Situation report active Rev. 2026.9 119 reports 239 source records updated
Real Life After AGI Pengarahan kelangsungan hidup manusia
ID

Digital identity hardening: a household checklist

A household checklist for protecting email, phone numbers, financial accounts and identity records from AI-assisted impersonation and account takeover.

Written by
Dwight Ringdahl
Status
Sumber diperiksa
Revised
Sources
8 cited
Reading
7 min
Belum tersedia dalam Bahasa Indonesia

Laporan ini belum diterjemahkan, sehingga naskah asli berbahasa Inggris ditampilkan di bawah. Lihat halaman metodologi untuk mengetahui cara cakupan terjemahan dilacak.

Protect the accounts that can reset everything else

Digital identity is not one account. It is the chain connecting your primary email, phone number, device-unlock code, financial accounts, cloud storage, health portals, tax records, and account-recovery methods. An attacker who takes over the primary email address may be able to reset several other accounts without defeating their passwords. AI can make phishing and impersonation faster and more polished, but the most useful defenses remain ordinary security controls: unique credentials, phishing-resistant sign-in, secure recovery, updates, and a practiced verification habit. CISA groups strong passwords, multifactor authentication, phishing recognition, and software updates as its core consumer actions.

Scope and limits

This is general guidance for U.S. households, not individualized legal, financial, or cybersecurity advice. People facing stalking, domestic abuse, targeted harassment, or a compromised device may need a safety plan with a qualified advocate or security professional before changing accounts, because abrupt changes can alert an abuser.

Start with the accounts that control recovery: primary email, platform account, mobile carrier, password manager, and financial accounts. Then cover lower-value services. This ordering reduces the chance that weak recovery defeats stronger protection elsewhere.

Use a password manager, then remove reuse

Use a reputable password manager to generate and store a different password for every account. The practical goal is not to memorize dozens of complex strings; it is to make one breach useless against every other service. Protect the manager with a long, unique master password and its strongest available multifactor option. Do not place the master password in an unencrypted note beside the recovery codes.

Change the highest-consequence accounts first, then update reused passwords as you encounter them. If a service reports a breach, change the credential through its known app or typed address rather than a warning-message link. For shared access, prefer separate service logins or a password manager’s family-sharing feature over texting a password.

Prefer passkeys or security keys, with recovery planned

Passkeys and FIDO/WebAuthn security keys are designed so the credential is bound to the legitimate site. Properly configured passkeys are phishing-resistant because a fake domain cannot capture a reusable secret for the real one; NIST describes that verifier-name binding and also explains the tradeoffs of synced passkeys. This makes them a strong choice for email, password managers, cloud accounts, and financial services when offered.

“Passkey” does not always mean a separate hardware key. A passkey may be held on one device, synced through a platform account, or stored on a physical security key. Synced passkeys improve usability and recovery across devices, but the platform account and its recovery process then become part of the security boundary. A hardware key can reduce dependence on that sync account, but a single key can be lost or damaged. For a high-value account, register at least two authenticators if the service permits it: keep one available and a backup in a secure, separate location.

Do not delete an existing sign-in method until you have tested the new method in a separate session and reviewed recovery. Save one-time recovery codes offline in a locked location. Check whether adding a new authenticator generates an alert, whether old sessions can be revoked, and which phone numbers or email addresses can reset the account. NIST’s current authenticator guidance treats recovery as its own lifecycle event, not an afterthought.

If passkeys are unavailable, use the strongest MFA the service supports. An authenticator app or hardware token generally avoids some weaknesses of SMS. SMS is still usually better than a password alone, but it is not phishing-resistant and depends on the security of the phone account. Add a carrier account PIN, enable any available port-out or SIM-swap lock, and never read a one-time code to an unsolicited caller. A real support agent should not need the code that authorizes a login.

Harden recovery and devices

Review account-recovery settings twice a year and after a phone-number, email, relationship, or household change. Remove former work addresses, old numbers, unknown devices, stale app passwords, and people who should no longer have recovery access. Use a recovery contact only if that person understands the responsibility and can protect their own account.

Turn on automatic updates for phones, computers, browsers, password managers, and security software. Use a device passcode that is not a birthday or repeated digit, enable full-device encryption where available, and configure the device to lock quickly. Hide message previews on the lock screen if they expose login codes or private information. Back up important data using a tested method, but remember that a cloud backup is accessible through its cloud account; secure that account accordingly. For the router configuration, network segmentation, and connected-device hardening that sit behind these accounts, see Home Network and Device Security.

Reduce identity exposure without chasing invisibility

Private social-media settings reduce casual exposure but do not make a post private forever. Remove public birth dates, home addresses, routine locations, schools, travel dates, relatives’ names, and phone numbers when they do not need to be public. Ask relatives before tagging children or publishing clear voice and face recordings. The goal is to make a convincing pretext harder to assemble, not to promise that cloning becomes impossible.

People-search sites compile data from public records, social media, and other brokers. The FTC explains how to find a site’s opt-out process, but opt-outs are incomplete and may need repeating. Use a dedicated email address for removal requests, provide only the verification data actually required, and keep a dated list of completed requests. Do not upload identity documents casually to an unfamiliar “removal” service.

Freeze credit where appropriate

A credit freeze limits access to a credit file and can make it harder to open new credit in that person’s name. It does not stop takeover of an existing account, misuse of a bank balance, tax fraud, medical identity theft, or every form of identity fraud. In the United States, freezes are free, must be placed with each nationwide credit bureau separately, and can be lifted when legitimate credit is needed. Protect the bureau accounts and freeze-management credentials.

Parents and guardians can request a freeze for a minor. A child generally should not already have a credit file; IdentityTheft.gov provides the bureau-specific process for checking and freezing a child’s file. Store the resulting records securely because they contain identifying information.

Credit monitoring can alert you after a file changes; it does not prevent the change. Review bank and card alerts as well, and obtain credit reports through AnnualCreditReport.com, the federally authorized source, rather than a look-alike site reached through an ad.

Give the household a transaction rule

Technology cannot determine whether a real-looking request is legitimate. Establish a rule that no unexpected request for money, credentials, recovery codes, remote computer access, or secrecy is acted on in the same conversation. End the contact and verify through a number, app, or in-person route already known to be genuine. A family verification phrase can help, but do not use a fact visible online, and do not treat the phrase as authorization to transfer money. A callback and second person’s review provide stronger confirmation.

Teach the protocol to everyone authorized on an account. For major transfers, ask the bank about alerts, limits, or second approval.

If identity theft or takeover occurs

Act from a device you have reason to trust. Contact the affected institution through a statement, card, or official website; change exposed credentials; revoke unknown sessions; and preserve messages, transaction details, and timestamps. If identity information was misused, IdentityTheft.gov creates a tailored recovery plan and FTC Identity Theft Report. Report cyber-enabled crime to the FBI’s Internet Crime Complaint Center when appropriate, but type the address directly because the FBI has warned about spoofed IC3 sites.

Do not pay a “recovery agent” who promises to retrieve stolen money for an advance fee. Recovery depends on the payment method and speed of reporting. Contact the bank, card issuer, transfer service, or gift-card issuer immediately and ask whether it can stop or reverse the transaction; the FTC lists the correct first contact for each payment type.

A workable first weekend

  1. Secure primary email and the password manager with unique credentials and phishing-resistant MFA.
  2. Register and test a backup authenticator; print or securely record recovery codes.
  3. Lock the mobile-carrier account and review account-recovery addresses, numbers, sessions, and devices.
  4. Enable automatic updates and device encryption on every supported household device.
  5. Freeze credit for household members who do not need frequent new-credit access.
  6. Agree that unusual money or credential requests always require an independent callback and a second look.

No checklist makes identity theft impossible. The realistic outcome is to remove common entry points, contain compromise, and make recovery faster.

Type to search the manual.

navigate open esc close