Maintenance
Part of Account security: requirements and practical steps for 2027
Account security risks: warning signs and safer responses
Account security risk ranked by blast radius: the email account first, then the phone number, and the failures that involve no attacker at all.
Most writing about account risk starts with the attacker. That ordering is wrong for a reader, because you cannot do anything about who is trying. Start instead with what you would lose, and the work sorts itself.
Two things follow immediately. Your accounts are not equal, and the largest risk to several of them is not an intruder at all. It is you losing access and never getting it back.
What to take away
- Rank accounts by what they can reset, not by how much you use them.
- Losing your own access is as common as being locked out by someone else, and it is more permanent.
- Risk arrives through other people: shared logins, family plans, an admin who left, a company that was acquired.
Rank by blast radius
An account's risk is what it unlocks, and the ranking is roughly the same for everyone.
| Account | What it reaches | Why it sits here |
|---|---|---|
| Primary email | Password resets for almost everything else | It is the master key, and it is treated as ordinary |
| Phone number | Anything using text codes or number lookup | It is a routing address, and it can be reassigned |
| Password manager | Every credential at once | Single point of both protection and failure |
| Cloud account and backups | Photos, documents, device backups, sometimes payments | Holds the material, not just access to it |
| Primary social account | Your contacts, and your voice to them | The damage lands on other people |
| Banking and payment | Money, directly | Best defended, most targeted |
Everything below that line is ordinary. Spending an hour on the top three is worth more than spending a month on the rest. The same ordering, with the reasoning about sign-in strength, appears in CISA's guidance on strong passwords.
The risks that have nothing to do with attackers
This is the category people never plan for, and the outcomes are worse because there is nobody to appeal to.
- The second factor you cannot produce. A phone lost, broken, wiped, or replaced, with an authenticator app that was never backed up and codes that were never printed.
- A phone number you gave up. Changing carrier or country quietly severs the reset route for every account still pointing at the old number.
- An address you no longer control. A work address after leaving the job, a school address after graduating, a domain that expired.
- A service closing your account. Automated enforcement happens, appeals are slow, and if that account is your sign-in for others, the loss spreads.
- Death or incapacity. Everything you have locked down well becomes inaccessible to the people who need it. Legacy contact and inactive-account settings exist for this and take five minutes to set.
- An employer-owned account. Work identities disappear on your last day, along with anything you attached to them.
The fix for the whole category is the same short list: backup codes on paper, a recovery address you will hold for decades, a current recovery number, and a note somewhere trusted about what exists. That takes one afternoon and prevents the class of loss that no support process reliably reverses.
The risks you inherit
Access you did not grant, on accounts you do use.
A shared login cannot be revoked for one person, and everyone who has ever had it still has it. A family plan links accounts and sometimes payment methods, and a compromise of the least careful member reaches the rest. An admin who left with a role nobody removed keeps that role indefinitely. An app you authorized years ago retains its permissions even if the company behind it has since been sold or wound up, and the security of your data is now whoever bought the assets.
The practical control is individual access rather than shared, removal on the day rather than at the next review, and a periodic read through the connected apps list. That pass sits inside the social media account security audit.
Exposure that is not access
Some risks do not involve anyone getting into anything.
What is publicly attached to you feeds directly into how convincing an attempt against you can be. A birthday, a school, a home town, a pet's name, a former handle, and an employer are individually unremarkable and collectively enough to answer a security question or persuade a support agent. This is the material that makes the identity claim work, which is the subject of identity verification.
Related: a visible contact list makes a cloned account convincing, a visible location history describes a routine, and a public post about being away describes an empty house. None of these are account compromises and all of them are account risks.
Warning signs worth acting on
Ordered by how much they should worry you.
- A code you did not request. Someone has your password and is using it now.
- Mail or texts that stop arriving. Check the phone for service, and the mail account for forwarding rules and filters.
- A sign-in alert you cannot place, or a device in the list that appears occasionally rather than constantly.
- Contacts receiving messages you did not send. Often the first sign, and it comes from outside.
- A setting that is not what you left it as, particularly a recovery address or an alternate email.
- A password reset email you did not trigger. By itself it means someone typed your address into a form. Repeated, it means someone is working on you.
The first three deserve a response tonight. The response order, and what to preserve before you change anything, is in scam reporting and recovery.
Reducing the top of the list
Most of the value is in a handful of moves, applied only to the accounts at the top of the table.
Give the email account a password used nowhere else and the strongest second factor available, preferably one bound to the real site so a copied page cannot use it. Move important accounts off text codes where an alternative exists. Print backup codes. Keep recovery contacts current. Ask the carrier about a port lock. And set the device layer up properly on any new hardware, which is easier at the start than later, as the new phone privacy checklist sets out. Keeping the device itself current closes a share of what remains, which is the point of CISA's advice on updating software.
Common questions
Which risk should I fix first?
Whatever protects the email address that receives your password resets. Every other improvement is smaller than that one.
Are text-message codes worth using at all?
Yes, if the alternative is nothing. They defeat a stolen password and they do not defeat a convincing fake page or a reassigned number, so use them where nothing better exists and move your top accounts to something stronger.
How likely is any of this, really?
Reused passwords and stale recovery contacts are extremely common, and they are what actually causes most account loss. The exotic cases get written about; the boring ones happen.
I have nothing worth stealing. Does this apply to me?
The value of most accounts is access to other people. A trusted account with real contacts is useful to somebody regardless of what is inside it.
What if I already suspect something is wrong?
Assume it is and act in order rather than investigating first. The sequence is set out in account security, and doing it unnecessarily costs you twenty minutes.