Learn › Take back control

Securing your accounts when someone knows you

Last reviewed 2026-07-29

Why “strong passwords” isn’t the whole answer

Most account-security advice is written for strangers trying to guess your password from across the internet. That advice changes when the person trying to get in already knows you — a partner, an ex, a family member. They may know your birthday, your kids’ names, your pet, your old addresses, and possibly a password you’ve used before. Security questions built on that kind of personal trivia were never designed to stop someone who already has the answers, and NIST’s guidelines for authentication agree they shouldn’t be used when you set a password.

Before changing anything below, read Safety first: before you remove anything. If you share devices, a family plan, or cloud accounts with the person you’re worried about, changing settings can notify them immediately, lock you out of something you need, or tip them off that you know. Plan the order of changes and have a safer device ready before you start.

Why security questions fail against this specific threat

“What’s your mother’s maiden name?” and “What city were you born in?” are facts an intimate partner already has, or can find through shared photos, social media, or public records. NIST SP 800-63B says verifiers “shall not” prompt people to use this kind of personal knowledge when choosing a password — reasonable, since anyone who knows you, or can search for you, likely knows the answers too. Here’s the honest version: if a site still forces you to set security questions, don’t answer them truthfully. Treat the answer field like a second password — make up something only you would remember and store it in a password manager, never something a partner or ex could guess or look up.

Passwords and password managers

A password manager solves two problems at once: it generates passwords a person who knows you could never guess, and stores them somewhere separate from your memory (and from anything written on paper at home). CISA recommends a password manager for every account, with the vault itself protected by one long, unique passphrase you don’t use anywhere else. If your accounts currently share a password, or reuse one you set up while living with someone, start there — reusing a password across accounts is a common way an ex retains access without any “hacking” at all.

Two-factor authentication (2FA) is essential, but the kind of 2FA matters more in this threat model than most. If the person you’re worried about had or has access to your phone plan — as an account holder, a family-plan admin, or someone who could plausibly call your carrier — SMS codes are not private. CISA’s guidance notes SMS messages aren’t encrypted and SMS-based verification isn’t phishing-resistant, and it recommends moving to an authenticator app or, better, a passkey. CISA’s overview of MFA lays out the hierarchy: any MFA beats none, app-based codes beat text messages, and phishing-resistant methods built on the FIDO standard are strongest. In practice:

Once you’ve set up a stronger method, remove SMS as a fallback where the account allows it — leaving it active as a backup defeats the purpose.

Auditing recovery email and phone numbers

Recovery options are how accounts get reset, which makes them a favorite target. On Google’s Security Checkup, review your recovery phone and email and remove anything you don’t fully control. The same applies to Apple: if your Apple Account is compromised or you’re not sure who has access, Apple’s guidance is to confirm you control every email address and phone number tied to the account — including checking with your carrier that SMS forwarding hasn’t been quietly set up on your number.

Signing out everywhere

Most major providers let you end every active session at once, which is worth doing any time you suspect someone still has access:

Checking for mail forwarding rules

A quiet, easy-to-miss tactic: someone with brief access to your email can set up a forwarding rule or filter that silently copies your messages, including password-reset emails, to another address. Google’s guidance on investigating suspicious activity calls out checking automatic mail forwarding and filters for anything you didn’t set up — in Gmail this lives under Settings → “Forwarding and POP/IMAP” and “Filters and Blocked Addresses.” Check this even if nothing else seems wrong; forwarding rules don’t announce themselves.

Shared and family accounts

Family Sharing, shared streaming logins, and joint cloud storage all mean someone else may see your activity or purchases by design. Apple explains how to leave or remove someone from a Family Sharing group — leaving stops shared location, purchases, and photo albums immediately, though it also means losing access to anything shared with you. Before you leave a shared account, think through what that person will see change on their end, and revisit the Safety first guidance if the timing matters.

None of this makes an account unbreakable — no setting stops someone who already knows your passcode and can unlock your phone in person. But moving off knowledge-based recovery, onto a password manager and app-based or passkey 2FA, and auditing who and what still has access closes the paths that don’t require physical control of your device at all. For what a security scan can and can’t add on top of this, see what a scan can and can’t tell you.