Security & Scams

How Do I Keep My Account Secure?

Strong, unique passwords, extra login security, and care with messages go a long way to keeping accounts safe.

In this answer

  • Adopt strong password habits
  • Use extra login security where available
  • Stay alert to suspicious messages
  • Keep devices and software up to date
  • Know how to respond if something seems wrong

5 min

Strong, unique passwords

A strong password is long and hard to guess, and using a different one for each account means that a single exposure does not put everything you have at risk. Reusing the same password across several services is one of the most common ways accounts are compromised, because once one site is breached, the same details can be tried everywhere else.

A password manager can take much of the strain out of this, helping you create and store unique passwords without having to memorise them all yourself. If you ever suspect that a password has been exposed, change it promptly and update it anywhere you happened to reuse it. Treating each account's password as separate and disposable, rather than as one key that opens many doors, is one of the most valuable security habits you can build.

Add extra login security

Where a service offers it, turn on two-factor authentication for an added layer of protection. This means that even if your password is somehow exposed, a second step is still required before anyone can log in, and that step usually depends on something only you have, such as your phone. It is one of the most effective and least demanding steps you can take to protect an account.

Many banks, email providers and online services now make this easy to enable in their security settings, so it is well worth taking a few minutes to switch it on for the accounts that matter most to you. Our guidance on two-factor authentication explains how it works and how to use your codes safely, so you can set it up with confidence and know what a genuine prompt should look like.

Stay alert to messages

Many account problems begin not with a technical attack but with a convincing message that persuades someone to hand over their details. Because of this, it pays to be cautious with unexpected emails, texts or calls that ask you to log in somewhere, confirm your details, or click a link, no matter how official they appear.

  • Go to websites directly rather than clicking links inside messages.
  • Never share passwords or one-time codes in response to a message.
  • Verify any unexpected request through official channels you look up yourself.

These simple habits protect you even when a message is well crafted. If a message claims to be from Merion, you can confirm whether it is genuine through merion.com.au or by contacting us directly, rather than acting on the message itself.

Keep devices updated

Keeping your devices, your browser and your apps up to date is a quiet but valuable part of staying secure, because updates often include fixes for known weaknesses. Installing them promptly, rather than putting them off, means those weaknesses are closed before they can be taken advantage of, and it usually takes very little of your time.

It also helps to lock your devices when they are not in use, to use reputable security software, and to be careful on shared or public networks where others may be able to see more than you expect. If you ever come to believe that an account has been accessed without your permission, act promptly: change the password, turn on any extra security that is available, and contact the service involved. A calm, prompt response is what limits any harm and helps you regain control.

Key takeaways

  • Use long, unique passwords and avoid reusing them across accounts
  • Turn on two-factor authentication wherever it is offered
  • Be cautious with messages asking you to log in or share details
  • Keep devices and software updated, and act quickly if something is wrong

Frequently asked questions

What makes a strong password?

A strong password is long and hard to guess, and is unique to each account so that one exposure does not put your other accounts at risk.

Do I really need a different password for every account?

It is strongly recommended. Reusing passwords means one exposure can affect many accounts. A password manager makes unique passwords easy to handle.

What should I do if I think an account was accessed?

Change the password immediately, turn on two-factor authentication, check for unexpected activity, and contact the service involved.

Our commitment

Fair, professional, compliant — always

Merion handles every account on the facts, with respect, and within the rules. Questions? We're happy to help.