Your bank login is the one password a criminal wants most, and it is often the one people guard least. They will spend an hour picking the perfect Netflix password and then log into their savings with “Summer2019” from three different laptops.

Securing online banking is not complicated. It is four or five settings, most of which you flip once and never touch again. Here is exactly how to do it, in the order that matters.

Key takeaways

  • Give your bank a long, unique password that exists nowhere else, stored in a password manager.
  • Turn on two-factor authentication, and use an app or a passkey instead of text codes where possible.
  • Always reach your bank through its official app or a typed address, never a link in a message.
  • Lock down the email tied to your bank, because it can reset your banking password.
  • Set alerts so a login from a new device or a big transfer pings you instantly.

Start with a password that exists nowhere else

The most common way bank accounts get taken over is not a clever hack. It is a reused password. A site you barely remember gets breached, your email and password leak, and thieves try that same combination on banking sites.

hand holding phone showing a banking app login screen
A unique password and a second step keep your banking login yours alone.

The fix is to make your bank password unique. Not “unique-ish,” but a string that appears on no other account you own. The only practical way to do that across dozens of logins is a password manager, which generates and remembers them for you.

If you have not set one up, it is the single best hour you can spend on your online security. It also anchors the wider plan in our overview of protecting your money and identity online.

Watch out

If your bank password is one you have used anywhere else, treat it as already compromised and change it today. You can check whether an email of yours has appeared in a known breach at haveibeenpwned.com.

Add a second step to your login

A password can leak. A second factor means a leaked password alone still cannot get in. This is the setting that stops most account takeovers cold.

Look in your bank’s app or website under Security or Sign-in settings for two-factor authentication, also called 2FA or two-step verification. Turn it on. When the bank offers choices, here is how they rank.

Which second factor to choose

Method Strength Notes
Passkey / biometric Strongest Uses your face or fingerprint, cannot be phished. Pick this if offered.
Authenticator app Strong A rotating code in an app like Google Authenticator or Authy.
Push approval Strong A tap-to-approve prompt in the bank’s own app.
Text message code Better than nothing Vulnerable to SIM swapping, but use it if it is the only option.

Many banks still default to text codes. They are far better than no second step, so turn them on if that is all your bank offers. But if you see an option for an authenticator app or a passkey, choose that instead.

A quick word on text codes: criminals can hijack your phone number through SIM swapping, then receive your codes. To blunt that, call your mobile carrier and ask for a port-out PIN on your account. It takes one phone call.

Only reach your bank the safe way

You can have a perfect password and still hand it to a thief by typing it into a fake page. Phishing pages that copy your bank down to the logo are cheap to make and land in inboxes daily.

The rule is simple: never log in from a link. If an email or text says there is a problem with your account, do not tap the link. Open the bank’s official app, or type the address into your browser yourself, and check from there.

A habit I recommend to everyone is bookmarking the real login page and using only that bookmark. It removes the daily judgment call about whether a link is real.

Tip

Save your bank’s real phone number, the one on the back of your card, in your contacts. Then if you ever need to call about fraud, you dial a number you trust instead of one from a suspicious message.

Protect the email behind the account

Here is a gap people miss. Even a perfectly secured bank login can be reset by whoever controls your email inbox, because that is where the reset link goes.

So your email deserves the same treatment: a unique password and 2FA of its own. If your inbox is protected with a weak or reused password, you have essentially left the back door open while bolting the front.

Treat your primary email as a top-tier account. It sits above your bank in the chain, and it is worth every minute you spend on it.

Turn on login and transaction alerts

The final layer is early warning. Most banks can notify you when someone logs in from a new device, changes your contact details, or moves money above an amount you set.

Switch these on. A login alert you did not trigger is your cue to act before any money moves. We cover the full menu of notifications in our guide to setting up bank and card fraud alerts, including which ones are worth the buzz.

And if the worst happens and someone does get in, do not panic. There is a clear path to regain control in our walkthrough on account takeover recovery steps. Knowing the plan exists takes the fear out of it.

Watch your device and network too

Keep your phone and computer updated, since banking apps rely on the operating system’s security. Avoid logging into your bank on shared or public computers, and be cautious on open Wi-Fi in cafes and airports.

If you must bank on the move, use your phone’s mobile data instead of open Wi-Fi. Your carrier connection is much harder for a stranger nearby to snoop on than a coffee-shop network.

Your afternoon checklist

  • Set a long, unique password on your bank account using a password manager.
  • Turn on two-factor authentication and pick an authenticator app or passkey over text codes.
  • Call your mobile carrier and add a port-out PIN to block SIM swapping.
  • Give your primary email its own unique password and 2FA.
  • Bookmark your bank’s real login page and stop reaching it through links in messages.
  • Switch on alerts for new-device logins, contact changes, and large transactions.
  • Save your bank’s real phone number in your contacts for fraud calls.
  • Update your phone and computer, and avoid banking on public Wi-Fi.

Do this once and your banking login goes from a soft target to a hard one. The thief moves on to someone easier, which is exactly the outcome you want.