Digital Safety Basics for Students: Passwords, Phishing and Backups
Students store a lot in their accounts: assignments, research, photos, university records and sometimes bank details. Losing access to an email account or a thesis file can be a serious setback. The good news is that a few simple habits prevent most problems. This guide covers the basics: passwords, two-step verification, phishing, public Wi-Fi, updates and backups.
1. Use strong, different passwords
A password is the key to your account, so it should be hard to guess and never reused.
- Make it long. A phrase of four or more unrelated words, such as a sentence you can remember, is stronger than a short word with a number at the end.
- Use a different password for every important account. If one website is hacked, attackers try the same password on others.
- Avoid personal details. Names, birthdays and phone numbers are easy to guess.
- Use a password manager. It remembers many long passwords for you, so you only need one strong master password. Choose a well-known, reputable one.
2. Turn on two-step verification
Two-step verification, also called two-factor authentication, asks for a second proof after your password, usually a code from an app or a message. Even if someone learns your password, they cannot enter your account without the second step. Start with your main email account, because it can be used to reset all your other passwords. Then enable it for your university account, social media and any banking or payment apps. Save the backup codes in a safe place.
3. Learn to spot phishing
Phishing is a trick that makes you give away a password or money by pretending to be a trusted person or organisation. It often arrives by email, text message or a social media message. Watch for these signs.
| Warning sign | Example |
|---|---|
| Pressure and urgency | Your account will be closed in 24 hours unless you click now |
| Unexpected prize or offer | You have won a scholarship or a phone you never entered for |
| Strange sender address | A free email address claiming to be a university office |
| Link that does not match | The visible text says one website, but the real address is different |
| Request for secrets | Asking for your password, a verification code or bank details |
| Poor language | Many spelling errors in a message from a supposed official body |
If you are unsure, do not click. Open the organisation’s website by typing its address yourself, or contact it using details you already trust. Never share a verification code with anyone, because no genuine organisation will ask for it. For scholarship offers in particular, read our guide on how to find and verify scholarships.
4. Be careful on public Wi-Fi
Free Wi-Fi in cafes, airports and campuses can be convenient but is not always safe. Avoid logging in to banking or other sensitive accounts on a network you do not trust. Check the exact name of the network with staff, because attackers sometimes copy real names. Use mobile data for important tasks if you can, and make sure websites you visit show the padlock and an address starting with https.
5. Keep devices and apps updated
Updates fix security problems that criminals already know about. Turn on automatic updates for your phone, computer, browser and apps. Install software only from official stores or the maker’s own website, and remove apps you no longer use. A lock screen with a PIN, fingerprint or face unlock protects your phone if you lose it.
6. Back up what matters
Phones get lost, laptops break and files can be locked by malware. A simple rule is 3-2-1: keep three copies of important files, on two different types of storage, with one copy kept away from your main device, such as in cloud storage. Back up your thesis, assignments and photos regularly, and check from time to time that you can actually open a backup file.
7. Protect your privacy online
- Check the privacy settings of your social media accounts, and limit who can see your posts and personal details.
- Think before sharing a photo of an ID card, a boarding pass or a certificate, because it can be copied.
- Log out of shared computers, and do not let the browser save passwords on a device you do not own.
- Be careful with requests from strangers online, especially for money or private photos.
What to do if an account is hacked
- Change the password at once, on a device you trust, and use a new one.
- Turn on two-step verification if it was off, and sign out all other sessions.
- Check whether the same password was used elsewhere, and change those too.
- Look for messages sent by the attacker, and warn your contacts not to click suspicious links.
- Report the problem to the website or your university IT office, and, if money was involved, to your bank.
A simple monthly checklist
- ☐ Install pending updates on all devices
- ☐ Check that your latest backup works
- ☐ Review which apps and websites have access to your accounts
- ☐ Change any password you suspect has been exposed
Key takeaways
Use long, unique passwords, switch on two-step verification, slow down when a message pushes you to act, keep software updated and back up your work. These habits take little time and protect your studies and your identity.
This article describes general good practice. See our Disclaimer.