Online Security Tips

Employee Benefits Security Administration - United States Department Of Labor Online Security Tips

You can reduce the risk of fraud and loss to your retirement account by following these basic rules.

Register, Set up, and Routinely Monitor Your Online Account

  • Maintaining online access to your retirement account allows you to protect and manage your investment.
  • Regularly checking your retirement account reduces the risk of fraudulent account access.
  • Failing to register for an online account may enable cybercriminals to assume your online identify.

Use Strong and Unique Passwords

  • Don’t use dictionary words.
  • Use letters (both upper and lower case), numbers, and special characters.
  • Don’t use letters and numbers in sequence (no “abc”, “567”, etc.).
  • Use 14 or more characters.
  • Don’t write passwords down.
  • Consider using a secure password manager to help create and track passwords.
  • Change passwords every 120 days, or if there’s a security breach.
  • Don’t share, reuse, or repeat passwords.

Use Multi-Factor Authentication

Multi-Factor Authentication (also called two-factor authentication) requires a second credential to verify your identity (for example, entering a code sent in real-time by text message or email).

Keep Personal Contact Information Current

A better option is to use your cellphone or home network.

Beware of Phishing Attacks

Phishing attacks aim to trick you into sharing your passwords, account numbers, and sensitive information, and gain access to your accounts. A phishing message may look like it comes from a trusted organization, to lure you to click on a dangerous link or pass along confidential information.

Common warning signs of phishing attacks include:

  • A text message or email that you didn’t expect or that comes from a person or service you don’t know or use.
  • Spelling errors or poor grammar.
  • Mismatched links (a seemingly legitimate link sends you to an unexpected address). Often, but not always, you can spot this by hovering your mouse over the link without clicking on it, so that your browser displays the actual destination.
  • Shortened or odd links or addresses.
  • An email request for your account number or personal information (legitimate providers should never send you emails or texts asking for your password, account number, personal information, or answers to security questions).
  • Offers or messages that seem too good to be true, express great urgency, or are aggressive and scary.
  • Strange or mismatched sender addresses.
  • Anything else that makes you feel uneasy.

Use Antivirus Software and Keep Apps and Software Current

Make sure that you have trustworthy antivirus software installed and updated to protect your computers and mobile devices from viruses and malware. Keep all your software up to date with the latest patches and upgrades. Many vendors offer automatic updates.

Know How to Report Identity Theft and Cybersecurity Incidents

The FBI and the Department of Homeland Security have set up valuable sites for reporting cybersecurity incidents: