Forget 200 Passwords. Three Accounts Actually Matter.
Last verified: August 3, 2026
Linda is 54. She's a bookkeeper in Ohio, which means she's more careful with numbers than most people alive.
In March, someone logged into her credit union account and moved $8,400 into an account in another state. They didn't guess her password. They didn't need to. A craft supply store she'd ordered from in 2019 had been breached, her email and password were on a list, and a machine tried that pair on four hundred banks until one of them opened.
She'd used that same password on her email too.
The short answer
You don't need to fix 200 passwords. Three accounts control almost everything else you own: your email, your phone carrier, and your primary bank. Whoever holds those three can reset their way into the rest of your life. Lock those three properly and you've done most of the work in about thirty minutes.
The thing nobody admits
For twenty years you've been told the same thing. Use a long, unique, random password for every single account. Never write them down. Change them regularly.
The average person now has around 255 online accounts.
Human working memory holds about seven things.
Nobody has ever done what that advice asks. Not one person. Not the security experts who repeat it, not the companies that print it in their onboarding emails, not me. It was never possible. It was advice designed for a world with six accounts, repeated without revision into a world with two hundred and fifty.
So if you're sitting there with the same four passwords across everything, slightly modified, with a number on the end that goes up each time a site forces a change:
You did not fail. You were handed an impossible instruction and you improvised. That's what competent people do with impossible instructions.
The problem is that the improvisation has a specific weakness, and criminals built an industry around it.
What actually happens
Nobody is sitting in a dark room trying to guess your password. That's a movie.
What happens is duller and much worse. A company you barely remember gets breached. Your email address and password end up on a list with fifty million others. That list gets sold for the price of a sandwich. Then software takes your pair and tries it automatically on banks, email providers, retailers, and insurance portals, thousands of attempts a second, around the clock.
They don't know who you are. They don't care. You're row 4,182,559.
That's why reuse is the whole game. One password stolen from a craft store becomes a key tried on every lock you own.
You can check whether this has already happened to you. Most people find something.
Affiliate disclosure: some links below are affiliate links. If you buy through them, SPG earns a commission at no extra cost to you. It doesn't change what I recommend. I've kept the free options in here where free is genuinely the right answer.
Check whether your email is already on a list →
Account one: your email
This is the one people get wrong.
Ask most people which account matters most and they say the bank. It isn't. It's email.
Think about what happens when you forget a password anywhere. You click "forgot password." A reset link goes to your email. Whoever controls your email controls the reset link, which means they control the bank, the brokerage, the insurance portal, the mortgage servicer, and the account where your tax documents live.
Your email isn't one of your 200 accounts. It's the master key to the other 199.
What to do, in order:
- Give it a password you use nowhere else. Long beats complicated. A phrase like
harbor-tuesday-lantern-49is stronger thanP@ssw0rd!23and you can actually type it. - Turn on two-step verification. Use an app like Google Authenticator or Authy rather than text messages, for reasons that become clear in the next section.
- Check the recovery email and phone number on the account. If they point to an address you closed in 2014 or your ex-husband's phone, fix that now.
You can generate a strong passphrase here. It runs in your browser and never sends anything to us.
Account two: your phone carrier
This is the one nobody thinks about, and it's the reason I said use an app instead of text messages.
There's an attack called a SIM swap. Someone calls your carrier, pretends to be you, and says they've got a new phone. If the representative believes them, your number moves to their device. Every verification code you were counting on now arrives on a criminal's phone.
They don't need your phone. They need a bored employee at a call center.
What to do:
- Call your carrier and ask them to add a port-out PIN or account PIN to your line. Every major carrier offers this. It takes about ten minutes and it's free.
- Ask them to flag the account so no changes can be made without that PIN.
- Move your two-step codes off text messages and onto an authenticator app wherever the option exists.
That's it. Ten minutes on the phone closes a door most people don't know is open.
Account three: your primary bank
Now the obvious one, last, because the first two protect it.
What to do:
- A unique password, not a variation of anything else you use.
- Two-step verification, app-based.
- Turn on transaction alerts for anything over an amount that would ruin your week. Most people set it far too high. Set it at $100.
That third step is the one people skip and the one that matters most. The damage from account theft isn't usually the first transaction. It's the six weeks before anyone notices.
What about the other 197?
Here's where you stop doing this by hand.
A password manager is one app that remembers every password for you. If you want a full comparison first, see the best password managers for 2026. You memorize one master password. It generates and fills the rest, and you never think about them again. That's the entire concept.
The objection I hear most from people your age and mine is reasonable: isn't putting everything in one place dangerous?
Compare the two situations honestly. Right now you have four passwords spread across 200 accounts, sitting in breach lists, being tried against banks nightly. That's 200 unlocked doors. A password manager is one door with a deadbolt, an alarm, and encryption the company itself cannot open. With a real manager, your data is scrambled on your own device before it's uploaded, so the company stores a sealed box it has no key to.
The math isn't close.
Two options I'd stand behind for someone who isn't technical:
NordPass. The one I'd set up for my own mother. It gets out of the way, the phone app works without a fight, and the family plan covers six people, which matters if you're also trying to get your spouse and your kids to stop using Fluffy2011. Around $18 a year for one person.
Proton Pass. Swiss company, open source, and there's a genuinely usable free tier if you want to try the idea before paying for it.
Both have a 30-day money-back guarantee on paid plans. Renewal prices are higher than the first-year rate, so check the terms at checkout, because I'd rather tell you now than have you find out in fourteen months.
Start by adding three accounts: email, carrier, bank. Add the rest as you naturally log into them over the next few months. Do not sit down and try to do 200 in one evening. That's the impossible instruction again, wearing a different hat.
If something has already happened
If you found your email on a breach list earlier, or money has already moved, the three steps above still come first. They stop the bleeding. But you'll also want to know if your information is being used elsewhere, because stolen data gets resold for years.
Monitoring services watch for your details appearing in new breaches, on dark web markets, and in credit applications, and alert you when they do. Coveron (from the same company as NordPass) covers identity monitoring with restoration support if something does happen. Surfshark Alert is the lighter, cheaper option if you mainly want breach notifications.
Whether that's worth paying for depends on your situation. If you've been breached once and nothing came of it, probably not yet. If money has actually moved, or you're managing things for an elderly parent, it usually is.
The part people put off
One more thing, and it's the one I get the most email about.
If something happened to you tomorrow, could your spouse get into your accounts? The bank, the insurance, the photos, the utility logins, the email that all of it resets through? (For the longer version, see what happens to your accounts when you die.)
For most families the answer is no. Not because of any security failure, but because the whole system is designed to keep exactly that from happening. Grieving families spend months on the phone with call centers proving they're allowed to exist.
Every serious password manager has an emergency access feature: you designate someone, and if you don't respond within a waiting period you set, they get in. Setting it up takes about five minutes and it's the single kindest thing on this list.
If you want to work through the whole picture properly, every account you own, who can reach it, what happens if you can't, the 30-Minute Digital Life Audit walks you through it in one sitting. It's $9, and there's a free 5-page starter if you'd rather see it first.
Where you'll be in thirty minutes
Not "more secure." Something more specific than that.
Thirty minutes from now, you'll have one password to remember instead of pretending to remember two hundred. Your email will be locked, which means the resets are locked, which means the rest of it is locked. Your phone number can't be stolen by someone with a convincing voice. Your bank will text you before a stranger empties it, not six weeks after.
And the low-grade guilt you've been carrying since roughly 2011 about not having dealt with this. That's gone too. That one's worth more than people expect.
Three accounts. Email, carrier, bank. Start with email.
Frequently asked questions
Which account should I secure first?
Your email. Every other account's password reset goes through it, so whoever controls your email can reset their way into your bank, insurance, and everything else. Give it a unique password and turn on app-based two-step verification.
Is it safe to keep all my passwords in one app?
Yes, and it's safer than the alternative. Reputable password managers encrypt your vault on your own device before uploading it, so the company cannot read your passwords even if its servers are breached. Compare that to reusing four passwords across 200 accounts, where a single breach anywhere exposes all of them.
What is a SIM swap and how do I prevent it?
A SIM swap is when someone convinces your phone carrier to move your number to their device, letting them receive your verification codes. Prevent it by calling your carrier and adding a port-out PIN to your account, and by using an authenticator app instead of text messages for two-step verification.
How much does a password manager cost?
Around $18 a year for a single user on most paid plans, with family plans covering up to six people for roughly $40 a year. Proton Pass and Bitwarden offer free tiers. Introductory prices are usually lower than renewal prices, so check the renewal rate before you buy.
What happens to my accounts if I die?
By default, your family likely cannot access them, and proving they're entitled to often takes months. Most password managers include an emergency access feature that lets you designate someone who can request access after a waiting period you set. It takes about five minutes to configure.
Do I need identity theft protection?
It depends on your situation. If your email has appeared in a breach but nothing came of it, basic breach monitoring is usually enough. If money has actually been taken, or you're managing affairs for an elderly relative, monitoring with restoration support is generally worth the cost.