Investor Protection Basics: Safeguarding Your Money and Account · Lesson 4 of 4
Brokerage Account Security: Protecting Your Login From Takeover
An account takeover skips every check from the earlier lessons, because the thief uses your own login. A few brokerage account security settings, turned on once, close most of the doors.
In this lesson you will learn to
- Set up a unique password and a stronger form of multi-factor authentication on a brokerage account
- Turn on login, trade and transfer alerts and name a trusted contact person
- Recognize a phishing attempt and report unauthorized activity quickly
“New login from an unrecognized device.” Seen within seconds, that alert lets you act early. If it never arrives, you may find out when a transfer has already gone.
A unique password
Start with the password. Give the brokerage account one you use nowhere else. When a site you signed up for years ago leaks its password list, attackers try those same email and password pairs on banks and brokers, and a reused password lets them straight in. Make it long. A password manager makes that practical. The one built into your phone or browser will do.
Multi-factor authentication
Multi-factor authentication asks for a second proof, usually a code. Turn it on. Look for it in the security settings.
The method matters. A code sent by text message is better than nothing, but a thief who talks a phone carrier into moving your number to their own phone, a trick known as SIM swapping, gets your codes along with it. An authenticator app on your phone generates codes on the device itself. A physical security key is stronger still, since it has to be plugged in or tapped against your device, and there’s no code to read out to a caller. Use the strongest method your broker supports. Set up a backup in case you lose the phone.
Alerts
Turn on every alert your broker offers for logins, trades and money movement, and make sure they go to a phone number and email address you check. Transfer alerts matter most, because a takeover usually ends with money or securities leaving the account, and the earlier you see that, the better your chance of stopping it. Some firms add a delay or a confirmation step before a newly linked bank account can receive money, and if yours offers that, turn it on, since it gives you time to spot a link you never made and call the firm before anything moves.
A trusted contact person
FINRA Rule 4512 requires brokerage firms to make a reasonable effort to ask each customer for the name and contact details of a trusted contact person. The firm can then call that person if it suspects exploitation or can’t reach you.
The trusted contact gets no authority over the account. They can’t trade or move money.
Pick someone you trust who isn’t involved in managing your money. Tell them you’ve named them.
Check statements and confirmations
Every trade produces a confirmation, and every month or quarter brings a statement. Read them. Look for trades you didn’t place, transfers you didn’t make, a changed mailing address or a new linked bank account, and report anything unauthorized to the firm at once, calling the number printed on your statement and then following up in writing so there’s a dated record of when you told them. Account agreements often set a time limit on disputing activity. Check yours.
Phishing
Many takeovers start with a message. An email or text says your account is locked, a transfer is pending, or a tax form needs attention, and it links to a login page that looks exactly like your broker’s. Enter your details there and the thief has them.
A legitimate broker won’t ask for your password by email or phone. Don’t click the link. Open the app or type the address yourself. Check the account from there. A caller claiming to be the firm gets the same treatment: hang up, then call back on the number from your statement.
Your email account
Your email is the master key. Password resets for your brokerage account, your bank and most other services go to it, so whoever gets into the email can often reset everything else, and the alerts that would warn you may be sitting in the same inbox the intruder is reading. Give the email account its own unique password, turn on the strongest multi-factor option it offers, and check its recovery phone number and backup address are still yours.
That completes the four protections. Check who you deal with, know what SIPC covers, watch for fraud, and keep the login yours. The investor safeguards overview links back to each lesson. Still weighing account types? Cash or margin account for swing trading is a sensible next read.
Check your understanding
Quick quiz
-
Show the answer
B: An authenticator app or a physical security key. Text codes can be intercepted or redirected to a thief's phone, while an authenticator app or a security key stays tied to a device you hold.
-
Show the answer
B: Contact that person if it suspects financial exploitation. Firms must make a reasonable effort to ask for a trusted contact, whom they can reach if they suspect exploitation; the contact gets no power over the account.
-
Show the answer
C: Ignore the link and contact the firm through the app, a typed address or the number on your statement. Legitimate firms don't ask for passwords by email, so check the account through a channel you found yourself.
-
Show the answer
A: Password resets usually go to email, so whoever controls the email can often reset the brokerage login. Most password resets and many alerts go to your email, which makes it the key to every account linked to it.
Readers also ask
What should I do if my brokerage account is hacked?
Call the firm at once on the number from your statement or its official app, and ask it to lock the account. Change your email and brokerage passwords from a device you trust, review recent trades, transfers and linked bank accounts, and then report the takeover in writing so the date is on record.
Is a text message code safe enough for two-factor authentication?
It beats a password alone, yet codes sent by text can be stolen if someone persuades a phone carrier to move your number to their device. An authenticator app or a physical security key is much harder to intercept, so use one of those wherever your broker supports it.
Can a trusted contact access my brokerage account?
No. A trusted contact person named under FINRA Rule 4512 has no authority to trade, withdraw money or make decisions on the account. The firm may reach out to that person if it suspects financial exploitation or cannot reach you, and naming one is optional.