The cybersecurity tips that matter most for creators go beyond passwords: protect the phone number your accounts fall back on by asking your telco for extra fraud protections, move logins from SMS codes to an authenticator app, passkey or security key, keep recovery codes somewhere other than the account they restore, and treat sponsorship files and signed-in sessions as ways in. A stolen number or a stolen session can get past a strong password, so each step closes a different door.
This page covers prevention across platforms. OnlyFans' own security settings are in the OnlyFans safety and privacy guide, giving an agency or assistant access is covered by the agency account access checklist, and if someone is already inside an account, start with the OnlyFans hacked account recovery steps or the Instagram recovery checklist. It is general information, not legal or security advice for your specific setup.
Why your phone number is the weak point
Australia's communications regulator describes two ways criminals take a number in its guide on what to do if your mobile number has been stolen. In an unauthorised port, they pose as you with a new telco and move your number to an account they control. In a SIM swap, they buy a SIM card and persuade your current telco to transfer your number onto it. Either way, your texts and calls start arriving on their device.
That matters because so many services still text codes to confirm who you are. The FCC's consumer guide on port-out fraud describes the race that follows: the scammer resets as many financial and social logins as possible before the victim notices the phone has lost service. It also notes that scammers gather the personal details they need from social media posts or buy them from hackers. A public creator persona, a business email in every bio and an old data breach can hand them the answers to a telco's security questions.
Watch for the warning signs listed in the ACMA's April 2026 scam alert: unexpected alerts about changes to your phone account, verification codes you did not request, login attempts or password resets you did not start, and a phone that suddenly shows no signal or only emergency calls.
Telco port-out protection steps
In Australia, telcos already have to verify identity before porting a mobile number, usually with a code or call to that number, and the ACMA's customer identity authentication rules require multi-factor checks for high-risk transactions including SIM swaps. The same rules require telcos to offer extra fraud protections to customers at risk, and to customers who believe they are at risk: notifications when a change is requested, a high-risk flag on the account, set channels for authentication, pausing some transactions, or sending notices only to an authorised representative.
In the US, the FCC's November 2023 order requires wireless providers to authenticate customers securely before SIM changes and ports, to notify customers of those requests, and to offer the option of locking an account against them. Compliance was tied to a federal paperwork review, so ask your carrier which of these protections it offers today.
- Call your telco on the number printed on your bill or shown in its app, never one from a text or email.
- Ask how it confirms identity before a SIM swap or a port, and whether it alerts you to every account change.
- Say you believe you are at risk of fraud because your work is public, and ask which protections it will add to your account.
- Set an account PIN or password that you use nowhere else, as the FCC and Australia's Telecommunications Industry Ombudsman both suggest.
- In the US, ask specifically for a SIM-change lock and a port-out lock.
- Turn on email and text alerts for your bank, payout platforms and email accounts, so a change shows up somewhere you can still see it.
- Delete old emails that carry your ID documents, including sent copies, which the ACMA's scam alert recommends.
- Remove your mobile number from media kits, link pages and public profiles.
- Write your telco's fraud line on paper, because you will not be able to look it up on a phone that has gone dark.
Move logins off SMS codes
Government guidance is consistent on the order of strength. The Australian Cyber Security Centre calls multi-factor authentication one of the most effective ways to protect accounts and lists security keys, biometrics, authenticator apps, passkeys and SMS as options. CISA's mobile communications guidance, written for highly targeted people, goes further: do not use SMS as a second factor, treat authenticator codes as better but still phishable, and rely on FIDO methods such as passkeys and security keys where you can. The UK NCSC says passkeys resist phishing because they cannot be intercepted or reused like passwords.
CISA also warns that some services fall back to SMS during account recovery, so adding a stronger method does not always remove the weak one. Google says the same of its own accounts: adding a passkey leaves your existing sign-in and recovery options in place. Check each account's recovery settings after you upgrade it.
| Platform | Strongest documented option | Caveat to check | Recovery item to store | Source |
|---|---|---|---|---|
| Google and YouTube | Passkey or FIDO2 security key | A passkey leaves existing recovery factors in place, and should only live on devices you own | Backup codes; each works once, and a new set cancels the old one | Passkeys, backup codes |
| Apple Account | Security Keys for Apple Account | Needs at least two FIDO Certified keys; losing every key and trusted device can mean permanent lockout | An optional recovery key, which replaces Apple's standard recovery process | Security keys, recovery key |
| Instagram and Facebook | An authentication app, which Meta recommends | The WhatsApp code option only works once text message codes are switched on | Backup codes for when you lose your phone | Meta help |
| TikTok | A passkey, plus 2-step verification with an authenticator app | 2-step verification asks for at least two methods, so pair the authenticator with email rather than phone | The recovery code shown during authenticator setup | TikTok support |
| X | A security key, which X accepts as the only method | Text message codes have been limited to Premium subscribers since March 2023 | The backup code X shows at enrolment | X help |
| Telegram | A Two-Step Verification password and a passkey | Without that password, whoever controls your number controls the account | The password itself, stored like any other recovery code | Telegram FAQ |
| Fansly | Authenticator-app 2FA and named management sessions | Covered step by step in the Fansly security checklist | Any backup codes Fansly shows you | Fansly help centre, via that guide |
Recovery-code storage plan
One rule covers almost every case: store recovery material outside the account it recovers. Apple says not to keep its recovery key in Apple Passwords, iCloud Photos, Notes or iCloud Drive, because you could not open them while locked out, and suggests printed copies in more than one place. X, by contrast, suggests saving a screenshot of its backup code. The two fit together if screenshots never land in a photo library that syncs to an account the code is meant to rescue.
- After switching on two-factor authentication, generate a fresh set of codes so any older set stops working.
- Keep two copies in two places: a password manager whose own login does not depend on your phone number, and a printed sheet somewhere locked.
- Keep codes out of your email, your notes app and any cloud photo library linked to the same accounts.
- Give vault entries neutral names, so a glance at your screen does not reveal what they open.
- Register at least two security keys where a platform supports them, and keep one away from home, as Apple suggests.
- Never pass codes to a manager, chatter or editor; give them delegated access instead.
- Generate new codes after a lost device, a suspected breach or a change of staff.
Keep a one-page register with a row per account, listing the recovery item, where each copy lives, when it was created and when you last confirmed it still works. That turns a stressful lockout into a lookup.
Session-theft hygiene
A signed-in session can be stolen without your password or codes. Google's Threat Analysis Group described a campaign that targeted YouTube creators with cookie theft malware, a session-hijacking technique sometimes called pass-the-cookie. Attackers posed as companies offering paid collaborations, sent a supposed demo of software such as a VPN, photo editor or game, and used the stolen browser cookies to hijack channels, which they sold or used for scams. When email filters caught on, they moved conversations to WhatsApp, Telegram and Discord.
- Treat any sponsor who asks you to install software before a deal as a red flag, and verify the brand through its official website rather than links in the pitch.
- Do not open executables or archives sent with a brand offer; view documents in the browser instead.
- If you ran something suspicious, use a different, clean device to sign out of every session, change passwords and remove connected apps, then have the affected computer checked or reset.
- Review active sessions and trusted devices on every platform once a month; TikTok's security checkup, for example, lists trusted devices and recent security activity.
- Use a separate browser profile for business accounts with as few extensions as possible, and keep the browser and operating system updated.
If your number suddenly stops working
Act straight away. The ACMA's stolen-number guide says to contact your telco immediately, ask whether your number was ported and have the port reversed, or have a swapped SIM deactivated and a new one sent. Then tell your bank, change passwords for banking, email and social accounts, report fraud to police and cybercrime to the Australian Cyber Security Centre, and report the activity to Scamwatch. The same ACMA page lists IDCARE on 1800 595 160 for identity crime support. In the US, the FCC's guide adds placing a fraud alert on your credit reports, filing a police report and contacting your bank and phone company. Once the number is back, work through the platform recovery guides linked at the top of this page.
Limitations of these tips
Telco protections differ by provider and country, platform settings move between app versions, and the options in the table reflect help pages as published on 1 October 2026. No combination of settings makes an account impossible to take over; these steps reduce the routes in. The advice is general, not a security audit of your devices. Contact police and your telco at once if your number is stolen or someone uses your accounts to demand money, and speak to a lawyer if a takeover leads to lost earnings or disputes with a platform.