Module 04Safety

Internet, Device & Account Safety

Use your devices confidently: practise passwords, two-step verification, WhatsApp and Telegram account controls, privacy, updates, malware protection and recovery.

Interactive security control room

Build your personal digital shield

Mark what you already do. Your score is private to this page and is not stored or sent anywhere.

0%hardened
Secure first

Google and Gmail

Passkey or strong 2FA, recovery details, devices, forwarding rules

Identity

Facebook

2FA, login alerts, active sessions, privacy and recovery contacts

Phone-linked

WhatsApp

Two-step verification, linked devices, account email and SIM protection

Session check

Telegram

Two-Step Verification, app passcode, devices and active sessions

Financial

Banking

Strong app lock, alerts, transfer limits and official contact details

Irreversible

Crypto accounts

Unique credentials, secure 2FA, verified URLs and offline key backups

Platform names and logos are used only to help learners recognise real-world account types. Stable Circle Academy is not affiliated with or endorsed by these platforms, and third-party trademarks remain the property of their owners.

Protect yourself

Your Personal Digital Security Checklist

0 / 16
Start with email, a password manager and MFA.

A checklist is not a guarantee. It is a practical way to reduce common risks and make recovery less stressful.

MFA comparison lab

Choose the strongest method available

Select a method to compare phishing resistance and recovery trade-offs.

Protection
Phishing resistanceHigh
Recovery planningPlan a backup key or recovery route

Best phishing resistance where the service supports it.

Incident response drill

What would you do first?

Practise the order now, before an actual compromise creates pressure.

1 / 3
ALERT

Your Gmail security page shows an unknown device and a forwarding rule you did not create. What comes first?

1
Lesson 1

Passwords, password managers and passkeys

What it is

Strong account security starts with unique passwords, a trusted password manager and passkeys where supported.

Using the internet is like learning to drive: useful everyday freedom comes with hazards you can learn to recognise and navigate. Keep enjoying your devices. These lessons build confidence through practical habits, not fear; no habit removes every risk.

Open guided lesson8 practical steps
How it works

Attackers test leaked email-and-password pairs on other services, trick people into typing credentials into copied sites, or abuse weak recovery questions. A password manager and passkeys reduce the number of reusable secrets a person must type.

A password manager lets you create and store unique, hard-to-guess passwords without trying to remember every one yourself. That matters because reused passwords turn one breach into many compromises.

Passkeys reduce reliance on typed passwords by using device-based cryptographic sign-in. Where supported, passkeys can be easier to use and harder to phish than a shared password.

The goal is not to make security complicated. The goal is to make the safe path the easiest path for everyday logins.

Realistic example

A shopping site is breached. Because Sipho reused the same password for Gmail, an attacker signs into his email and starts resetting his social and banking accounts.

Red flags
  • Unexpected password-reset notices
  • A familiar login page on an unfamiliar domain
  • Repeated sign-in prompts
  • A password manager warning that a credential appeared in a breach
What not to do
  • Do not reuse one memorable password everywhere
  • Do not approve an unexpected passkey or sign-in prompt
  • Do not store passwords in chats or unsecured notes
What to do instead
  • Use a unique generated password for every account
  • Use a trusted password manager
  • Enable passkeys on important accounts where supported
  • Type or retrieve important addresses independently
If already compromised or you interacted
  • Change the affected password from a trusted device
  • Change every account that reused it
  • Review sessions and recovery methods
  • Secure email first if it may be affected
Why this matters

Most account takeovers begin with a guessed, reused or stolen password. Better sign-in habits prevent a lot of damage before it starts.

Try it now

Choose one password manager, switch your most important accounts to unique passwords, and enable passkeys where a service offers them.

Quick knowledge check

One reused password appears in a breach. What is the first useful conclusion?

RememberUse unique passwords everywhere.Prefer a password manager.Enable passkeys where available.
2
Lesson 2

2FA, recovery codes and account recovery

What it is

2FA adds a second proof of identity, but the type you choose affects both security and recovery.

Open guided lesson8 practical steps
How it works

Multi-factor authentication asks for another proof beyond a password. Passkeys and security keys are designed to resist copied login pages; authenticator apps avoid the mobile network; SMS is better than password-only access but remains exposed to number takeover.

Replace SMS 2FA with an authenticator app, passkey or hardware security key wherever the service supports it. SMS depends on the mobile number and is more exposed to SIM-swap and number-porting abuse.

Recovery codes are your emergency back door. If a device is lost or an authenticator app stops working, offline recovery codes can help you regain access without begging a scammer or support agent for help.

Account recovery planning means deciding in advance how you will regain access to email, social media, banking and crypto accounts if the normal login path breaks.

Realistic example

A caller claiming to be a bank says a fraud reversal needs the OTP just sent to your phone. The code actually authorises the caller's login.

Red flags
  • Anyone asking you to read back an OTP
  • An approval prompt you did not initiate
  • Recovery details changed without your action
  • A sudden loss of mobile service
What not to do
  • Do not share OTPs or recovery codes
  • Do not approve prompts to make a call stop
  • Do not keep the only recovery copy on the device it unlocks
What to do instead
  • Prefer a passkey, security key or authenticator app where supported
  • Store recovery codes securely offline
  • Protect the recovery email with strong MFA
  • Review recovery methods twice a year
If already compromised or you interacted
  • Reject or cancel the login
  • Change the password
  • Revoke unfamiliar sessions
  • Contact the provider through its official channel
  • Contact the mobile provider if SIM takeover is suspected
Why this matters

A locked-out account is stressful. A well-planned recovery path prevents panic, improvisation and social-engineering mistakes.

Try it now

For each major account, check whether you can use an authenticator app or passkey, then download and store recovery codes offline in a secure place.

Security warning

Never give a one-time code, recovery code or reset link to anyone who contacts you first.

Quick knowledge check

Which option is most resistant to a copied login page?

RememberAuthenticator apps are usually stronger than SMS.Recovery codes must be stored safely offline.Plan recovery before you need it.
3
Lesson 3

Device lock, updates and browser safety

What it is

A secure device makes it much harder for an attacker to reach your accounts, tokens or messages.

Open guided lesson8 practical steps
How it works

Malicious apps, extensions and files can watch browsing, replace copied payment details, steal sessions or gain remote control. Updates close known weaknesses, while device locks and careful permissions limit easy access.

Use a strong device PIN, password, fingerprint or face unlock. The lock should stop casual access when your phone or laptop is left unattended.

Install operating-system, browser and app updates through official channels. Updates close security holes and reduce the risk of known malware or phishing kits succeeding.

Install browser extensions only from the official browser store after reaching the publisher through an independently verified website. Never side-load an extension file sent through chat or disable browser protections to install it.

Malicious extensions and information-stealing malware can copy session cookies. A stolen active session may let an attacker enter an account without repeating the normal password or 2FA step, so removing malware, signing out all sessions and changing credentials from a clean device are separate recovery actions.

Realistic example

A free coupon extension requests permission to read and change data on every website. It later captures account sessions and changes a copied payment address.

Red flags
  • Broad permissions unrelated to an app's purpose
  • Apps installed outside official stores
  • Security updates repeatedly disabled
  • Unexpected pop-ups, redirects or clipboard changes
What not to do
  • Do not install software from an unsolicited message
  • Do not disable security tools to make an app work
  • Do not keep unused high-permission extensions
What to do instead
  • Use a strong PIN or biometric device lock
  • Enable automatic updates
  • Install through official stores
  • Remove extensions and apps you no longer need
  • Use reputable built-in security or antivirus controls
If already compromised or you interacted
  • Stop sensitive activity on the device
  • Disconnect remote-access tools
  • Scan or reset the device using trusted guidance
  • Change important passwords from another trusted device
Why this matters

Many attacks begin on the device itself, not inside the account. If the device is weak, every account on it becomes easier to reach.

Try it now

Review installed extensions and app permissions now. Remove anything you do not recognise or no longer use.

Quick knowledge check

A calculator app requests access to contacts, SMS and accessibility controls. What should you do?

RememberUse a strong device lock.Keep software updated.Never side-load browser extensions.Revoke active sessions after suspected cookie theft.
4
Lesson 4

Public Wi-Fi, shared devices and email security

What it is

Unsafe networks and shared devices make it easier for someone else to observe, redirect or reuse your information.

Open guided lesson8 practical steps
How it works

Shared devices can retain sessions, downloads, autofill data and passwords. Fake or poorly secured networks can support redirection and observation attempts. Email is especially valuable because it often controls recovery for other accounts.

Public Wi-Fi can be fine for low-risk browsing, but it is not the right place for sensitive account changes or important financial activity unless you are confident in the network and your device posture.

Shared devices introduce a different risk: cached sessions, saved passwords, auto-filled forms and synced browser data can be exposed to the next person.

Email deserves special care because it is often the reset channel for bank, social and crypto accounts. If email is compromised, many other accounts can fall one by one.

Realistic example

Lerato signs into webmail on a hotel business-centre computer, closes the tab without signing out, and leaves an active session for the next user.

Red flags
  • A network name duplicated with slightly different spelling
  • Certificate or browser security warnings
  • A shared browser offering to save your password
  • Unfamiliar email forwarding rules
What not to do
  • Do not perform account recovery on an untrusted shared device
  • Do not ignore browser certificate warnings
  • Do not leave sessions signed in
What to do instead
  • Use your own updated device for sensitive actions
  • Sign out and remove downloaded files on shared devices
  • Give email the strongest MFA available
  • Review forwarding rules and active sessions
If already compromised or you interacted
  • End the shared-device session remotely
  • Change the password if it may have been saved or observed
  • Review email rules, delegates and recovery details
Why this matters

Your email account is often the key to your other accounts. Protecting it reduces the blast radius of a single mistake.

Try it now

Sign out of shared devices, avoid saving passwords there, and review whether your email account has stronger 2FA than the rest of your accounts.

Quick knowledge check

Why should email be secured before many other accounts?

RememberShared devices can leak sessions and passwords.Email is a high-value recovery target.Use caution on public Wi-Fi for sensitive actions.
5
Lesson 5

Backups, SIM-swap awareness and privacy settings

What it is

Good backup and privacy habits help you recover and reduce how much a scammer can learn about you.

Open guided lesson8 practical steps
How it works

Scammers combine public details with phone-number takeover and weak recovery paths. Good backups preserve access, while tighter privacy settings reduce the personal information available for impersonation.

Backups are not only for files. They are also for access: recovery codes, important account details and trusted recovery contacts should be planned and stored carefully.

SIM-swap awareness matters because phone numbers are sometimes used as a recovery factor. If someone takes over your number, SMS-based logins and resets may become unsafe.

Privacy settings can reduce oversharing across social media, messaging apps, phone directories and payment apps. The less unnecessary detail strangers can gather, the harder it is to personalise a scam.

Realistic example

A criminal knows a victim's birthday, mobile provider and workplace from public profiles, then persuades support staff to move the number to a new SIM.

Red flags
  • Unexpected loss of calls and mobile data
  • Password resets you did not request
  • Personal questions from a supposed support agent
  • Recovery methods you do not recognise
What not to do
  • Do not publish identity answers such as birthdays and family details unnecessarily
  • Do not keep backups only on one device
  • Do not treat a phone number as permanent proof of identity
What to do instead
  • Ask the mobile provider about SIM-swap protection
  • Keep offline recovery codes
  • Review social privacy settings
  • Maintain tested backups of important files and access information
If already compromised or you interacted
  • Contact the mobile provider immediately
  • Secure email and financial accounts
  • Replace compromised recovery methods
  • Preserve alerts and timestamps
Why this matters

Attackers often combine small bits of public information to sound convincing. Privacy settings make that job harder.

Try it now

Review who can see your profile photo, phone number, posts and friend list. Then confirm your mobile provider's SIM-swap protection options.

Quick knowledge check

Your phone suddenly loses service while unknown login alerts arrive. What is the safest assumption?

RememberBackup plans should include access, not only files.Treat your phone number as a potential recovery risk.Oversharing helps scammers personalise attacks.
6
Lesson 6

What to do after a compromise

What it is

A calm response can limit damage after a password leak, device compromise or suspicious login.

Open guided lesson8 practical steps
How it works

Attackers try to extend initial access by changing recovery details, creating forwarding rules, retaining active sessions and moving into connected accounts. A calm response order limits that spread.

First, secure the most important account you still control, usually email. Then change passwords from a trusted device, revoke unknown sessions and remove suspicious forwarding rules or recovery methods.

If a device may be infected, stop using it for sensitive actions until it has been checked or reset. If financial accounts may be affected, contact the provider through an official channel and watch for unauthorised activity.

For crypto wallets, exposed recovery phrases or private keys should be treated as a serious compromise. Move assets to a new wallet only through a trusted device and verified steps.

Realistic example

An unknown login appears in Gmail. The victim changes the password but misses a malicious forwarding rule, so reset emails continue going to the attacker.

Red flags
  • Unknown devices or sessions
  • Changed recovery email or phone
  • New forwarding rules
  • Payments or messages you did not create
What not to do
  • Do not investigate from a device that may be infected
  • Do not delete all evidence immediately
  • Do not negotiate with an unsolicited recovery service
What to do instead
  • Use a trusted device
  • Secure email first
  • Change unique passwords and revoke sessions
  • Remove unknown recovery methods and rules
  • Contact financial providers through official channels
If already compromised or you interacted
  • Document what happened
  • Report unauthorised activity
  • Monitor affected accounts
  • Replace exposed crypto keys by moving remaining assets from a trusted device when necessary
Why this matters

The first hour after a compromise is when good decisions matter most. A simple response plan prevents panic.

Try it now

Write down your incident-response order now: secure email, change passwords, revoke sessions, check payments, check devices, then document what happened.

Security warning

If a recovery phrase, private key or one-time code is exposed, act as if the account is already compromised.

Quick knowledge check

After changing a compromised email password, what should you check next?

RememberStart with the highest-value account.Revoke unknown sessions and recovery methods.Treat exposed secrets as a real compromise.
7
Lesson 7

Secure WhatsApp and Telegram accounts

What it is

Protect sign-in, recovery, devices and privacy before a suspicious message arrives.

Open guided lesson8 practical steps
How it works

Two-step verification adds a secret beyond a login code. It does not remove an already linked attacker device; session reviews and recovery security are separate tasks.

WhatsApp: open Settings > Account > Two-step verification and enable the protection offered. Older versions use a six-digit PIN; Meta announced an upgrade to a stronger password in August 2026. Choose a unique secret and add or confirm a recovery email where supported. Enable passkeys through the official app where available; never share passkeys or approve another person's sign-in.

Telegram: open Settings > Privacy and Security > Two-Step Verification, create a strong unique password and confirm a recovery email. Protect that email with its own MFA. An app lock protects this device; it is not the same as the account Two-Step Verification password.

Monthly, review WhatsApp Linked Devices and Telegram Settings > Devices (also called Active Sessions). Log out or terminate unknown sessions, and check promptly after unexpected sign-in alerts.

Use a strong phone PIN or biometrics and automatic OS/app updates from official stores; verify publishers. Secure your carrier account with a unique PIN/password and ask about SIM-swap and number-porting protection. A SIM swap moves your number to another SIM; fraudulent porting moves it to another provider. Both may expose calls and SMS. Protect voicemail with a non-default PIN because voice-delivered verification codes may otherwise be exposed.

In WhatsApp Settings > Privacy, review Profile photo, About, Status and Groups. Select the narrowest useful audiences, check exceptions and restrict who can add you to groups. Group membership can still reveal your number to participants. Menu names and options vary by version.

Realistic example

Thandi enables Telegram's phone app lock but leaves account Two-Step Verification off. A stolen login code could still let someone sign in on another device.

Red flags
  • An unfamiliar session
  • Recovery details changed without you
  • Sudden loss of mobile service alongside login alerts
What not to do
  • Do not reuse your email password
  • Never share six-digit verification codes, PINs, recovery codes, QR login codes, device-linking approvals or passkeys
What to do instead
  • Enable both apps' two-step verification
  • Protect recovery email with MFA
  • Review devices and sessions monthly
If already compromised or you interacted
  • Revoke unknown sessions from a trusted device
  • Secure email and change exposed or reused passwords and two-step secrets
  • Contact your carrier if SIM swap or porting is suspected; secure voicemail
  • Follow the app-specific recovery lessons in Module 5
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Open each app yourself and check one setting. Never enter real passwords, PINs or codes into the Academy.

Quick knowledge check

Telegram's local app lock is enabled. What still needs checking?

RememberEnable both apps' two-step verificationProtect recovery email with MFAReview devices and sessions monthly
8
Lesson 8

Malware protection: useful, not a guarantee

What it is

Use reputable malware protection appropriate to your device, alongside updates and careful account habits. Free options are available.

Open guided lesson8 practical steps
How it works

Malware protection can detect or block some harmful apps, files and behaviour. Built-in protections may already be available at no extra cost, and free third-party options also exist. Features, device support and free-tier limits vary; a paid product is not automatically safer.

Choosing, installing, configuring and maintaining any protection software or service is entirely the learner's responsibility. Stable Circle Academy does not promote or endorse any particular software program or provider. Check the publisher, supported operating system, update policy, privacy terms and costs independently.

Open your device's own security settings first. Keep protection and security updates enabled; obtain software from official stores or an independently verified publisher site. Do not install a cleaner advertised by a pop-up or a messaging-app helper. Protection capabilities differ by operating system.

No malware protection guarantees complete safety. A clean scan cannot prove an account or device is uncompromised, reverse a payment, or make sharing an OTP or signing an unknown wallet request safe. Keep using two-step verification, session checks, backups and independent verification.

Realistic example

A Telegram helper sends a free security APK and asks you to disable protection. Your existing scanner shows no threats, but that does not make the request safe.

Red flags
  • Disable-protection instructions
  • A free cleaner sent in a chat
  • Claims of 100% protection
What not to do
  • Do not disable protection for a stranger's app
  • Do not treat a clean scan as proof of safety
  • Do not buy software under pressure
What to do instead
  • Use reputable protection suitable for your device
  • Keep protection and updates enabled
  • Review free-option limits and publisher details yourself
If already compromised or you interacted
  • Disconnect remote access and stop sensitive activity on a suspect device
  • Use another trusted device to secure email, messaging sessions and passwords
  • Use official device recovery guidance or trusted technical help; a scan alone may not remove all compromise
  • Preserve evidence and report the sender
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Find your device's security settings and check protection/update status. You do not need to purchase software for this exercise.

Quick knowledge check

A free malware scanner reports no threats. Does that make a Telegram wallet-signing request safe?

RememberUse reputable protection suitable for your deviceKeep protection and updates enabledReview free-option limits and publisher details yourself
Primary-source references

Verify the learning material

The Academy uses authoritative primary sources wherever practical and converts them into beginner-friendly explanations.