Staying Safe Online: Protecting Your Accounts and Mobile Money
Mohamed Sesay

You do not need to be a hacker target to get hacked. Most people who lose money or accounts are not caught by some genius cyberattack. They are caught by ordinary tricks that work because of one weak habit, one moment of rushing, one code shared with the wrong person. The good news is the reverse: fix a handful of habits and you close the door on the large majority of attacks that actually happen to ordinary people.
Never share your PIN or one-time code
This is the single most important rule, so it goes first. No real bank, no mobile money agent, no company staff member will ever ask you for your PIN or for the one-time code that was just sent to your phone. Not to "verify" you, not to "confirm" a prize, not to "fix" a problem with your account. Anyone who asks is a scammer, full stop, no exceptions. The code is the key to your money. Treat it exactly like cash you can never get back, because that is what it is.
The classic scam
A caller says you won airtime or a grant and need to "confirm" with the code you just received. That code is them trying to log in as you. Hang up. Real prizes never need your code.

Use a different password for important accounts
Here is how most account takeovers actually happen. A website you barely remember signing up for gets breached, and your email and password leak. Attackers then take that same email and password and try it on everything: your main email, your social media, your money apps. If you reused the password, they are now inside all of them. This is called credential stuffing, and it is automated, cheap, and constant.
Your email and money accounts deserve their own strong, unique passwords that you use nowhere else. A short passphrase of three random words, like "mango-bridge-thunder," is both stronger and easier to remember than something like "Pass123". Length beats complexity. If remembering many passwords is hard, that is exactly what a password manager is for.
Turn on two-factor where you can
Two-factor authentication means that even if someone steals your password, they still cannot get in without a second proof that is on your phone. It is the single biggest upgrade you can make to your security, and it takes five minutes. Start with your email, because your email is the master key: whoever controls your email can reset the password on almost everything else you own.
- Switch on two-step verification for your email first. It is the master key to everything else.
- Lock your phone with a PIN or fingerprint, not a swipe pattern people can watch over your shoulder.
- Be suspicious of links in SMS and WhatsApp, even when they appear to come from someone you know.
- Never install an app from a link someone sends you. Use the official store and check the developer.
Slow down when something feels urgent
Almost every scam runs on manufactured urgency. "Act now or your account will be closed." "Confirm in the next ten minutes or lose the grant." "Your relative is in trouble and needs money immediately." The urgency is the attack. It is designed to push you past the calm thirty-second check that would expose the lie. So make the rule automatic: the more urgent a message feels, the more slowly you respond. Call the bank back on their official number. Call your relative directly. Real situations survive a thirty-second pause. Scams do not.
"Security is not about being clever. It is about a few boring habits you never break, even when someone is rushing you."
The rule that protects your money
None of this requires technical skill. Guard your codes, use unique passwords on the accounts that matter, turn on two-factor, and slow down when pushed. Those four habits stop the attacks that actually happen to real people far more often than any virus ever will.