Passwords and verification codes
Legitimate services do not need you to read your password to a support agent. One-time codes are designed to prove possession of your device or account.
If someone asks you to read back a code you did not request, stop the interaction.
Recovery codes and reset links
Recovery codes can bypass ordinary sign-in protections. Treat them like spare keys.
Do not store them in public notes, send them through ordinary chat, or photograph them where cloud sharing is uncontrolled.
Government and financial identifiers
Social Security numbers, full bank-account numbers, full card numbers, tax IDs, and similar identifiers should be shared only through a verified process when genuinely required.
An unexpected message claiming urgency is not a verified process.
Personal facts used for impersonation
Birth dates, family names, pet names, schools, hometowns, addresses, and travel plans can help scammers impersonate you or answer security questions.
Privacy does not require hiding your life; it requires understanding that small details can accumulate.
Screenshots can reveal more than expected
A screenshot can include account balances, email addresses, phone numbers, QR codes, confirmation numbers, browser tabs, or notifications.
Crop and review before sharing.
Remote access is especially sensitive
Do not install remote-control software or give screen-control access because an unexpected caller claims to be technical support, a bank, or a government agency.
Remote access can let another person see or control your device.
Quick Reference
| Never share unexpectedly | Why |
|---|---|
| Password | Direct account access |
| One-time verification code | Can approve a sign-in/reset |
| Recovery code | Can bypass normal login |
| Full SSN | Identity theft risk |
| Full bank/card details | Financial theft risk |
| Remote-control access | Can expose/control device |
| Security-question answers | Can help account recovery attacks |
Treat one-time codes like temporary passwords
Verification codes, account-recovery codes, and sign-in approvals exist to prove that you are the person trying to access the account.
Do not read them to someone who calls, texts, or emails unexpectedly. A real support representative should not need you to defeat the account’s security by handing over the code.
Be careful with full identity documents
A driver’s license, passport, Social Security card, insurance card, tax form, and bank statement can expose multiple pieces of information at once.
Upload them only when the service legitimately requires them and you have confirmed the destination. Avoid sending sensitive documents through casual text messages or unfamiliar file-conversion websites.
Remember that screenshots can contain hidden clues
A screenshot may show account names, email addresses, balances, browser tabs, notifications, or part of another conversation.
Look at the entire image before posting or sending it. Crop out anything that the recipient does not need.
Do not give remote access to an unexpected helper
Remote-access software can allow another person to see or control your computer. Scammers often use it while pretending to be technical support, a bank, or a government office.
Only use remote support when you initiated contact with a trusted provider and understand what access you are granting. End the session when the work is complete.
Build a security routine you can keep
You do not need to understand every technical detail to protect your accounts. Use unique passwords, protect email carefully, add a second sign-in step where practical, keep devices updated, and verify unexpected requests through a route you choose.
When something feels wrong, stop before entering a password, sharing a code, sending money, or installing software. A few extra minutes of independent verification can prevent a much larger problem.
Make security easier to maintain
A security system only works when you can live with it. Use a password manager if remembering many unique passwords is unrealistic, keep recovery information current, and choose an additional sign-in method you understand. The goal is stronger protection without creating a system so complicated that you work around it.
Review the important accounts once or twice a year. Confirm the recovery phone number, recovery email, and trusted devices. Remove old devices and outdated contact methods before you need account recovery.
Slow down when a message creates urgency
Scammers often try to compress your decision into a few minutes. They may claim your account will close, a payment failed, a relative needs help, or suspicious activity requires immediate verification. Urgency is a reason to verify, not a reason to skip verification.
Close the message and contact the organization through an official app, saved bookmark, statement, card, or number you already trust. If the problem is real, you should be able to find it without using the message’s link or phone number.
Keep a simple recovery sheet
Write down which email address is used for your most important accounts, where recovery codes are stored, and which trusted person should be contacted if you cannot access a device. Do not put actual passwords, one-time codes, or full account numbers on a general household sheet.
Store the recovery information somewhere secure but practical. A plan that exists only in your memory can disappear at the exact moment you need it.
Update devices and browsers regularly
Security updates fix known weaknesses in phones, tablets, computers, browsers, and apps. Turn on automatic updates when that works for you, or set a recurring reminder to check for them.
If an old device can no longer receive important security updates, consider whether it should still be used for sensitive tasks such as email, banking, or password management. A familiar device can become less trustworthy when its software is no longer maintained.
Review account alerts instead of ignoring them
Sign-in alerts, password-change notices, and recovery-email messages can be useful early warnings when something changes on an account. Do not automatically click the alert’s link, especially if the message was unexpected. Open the official app or website yourself and check recent activity there.
If the alert is legitimate and the activity was yours, no further action may be needed. If you do not recognize the activity, change the password from a trusted device, review recovery settings, and sign out unfamiliar sessions.
Sources
Frequently Asked Questions
Can a bank ask me to verify information?
Banks may verify identity, but do not provide sensitive information to an unexpected caller. Contact the bank using a number or app you independently know is real.
Is it safe to text a verification code to family?
No. Verification codes are for the sign-in process and should not be shared casually.
Can I post my birthday online?
You can choose to, but understand it becomes public information that may be combined with other details.
Are screenshots risky?
They can reveal more information than intended. Review and crop them before sharing.
Should I ever allow remote access?
Only in a support situation you independently initiated with a provider you trust and after understanding exactly what access is being granted.
Keep this visual on Pinterest
Save the infographic so you can return to the checklist or comparison when you need it.
Save on Pinterest