The rise of AI tools has made account takeovers more personal. Scammers now clone voices, create deepfake video calls, and send phishing emails that sound like your boss or your bank. If they get one password, they do not stop there. They test it across your email, your bank, your social accounts, and your cloud storage. This checklist gives you a calm, clear path to lock every door. You can do this in one afternoon. Start with the basics and work down the list.

Many people think they are too small to target. That is not true. Automated AI attacks scan millions of logins at once. They do not care who you are. The FBI Internet Crime Complaint Center reported over $12.5 billion in losses in 2023. You cannot stop every attack, but you can make your accounts a hard target. Hard targets get skipped. This checklist shows you how to become one.

The good news is that most account protection is free and simple. Unique passwords, two-factor authentication, recovery keys, and app permission reviews do not ask for special skills. They ask for 20 minutes per account. You can work through this guide slowly. No one expects perfection. Even fixing one weak login makes a real difference. We will walk through each step with concrete actions.

Before you start, try not to panic if you already clicked a suspicious link or shared a code. Move forward with this checklist anyway. Securing your accounts now can stop a scammer who is already inside. You can also learn how to recognize AI phishing emails before they trick you again. Let us begin.

How Do You Build an Account Security Checklist That Stops Scammers?

  1. Start with your email account.

Your email account is the master key. Password reset links for almost every other service land there. If a scammer owns your email, they can take over your bank, your social media, and your cloud storage without knowing those passwords. Start here before you touch anything else. This step is the highest leverage move.

Log in to your email on a trusted device. Go to security settings. Find ‘Active sessions’ or ‘Devices’. Sign out every device you do not recognize. Then change your password. Use a long passphrase with at least 16 characters. Avoid names, birthdays, and common words. A passphrase like ‘frog window blue kettle’ is easier to remember and hard for AI tools to guess.

Use a password manager to generate a truly random password instead. Password managers create and store unique logins for every site. You only remember one master password. This solves the biggest problem: password reuse. Most breaches start because one reused password was leaked. If you reuse a password, you hand scammers a key that fits many doors.

Do not just add a number to an old password. Attackers use AI to predict common patterns. They know ‘Summer2024!’ becomes ‘Summer2025!’ after a forced change. Change to something completely new. After you update the password, move to two-factor authentication. That is the next step. A strong password helps, but it is not enough on its own.

Hands typing a new password on a laptop at a clean home desk with a notebook nearby.
Photo by Pexels
  1. Turn on two-factor authentication everywhere.

Two-factor authentication adds a second lock. Even if someone steals your password, they still need a code from your phone or a hardware key. According to CISA, enabling multi-factor authentication can prevent over 99% of automated account compromise attacks. That is one of the highest returns for five minutes of work. Turn it on for email first, then banking, then social media.

Open security settings on each account. Look for ’two-factor authentication’, ‘2FA’, or ‘multi-factor authentication’. Choose an authenticator app like Google Authenticator, Authy, or Microsoft Authenticator. Scan the QR code shown on screen. The app will generate a six-digit code that changes every 30 seconds. Enter the code to confirm setup. Most services then show backup codes. Save those codes offline.

Some people prefer SMS codes because they are familiar. SMS is better than nothing, but it has a weak spot. Scammers can hijack your phone number through a SIM swap. That lets them receive your codes. An authenticator app stays on your device and does not rely on your phone carrier. Use SMS only when it is the only option. Then plan to switch when the service adds app support.

Be very careful about approving login requests you did not start. Scammers now use AI deepfake video or voice calls to pressure you into reading a code aloud. A real company will never call and ask for your 2FA code. If you get an unexpected push notification, deny it. Then log in through the official app to check for suspicious activity. Never share a code with anyone, even if they sound like family.

After you enable 2FA, make a list of which accounts have it. Some services hide the option under ‘privacy’ or ’login settings’. Spend ten minutes searching each major account. The next step is recovery keys. Those are the backup that gets you back in if your phone is lost or stolen.

Close up of a hand holding a smartphone showing a six-digit authentication code on the screen.
Photo by Pexels
  1. Save recovery keys offline.

Recovery keys are a set of one-time codes that let you back into an account when you cannot use your phone. They often appear as ten codes with letters and numbers. Treat them like cash. Anyone with your recovery key can get past two-factor authentication. That is why they must be stored offline, away from your phone and computer.

When you see backup codes during 2FA setup, write them down or print them. Do not take a screenshot. Do not save them in a plain note on your phone. Do not email them to yourself. A scammer who gains access to your device or email would then have both locks. Use a small notebook, a printed page, or a locked fireproof safe for paper copies.

Make two copies. Keep one at home and one in a secure location outside your home, like a trusted relative’s safe or a bank safe deposit box. This protects you from fire, flood, or theft. If you use a password manager, many managers let you store secure notes. You can save recovery keys there if the manager itself has a strong master password and two-factor authentication. However, avoid storing both your password manager recovery key and your individual account keys in the same place.

Test one recovery key before you need it. Log out of an account where you have a backup code. Choose ‘Use recovery code’ instead of your authenticator. Enter one code. If it works, mark that code as used and cross it out. Many services rotate new codes after you use one set. This small test prevents panic later. If you lose your phone, you will know exactly what to do.

Do not skip this step because you think you will never lose your phone. Phones get lost, stolen, or broken. Scammers also try to trick phone carriers into transferring your number. Recovery keys are your emergency exit. The next part of the checklist is about app permissions. Those are the hidden doors most people forget.

  1. Audit app permissions on every account.

You may have given apps permission to read your email, post on your behalf, or see your contacts years ago. Those permissions do not expire just because you stopped using the app. A malicious or hijacked app can quietly misuse its access. Scammers build fake quiz apps, photo editors, and productivity tools that request broad account access. Once you approve, they can harvest data or send spam. Review these connections.

Go to each major account’s security settings. On Google, visit myaccount.google.com and open ‘Security’, then ‘Third-party apps with account access’. On Facebook, go to Settings, then ‘Apps and websites’. On Microsoft, check account.microsoft.com under ‘Privacy’. You will see a list of apps and what they can access. Revoke any app you do not recognize or have not used in the last 90 days. Revoke everything that seems unclear. You can always reauthorize later.

Pay special attention to apps that can read email, send mail, or access contacts. These permissions are gold to a scammer. A malicious app with email access can search for password reset links and banking alerts. It can also set up forwarding rules to steal future messages. After revoking suspicious apps, check your email forwarding settings. Make sure no unknown address is receiving copies of your inbox.

If you help a parent or older relative, walk them through this same review. Scammers often target older adults with fake tech support apps that ask for screen sharing or account access. Our guide on protecting elderly parents from AI scams has scripts you can use. The same principle applies to your own accounts: fewer connected apps means fewer hidden doors.

Repeat this audit every three months. Set a calendar reminder. When you install a new app, read what it asks for. If a free game wants access to your contacts and email, that is a red flag. Decline and find another option. Next, we will check your account recovery information and contact details.

Person checking app permission settings on a smartphone with a focused expression.
Photo by Pexels
  1. Verify recovery contact details and security questions.

Account recovery options are supposed to help you get back in. But they can also help a scammer. If your recovery phone number belongs to an old prepaid SIM or your recovery email is one you no longer check, an attacker could exploit that. Log in to your main accounts and confirm the recovery email and phone number are current and yours. Remove any number or address you do not recognize.

Security questions are another weak lock. Questions like ‘What is your mother’s maiden name?’ or ‘What was your first pet’s name?’ have answers that are easy to find. People share that kind of information on social media without thinking. Scammers use AI to scrape public profiles and guess answers. Treat security questions as extra passwords. Give false answers that no one can research. Store those false answers in your password manager.

For example, if the question asks for your first school, answer ‘purple bicycle 42’ instead of the real name. This sounds odd, but it works because it is not guessable. Just make sure you can retrieve the false answer later. A password manager makes this easy. If you do not use one, write the false answers in the same locked notebook where you keep recovery keys.

Also review who has account recovery or legacy contact access. Some accounts let you designate a trusted person to help you recover access. Make sure that person is still someone you trust. If an account has no recovery email or phone listed, add one. A missing recovery option can lock you out, and a wrong one can let a scammer in.

This step connects directly to the next one. Once your recovery details are correct, you need to check for signs that someone has already tried to use them. We will look at account activity and login alerts.

  1. Set up login alerts and check account activity.

Most major services can alert you when someone logs in from a new device or location. Turn those alerts on. In Google, go to Security, then ‘Manage devices’ and enable ‘Notify me about new devices’. In Facebook, go to Security and Login, then ‘Get alerts about unrecognized logins’. In banking apps, look for ‘account alerts’ or ‘security alerts’. Choose email and push notifications. These alerts give you early warning.

Once alerts are on, do a manual check of recent activity. On Google, review ‘Your devices’ and ‘Recent security activity’. On Facebook, look at ‘Where you’re logged in’. On Microsoft, check ‘Sign-in activity’. Look for locations you did not visit, devices you do not own, and times you were asleep. A login from another country or a browser you never use is a red flag.

If you see something strange, do not just ignore it. Sign out that device or session immediately. Then change the password for that account. Check for changes to recovery email, phone, and forwarding rules. A smart scammer often adds their own recovery option so they can come back. Remove anything you did not add. Then enable stronger 2FA if you had only SMS or none.

You should also report the suspicious activity. The FTC accepts fraud and identity theft reports. Use their online assistant to document what happened. Our guide on how to report an AI scam step by step walks you through the process. Reporting helps law enforcement track patterns and may help you recover losses.

After you handle any suspicious activity, do one more thing. Check your financial accounts and credit reports. Account takeover sometimes leads to new accounts opened in your name. The next step covers monitoring and credit freezes.

  1. Monitor accounts and freeze credit if needed.

Account security is not a one-time fix. Scammers work in cycles. You need a simple monitoring routine. Check your main email, bank, and credit card accounts once a week for transactions or messages you do not recognize. This takes about ten minutes. The faster you spot a problem, the easier it is to stop. Many banks let you set real-time alerts for purchases over a certain amount. Turn those on.

Once a month, review your credit card statements line by line. Look for small test charges. Scammers often make a tiny charge of a dollar or two to see if a stolen card works before making bigger purchases. If you see a charge you did not make, call the number on the back of your card right away. Report it as fraud and request a new card number. Banks have zero-liability protections, but only if you report quickly.

Check your credit reports at least once a year. AnnualCreditReport.com gives you free weekly reports from the three major bureaus. Look for accounts you did not open, addresses you never lived at, and hard inquiries you did not authorize. The FTC received over 1 million identity theft reports in 2023. A credit report review is your best early detection tool for new account fraud.

If you have already seen signs of account takeover or identity theft, consider freezing your credit. A freeze blocks new credit accounts in your name. It is free and does not affect your existing accounts. You can learn the exact steps in our guide on how to freeze credit to protect against AI identity theft. Lifting a freeze is quick when you need to apply for credit. This is one of the strongest moves you can make.

Keep this entire checklist handy. Run through it every few months. Update passwords after any breach notice. Review app permissions each quarter. Treat account security like brushing your teeth: boring but essential. The next section covers common mistakes that undo all this work. Avoid them and you stay ahead of most AI scam attempts.

Red Flags & Warnings

  • 🚨 Never reuse a password across your email, bank, or social accounts. One leaked password can unlock everything.
  • 🚨 Do not store 2FA backup codes in your email, phone notes, or cloud photos. Write them on paper or keep them in a locked safe.
  • 🚨 Never approve a login request or tell someone a code if you did not start the login. Real companies will not call or text you for that code.
  • 🚨 Do not answer security questions with real public details like your mother’s maiden name or first pet. Use false answers stored in a password manager.
  • 🚨 Never ignore an alert about a new device or unusual sign-in. Sign out the device, change your password, and check recovery settings.
  • 🚨 Do not click password reset links in unexpected emails. Go directly to the service’s website or app instead.

Frequently Asked Questions

What should I do first if I think my account is already compromised?

Sign out all sessions from a trusted device, change your password to a long unique passphrase, then turn on two-factor authentication. Check recovery email and phone for unknown changes. Report the incident to the FTC or the FBI Internet Crime Complaint Center.

Is SMS two-factor authentication safe enough?

SMS is better than no two-factor authentication, but it can be defeated by a SIM swap. Use an authenticator app or a hardware security key whenever possible. If a service only offers SMS, enable it and plan to upgrade when the option appears.

How often should I review app permissions?

Review connected apps on your main accounts every three months. Set a calendar reminder. Revoke anything you do not recognize or have not used in 90 days. Pay special attention to apps that can read email or contacts.

Where should I store recovery keys?

Store recovery keys offline in a locked notebook, a fireproof safe, or a bank safe deposit box. Make two copies and keep one outside your home. Do not save them as screenshots or plain notes on your phone or computer.

Can AI scammers bypass two-factor authentication?

AI does not directly brute force a well-implemented authenticator app, but scammers can trick you into approving a push or reading a code aloud. Never share a code or approve an unexpected login request. If someone calls claiming to be your bank and asks for a code, hang up and call the number on your card.

How do I report an AI scam or account takeover?

Report it to the FTC at ftc.gov and to the FBI Internet Crime Complaint Center at ic3.gov. If financial accounts are involved, contact your bank or card issuer immediately. You can also file a report with the BBB Scam Tracker to warn others.

What Should You Remember?

  • Unique password: Use a password manager to create a different long passphrase for every account, starting with email.
  • Two-factor authentication: Turn on an authenticator app for email, banking, and social media to block most automated attacks.
  • Recovery keys: Print or write backup codes and store them offline in two secure places, never on your phone or email.
  • App permissions: Revoke third-party app access you do not use every 90 days, especially apps that can read email.
  • Login alerts: Enable new device notifications and review account activity weekly for unknown sessions.
  • Credit freeze: Freeze your credit if you see signs of identity theft to stop new accounts being opened.

This article is for general educational information only and is not legal, financial, or professional security advice. Scam tactics evolve quickly, so verify current guidance with official sources like the FTC, FBI IC3, or CISA before acting. Some links may be affiliate links that support this site at no cost to you.