Skip to content
← All articles

The account security checklist: alerts, devices, credit freezes and recovery

Four habits that help you spot trouble early, shut out unwanted sign-ins, block new credit in your name and get back in if you are locked out.

Spectre Editorial

· 6 min read

Contents

Most account security advice focuses on the moment you sign in. That matters, but a lot of protection happens around it: knowing quickly when something changes, knowing which devices still have access, stopping new credit from being opened in your name, and making sure you can get back in if you lose a phone. This checklist walks through those four areas, with links to the agencies that publish the underlying guidance.

1. Turn on alerts, so you hear about changes first

Alerts are an early-warning system, and timing matters.

The Consumer Financial Protection Bureau (CFPB) explains that federal law sets reporting windows for unauthorized electronic transfers. For a lost or stolen debit card or PIN, reporting within two business days limits how much you can be held responsible for; waiting longer can raise that amount. For unauthorized transactions more generally, the CFPB describes a window of 60 days after your bank or credit union sends the statement showing the transaction. The details are on the CFPB's page about unauthorized transactions.

Two kinds of alerts are worth knowing about:

  • Money alerts tell you about activity on an account, such as a balance dropping below a level you choose.
  • Security alerts tell you about changes to the account itself: a new sign-in, a password change, or a change to your e-mail address or phone number.

The Federal Trade Commission (FTC) lists several warning signs of a compromised account, including a notification that your e-mail or phone number changed or your password was reset when you did not do it, and a message that someone signed in from a device or place you do not recognize.

In Spectre, you can set a low-balance alert on an account, and security notices, such as a sign-in from a new device, are sent by e-mail.

An alert does not stop fraud by itself; it shortens the gap between something happening and you knowing about it.

2. Review your devices and sessions

Every phone, laptop or browser that has signed in to an account may still have access to it, and over time that list grows.

The FTC's guidance on recovering a hacked account recommends signing out of all devices, so that anyone signed in on another device is removed from the account. The same guidance suggests checking account settings for changes you did not make. For e-mail, that includes forwarding rules, because an unfamiliar rule can quietly send your messages to someone else's address. That matters for financial accounts too, since password-reset messages and security notices usually arrive by e-mail.

A periodic review is simple:

  • Look at the list of devices or active sessions, if the service shows one, and sign out of anything you do not recognize or no longer use.
  • Check that the e-mail address and phone number on file are ones you entered and still control.
  • If you find something you did not set up, change your password and follow the provider's recovery steps.

3. Freeze your credit, and know how it differs from a fraud alert

The first two steps protect accounts you already have. A credit freeze protects against something different: someone opening new credit in your name.

According to the FTC, a credit freeze prevents anyone, including you, from opening new credit accounts in your name while it is active; the CFPB describes it as preventing prospective creditors from accessing your credit file. It is free to place and free to lift, and it lasts until you lift it. The CFPB adds a few details:

  • You place a freeze separately with each of the three nationwide credit reporting companies: Equifax, Experian and TransUnion.
  • A request made by phone or online must be placed within one business day; a request by mail within three business days.
  • When you ask to lift a freeze by phone or online, it must be lifted within one hour.
  • Some parties can still see a frozen file, including creditors on accounts you already hold, certain government agencies, and companies you have hired to monitor your credit.
  • A freeze does not affect your credit scores.
  • Parents and guardians can also place a freeze for children under 16.

A fraud alert works differently. The FTC explains that a fraud alert tells businesses to check with you before opening new credit in your name, but it does not block access to your report. You only need to contact one of the three bureaus; that bureau must tell the other two. An initial fraud alert lasts one year. An extended fraud alert lasts seven years and also takes you off the bureaus' marketing lists for unsolicited credit offers.

If you believe your identity has already been misused, IdentityTheft.gov, run by the FTC, lets you report it and get a personal recovery plan.

4. Keep your sign-in methods and recovery options current

Strong sign-in is the base layer. The Cybersecurity and Infrastructure Security Agency (CISA) lists turning on multifactor authentication (MFA) as one of four basic habits in its Secure Our World program, alongside recognizing phishing, using strong passwords and updating software. CISA describes MFA as an extra check that confirms your identity when you sign in, so a stolen password alone is not enough to get into the account.

Not every second factor is equally strong. The FTC's guidance on two-factor authentication explains that text-message codes can be intercepted if someone takes over your phone number through a SIM swap. It describes authenticator apps as safer, because the code is not sent over your phone line or e-mail, and it calls security keys the strongest method because they do not rely on credentials that can be stolen. The FTC also suggests starting with your most important accounts: banking, e-mail and payment services.

Spectre supports passkeys, which use your device's built-in security rather than a password you type, and an authenticator app that generates time-based codes. When you set up the authenticator app, Spectre also issues a set of backup codes.

Recovery is the part people tend to forget until they need it. The FTC recommends making sure the recovery e-mail addresses and phone numbers on an account are ones you entered and can still access. A few things are worth checking now and then:

  • Backup codes: stored somewhere safe and separate from the device that holds your authenticator app, so losing one does not mean losing both.
  • Recovery contacts: the e-mail address and phone number on file are current and still yours.
  • Passkeys and authenticators: devices you no longer own are removed.

If something has already gone wrong

If you see a transaction you do not recognize, the CFPB explains that contacting your bank or card provider promptly helps preserve your protections under federal law. Freezing the card stops new card transactions while you sort it out; in Spectre you can freeze a card from the app and unfreeze it later. The FTC's hacked-account guide covers taking back an account, and IdentityTheft.gov covers identity theft more broadly.

Together, these steps mean you hear about problems sooner, fewer devices can reach your accounts, new credit is harder to open in your name, and you have a way back in.