Bnka
Security & fraud

How to secure your account in 10 minutes: what works and what is theatre

The weak point is not your password. It is your phone line. Seven steps ordered by real impact, and four things everybody does that do nothing at all.

Equipo BNKA6 min read
Ilustracion plana: escudo coral con marca de verificacion, telefono y una llave. Seguridad de la cuenta

Most security guides are useless because they mix the critical with the decorative. They give you fifteen tips as if they all weighed the same, and they do not.

This list is ordered by real impact. If you only do the first three, you have already covered most of the risk and you can close the page.

1. Put a PIN on your phone line

Five minutes, and it is the step almost nobody takes.

Your phone number is the master key to your digital life. It receives codes, resets passwords, confirms transactions. And it is surprisingly easy to steal.

The attack is called a SIM swap. Someone shows up at your carrier with your details, says they lost their phone, asks for a new SIM with your number. From that moment your codes go to that person.

The defence is one phone call. You ask your carrier to add a PIN or security code for any change to the line, replacements in particular. Every carrier offers it and almost nobody switches it on.

And a warning sign: if your phone suddenly loses signal for no reason and does not recover within a few minutes, do not assume it is a fault. Call your carrier from another phone.

2. Turn on biometrics, and use them inside the app

A code can be extracted by deception. A fingerprint cannot.

When an app gives you the option to confirm a transaction with biometrics instead of a code, that is the safer route. Also enable the phone's own biometric lock, with a backup code of six digits or more. An unlocked phone is an open account.

3. Harden your email before your financial account

This sounds backwards and it is true: whoever controls your email can reset the password for almost everything else. Your email is more critical than any single app.

Four things there:

  • A long, unique password you do not use anywhere else.
  • Two-step verification, better with an authenticator app than with SMS.
  • Open "recent activity" or "devices" and remove anything you do not recognise.
  • Check there are no automatic forwarding rules you did not set. It is a common way to read your mail without logging back in, and almost nobody checks it.

4. Use a password manager

You do not need to pay for anything. Browsers and operating systems already ship with one.

The goal is not sophistication. It is that a leak at some random online shop does not end up opening your financial account. As a floor: your email, your bank and your money apps have three different passwords, and none of them resembles the one you use on social media.

5. Review your devices once a month

Set a reminder, seriously. Once a month, open the active sessions list on your email, your social accounts and your money apps, and remove everything you do not recognise. The old phone you sold, the laptop from your previous job, that computer in an internet café.

6. Turn on alerts for everything, including the small stuff

How much damage fraud does depends mostly on how long it takes to spot.

Set notifications for every movement, including one-euro ones. The classic test before a large charge is a tiny charge, to see whether the account responds and whether anybody is watching.

7. The one rule with no exceptions

No legitimate party will ever ask you for a verification code, or a password, or to move your money to another account to protect it. Not support, not your bank, not the police. Nobody, ever, for any reason.

If someone asks, the conversation is over right there. And it does not matter that they know your name, your ID number or your recent transactions: that data circulates in leaks and proves nothing.

What is pure theatre

To save you time, these deliver far less than they appear to:

HabitWhy it does not help much
Changing your password every monthPushes you to simpler, reused passwords. Better one long and unique.
Mobile antivirusThe real vector is installing apps outside the official store or granting permissions to an unknown app.
Covering your phone cameraNot the financial fraud vector. The vector is the message that convinces you.
Using a VPN "to be safe"It encrypts traffic. It does not stop you handing a code to a scammer.

If something already happened

The order matters. First you block the line with your carrier, because while the SIM is in someone else's hands everything else can be reopened. Then you change your email password and close every session. Only then do you notify your financial providers through their official channels, that same day. And you file a report, because without one almost no claim moves forward.

How those messages arrive and how to recognise them is in the scams that hit Latinos in Spain hardest. And if a transaction of yours has been held, your account is under review explains what is happening on our side.

Any specific question about your account, write to us from support.

Your life crosses borders. Your money moves with you.

Open your account with your passport, get paid in euros and send home whenever you need to.

Frequently asked questions

Is an SMS code or biometrics safer?

Biometrics, and by a fair margin. An SMS code travels over the phone network, so it can be intercepted with a SIM swap or extracted by deception. A fingerprint or a face cannot be requested over the phone. When the app offers biometric confirmation, take that option.

I lost my phone. What do I do first?

Before anything else, ask your carrier to block the line, because the SIM is the key that allows password resets. Then log out remotely from another device and change your email password. Only then notify your financial providers.

Does changing my password every month help?

Very little. Changing often pushes you towards simpler, reused passwords. It pays off far more to have one long, unique password per service, stored in a manager, and change it only if there are signs of a leak.

Does mobile antivirus help?

Less than people think. On mobile the real vector is the user installing something from outside the official store, or granting accessibility permissions to an unknown app. Installing nothing outside the App Store or Google Play protects you more than any antivirus.

ShareWhatsAppLinkedInX
EB
Written byEquipo BNKAProduct securityUpdated on August 5, 2026 10:08

Informational content. This does not constitute financial, legal, tax or investment advice.

Keep reading

One useful guide a month. Nothing else.

Paperwork, fraud alerts and changes that affect your money between Europe and LatAm.

You can unsubscribe at any time. We do not share your email.