10 Password Mistakes That Put Your Accounts at Risk (And How to Fix Them)
Most people know they should use strong passwords — but still make the same mistakes that get accounts hacked. Here are the 10 most common errors and exactly how to fix each one.
10 Password Mistakes That Put Your Accounts at Risk (And How to Fix Them)
Every week we help customers in the Atlanta area recover from hacked email accounts, compromised online banking, and stolen identities. In almost every case, the root cause traces back to one or more of the password mistakes on this list.
The good news: every single one of these is fixable today, for free, in under an hour.
Mistake #1: Using the Same Password on Multiple Sites
This is the single most dangerous password habit, and it's also the most common. When a website gets breached — and breaches happen constantly — attackers take the leaked username/password combinations and try them on hundreds of other sites automatically. This is called "credential stuffing."
If you use the same password for your email, your bank, and your Amazon account, one breach at any of those sites puts all three at risk.
The fix: Every account needs a unique password. A password manager (see Mistake #3) makes this practical.
Mistake #2: Using Weak or Predictable Passwords
"Password123," your pet's name, your birthday, your street address — these are guessed in seconds by automated tools. Attackers use lists of the most common passwords and personal information scraped from social media.
A strong password is:
- At least 12 characters long
- A mix of uppercase, lowercase, numbers, and symbols
- Not a real word or name
- Not based on personal information
The fix: Use a passphrase — four or five random words strung together ("correct-horse-battery-staple") — or let a password manager generate a random string for you.
Mistake #3: Not Using a Password Manager
The reason most people reuse passwords is simple: it's impossible to remember 50 unique, complex passwords. A password manager solves this by storing all your passwords in an encrypted vault. You only need to remember one master password.
Good free options: Bitwarden (highly recommended), KeePass. Paid options with extra features: 1Password, Dashlane.
The fix: Pick one, spend 30 minutes setting it up, and start adding your accounts. Most password managers have browser extensions that auto-fill passwords for you.
Mistake #4: Not Using Two-Factor Authentication (2FA)
Even a strong, unique password can be stolen — through phishing, malware, or a data breach. Two-factor authentication (2FA) adds a second layer: even if someone has your password, they still can't log in without a code from your phone.
Enable 2FA on your most important accounts first:
- Email (Gmail, Outlook)
- Online banking and financial accounts
- Social media
- Amazon and other shopping accounts
The fix: Go to the security settings of each account and enable 2FA. Use an authenticator app (Google Authenticator, Authy) rather than SMS text messages when possible — SMS can be intercepted.
Mistake #5: Saving Passwords in Your Browser Without a Master Password
Chrome, Firefox, and Edge all offer to save your passwords. This is convenient, but if someone gets access to your computer — physically or through malware — they can view all your saved passwords in seconds. Chrome's saved passwords are visible in plain text at chrome://settings/passwords.
The fix: Either use a dedicated password manager instead of the browser's built-in storage, or at minimum set up a Windows login password so your computer requires authentication before anyone can access it.
Mistake #6: Using Security Questions With Real Answers
"What was the name of your first pet?" "What street did you grow up on?" These answers are often findable on social media or through a quick conversation. Attackers use them to bypass passwords entirely via account recovery.
The fix: Treat security question answers like passwords — make them up. "First pet's name: Xk7#mPqL." Store the fake answers in your password manager.
Mistake #7: Never Changing Passwords After a Breach
Data breaches are announced regularly. If a site you use gets breached and you don't change your password, attackers may have your credentials sitting in a database waiting to be used.
How to check: Go to haveibeenpwned.com and enter your email address. It will show you every known breach that included your email.
The fix: Check haveibeenpwned.com now. For every breach listed, change that password immediately — and change it on any other site where you used the same password.
Mistake #8: Using Public Wi-Fi Without a VPN
When you log into accounts on public Wi-Fi — at a coffee shop, airport, or hotel — your traffic can potentially be intercepted by others on the same network. This is less common than it used to be (most sites use HTTPS), but it's still a real risk on unsecured networks.
The fix: Use a VPN (Virtual Private Network) when on public Wi-Fi. Reputable options include ProtonVPN (free tier available), Mullvad, and ExpressVPN. Alternatively, use your phone's mobile hotspot instead of public Wi-Fi for sensitive tasks.
Mistake #9: Clicking "Forgot Password" Links in Emails
Phishing emails that mimic password reset notifications from banks, Amazon, and Google are among the most effective attacks out there. The email looks legitimate, you click the link, enter your current password on a fake site, and it's gone.
The fix: Never click password reset links in emails you didn't request. If you need to reset a password, go directly to the website by typing the address in your browser. If you receive an unsolicited reset email, log into the real site and change your password immediately — someone may be trying to access your account.
Mistake #10: Not Having a Recovery Plan
What happens if you forget your master password, lose your phone, or get locked out of your email? Without a recovery plan, you could lose access to dozens of accounts permanently.
The fix:
- Store your password manager's emergency recovery kit (most generate one) in a secure physical location
- Set up backup 2FA codes and store them safely
- Make sure your account recovery email and phone number are current on important accounts
- Consider a trusted family member who knows how to access critical accounts in an emergency
Already Been Hacked? We Can Help
If you suspect your computer has malware, your accounts have been compromised, or you're seeing signs of unauthorized access, call us. We'll scan your machine, remove any infections, help you secure your accounts, and set up proper protection going forward.
Call 404-295-2020 — flat $59 on-site service fee, we come to you anywhere in the Atlanta metro.
Explore Topics
Written by
Computer Geeks of Georgia
Content creator and writer sharing insights and stories.