save any recovery codes it provides somewhere secure.
  3. Choose the strongest option the retailer supports. A FIDO-compatible security key or authenticator app is preferable to a text or email code when available. The exact methods and labels vary by retailer; check the current account settings rather than assuming a particular store offers a method.
  4. Review recovery details. Check which email address, phone number, and trusted devices can be used to recover or approve access to the account. Use unique answers for security questions; where possible, avoid answers that others could find in public records or on social media.
  5. Secure the email account used for recovery. Give that inbox its own unique password and turn on MFA. If a retailer sends sign-in codes or recovery links by email, access to the inbox can affect the security of the shopping account.

Official guidance includes a FTC overview of protecting personal information, the FTC guide to two-factor authentication, and CISA’s consumer steps for turning on MFA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which two-factor authentication method should you use?

Method What to know Practical choice
Physical security key or FIDO sign-in Provides strong phishing resistance when the service and device support it. A key cannot protect an account if the retailer does not support the method. Prefer it when offered. Check compatibility and keep recovery options current. CISA’s MFA guidance
Authenticator app FTC guidance ranks authenticator apps above text or email codes. Prefer it when a security key is unavailable and the retailer supports an app.
SMS or email code Adds a sign-in step beyond the password, but FTC guidance places these below security keys and authenticator apps. An email code depends on the security of the receiving inbox. Use it rather than leaving the account password-only if stronger methods are unavailable. Protect the phone number and email account used to receive codes.
No MFA option shown Retailer offerings differ, and a method may not be available for every account. Keep a unique generated password, secure the recovery email, and ask the retailer whether MFA is available.

FTC and CISA explain the differences between MFA methods in their FTC account-protection guidance and CISA MFA guidance. CISA’s MFA material is aimed in part at organizations, so treat its method hierarchy as general guidance rather than a guarantee about any retailer’s implementation.

Protect your password manager

A password manager holds credentials for many accounts, so protect the vault itself. Use a strong master passphrase, enable MFA for the manager if it offers it, and understand how recovery works before you need it. Check that the manager supports your devices and browsers, and review how its provider handles account recovery and security. CISA offers guidance on using password managers to create and store strong passwords.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How to avoid phishing when signing in

MFA does not make a fake sign-in page safe. Do not follow a login link in an unexpected text or email. Instead, open a saved bookmark you recognize or type the retailer’s address yourself, then sign in there. A phishing-resistant security key or FIDO method can prevent credentials from being entered on a fake site when the retailer supports it; ordinary codes may still be tricked or stolen.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if the retailer does not offer MFA

Use a unique password generated by a password manager and secure the email account used for recovery with a separate password and MFA. Review the retailer’s recovery email, phone, and trusted-device settings, and contact its support team to ask whether MFA is available. Do not assume that the same options exist across all retailers.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.