Here's an uncomfortable truth: the odds that you or someone you know will be targeted by fraud this year are higher than ever. Americans reported losing $15.9 billion to fraud in 2025, according to the Federal Trade Commission.* That's up 25% from the year before. The FBI's Internet Crime Complaint Center (IC3) paints an even bigger picture, with total losses topping $20.8 billion and cyber-enabled fraud responsible for 85% of it.**
So what's actually letting criminals in? Most often it comes down to something as basic as a password. Compromised credentials were the top way attackers broke into networks last year, showing up in 22% of confirmed data breaches.1 And account takeover, when a criminal simply logs in with a stolen password instead of tricking anyone into wiring money, cost consumers over $15 billion last year and hit 6 million people.2
Here's the part that should make you feel a little better: fixing this is genuinely one of the easier problems in personal security. A handful of changes to how you log in can shut most of these attacks down before they start.
The reuse problem nobody wants to admit to
Most people juggle dozens of accounts and end up reusing the same password, or a slight variation of it, across half of them. Criminals count on this. It's called credential stuffing: once your password leaks in a breach at some random retailer or app, bots quietly test it against banking sites, email providers and everything else. Fewer than half of a typical person's passwords across different services are actually unique. One leak, in other words, can unlock a lot more than you'd think.
Password rules just changed
If you still think a strong password means a chaotic mix of symbols, numbers and one capital letter shoved in somewhere, the rules changed on you. In 2025, the National Institute of Standards and Technology finalized new guidance that overhauled advice that had been around for roughly 20 years. A few highlights:
- Length beats complexity now. Passwords of at least fifteen characters are recommended. A random string of unrelated words tends to be far harder for a computer to crack than a short, symbol-heavy password.
- Forced password resets are also on their way out. Changing a password every 90 days for no reason tends to produce weaker, more predictable choices, not stronger ones, so it is now recommended to change only when there’s a breach.
- New passwords should also be checked against lists of previously leaked credentials before they're even accepted, which closes off one of the easiest ways in.
- Since nobody is memorizing a unique 15-character phrase for 40 different logins, a password manager isn't optional anymore. It's the only realistic way to pull this off.
Multi-factor authentication does most of the heavy lifting
Here's the single most effective thing you can do, and it takes about 30 seconds to set up. Multi-factor authentication (MFA) cuts the risk of account compromise by 99.22%, and it still blocks 98.56% of attacks even when the attacker already has a valid stolen password.3 Even if your password gets leaked somewhere, that extra text code, app prompt or facial recognition check is very likely to stop a criminal cold.
One step past MFA is skipping the password completely with a passkey. Passkeys let you sign in with the same fingerprint, face scan or PIN you already use to unlock your phone, and because there's no password sitting in a database somewhere, there's nothing for a criminal to phish or steal in a breach.
What this actually looks like day to day
- A unique passphrase, 15 characters or more, for every account that matters, stored in a password manager rather than your memory or a sticky note.
- Multi-factor authentication turned on everywhere it's offered, especially banking, email and anything tied to your finances.
- Use of a passkey instead of a password wherever one is available.
- Alerts turned on for logins and transactions, so you find out about suspicious activity when it happens.
- No password recycling. Ever. Especially not between financial accounts and hardly used apps.
If something feels off
If you notice a log in you don't recognize or a transaction you didn't make, call your bank immediately, change that password on the spot and turn on MFA if you haven't already. It's also worth filing a report with the FTC. Reports like these are exactly how investigators spot patterns and eventually catch the people running these schemes.
Fraud isn't going away, and the people behind it aren't running out of new tricks. But the fix for a lot of it is surprisingly unglamorous: a longer passphrase, a second login step and, where you can get it, a passkey instead of a password. None of that takes long to set up. All of it makes you a much harder target.
** https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
1Verizon's 2025 Data Breach Investigations Report
2Javelin Strategy & Research's 2026 Identity Fraud Study
3Security Boulevard