What's inside
The whole thing, top to bottom
- → What an AI swarm actually is, explained the way I explained it to my mom
- → Step 1: freeze your credit at all 3 bureaus, plus the 3 nobody tells you to freeze
- → Step 2: kill your reused passwords in 20 minutes without changing all 200 of them
- → Step 3: get off text-message codes, in the exact order that matters
- → Step 4: transaction alerts, and the 2-minute test that proves they work
- → The bonus 15 minutes: IRS PIN, SIM-swap lock, and the free breach check
- → What to do first if you think someone is already in
- → Two copy-paste prompts: one that audits you, one that walks your parents through it
First
What an AI swarm actually is
Here is the version I would give my mom.
An AI agent is an AI that can do things on its own. Open websites, log in, fill out forms, move stuff around. A swarm is thousands of those agents running at the same time with no human steering them.
Why that matters to you: a swarm can take one leaked password and try it on thousands of websites in seconds. Your email. Your bank. Your brokerage. And if they get into your email, they can reset the password on almost everything else you own.
This is not hypothetical. In July, roughly 700 AI agents OpenAI was running in a test broke into the systems of a major AI company called Hugging Face. No human told them to. They worked it out on their own.
Americans reported about $893 million in losses to AI-related fraud last year, according to the FBI. That was before the swarms Dario Amodei is warning about.
None of the four steps below are about being clever. They are about not being the easy one. Automated attacks do not negotiate, they move on.
Step 1 — 15 minutes
Freeze your credit
A credit freeze stops anyone from opening a new account in your name. It is completely free by federal law, it does not touch your credit score, and you can lift it anytime.
Before you start, have these in front of you: your Social Security number, your date of birth, your address history for the last two years, and somewhere to write down three PINs. Do each bureau separately. They do not talk to each other.
Account required. Freeze and unfreeze from the dashboard or the myEquifax app.
Account required. They will push you toward paid products. You don't need any of them. The freeze is free.
Account required. Their site calls it a Credit Freeze in the Security menu.
The part nobody tells you
Freezing the big three is the advice everyone repeats. There are three more, and the gaps they leave open are the ones actually getting used.
The fourth credit bureau almost nobody freezes. Some lenders pull from here specifically because everyone forgets it.
This is the one banks check before opening a new checking or savings account in your name. A credit freeze does not cover it.
The utility and telecom bureau. Freezing it stops someone from opening a phone line or a power account as you, which is how a lot of identity theft actually starts.
Need to apply for something later? You can unfreeze anytime. Online or by phone, they have to lift it within one hour. Lift it for the one bureau the lender actually pulls, for the few days you need, then it re-freezes.
Save your PINs where you will find them. In your password manager, as a secure note, the second you finish Step 2. Not in a text to yourself.
Freeze your kids too. A child's credit file is a blank slate nobody checks for 18 years. Each bureau has a protected consumer freeze for minors, same price: free.
Step 2 — 20 minutes
Kill your reused passwords
This is the one that actually stops a swarm. The attack is called credential stuffing, and it is exactly what it sounds like: take one email and password from a leak, stuff it into thousands of login pages, keep whatever opens.
The same password everywhere means one leak opens every door. A different password everywhere means one leak opens one door, and that door is usually something you do not care about.
You do not have to change 200 passwords today. Here is the version that actually gets done.
The one I point people to when they say they don't want another subscription. Free tier is genuinely full featured, works on every device, and it is open source.
The nicest one to actually use, and the family plan means you can set it up for your parents and fix it for them when it breaks. That last part is worth the money.
Good option if you already live in Proton Mail. Free tier covers unlimited passwords on unlimited devices.
Already built into your phone
FreeApple Passwords on iPhone, Google Password Manager on Android. Worse than the three above if you mix devices, and infinitely better than reusing one password. If the choice is this or nothing, pick this today and upgrade later.
The 20-minute method
1. Install the manager and set one long master password. Four or five random words you can picture. Length beats symbols.
2. Import everything your browser already saved. Every manager has a one-click import. This takes 30 seconds and instantly shows you how bad it is.
3. Run the built-in security report. Bitwarden calls it Reports, 1Password calls it Watchtower. It tells you which passwords are reused, weak, or already in a known breach.
4. Fix the six accounts below, in this order. Not all of them. Six.
5. From here on, let the manager generate every new password. You never think about this again.
Your main email
Whoever owns this can reset every other account you have. It is not the most valuable account, it is the master key.
Your password manager
One password protecting all the others. Make it long, make it unique, and never reuse it anywhere.
Your bank and brokerage
The actual money. Also the accounts with the slowest recovery process if you lose them.
Your phone carrier account
Control of your number means control of every text code you get. More on this in Step 3.
Amazon, PayPal, Venmo, Cash App
Saved cards, saved addresses, and a checkout button. This is where a stolen login turns into a charge in under a minute.
Anything with your Social Security number in it
Your tax software, your payroll portal, your health insurance login. Boring accounts, permanent damage.
Step 3 — 20 minutes
Get off text-message codes
Those six-digit codes your bank texts you feel like security. They are the weakest kind. A text can be intercepted, and more commonly, your phone number can be moved to someone else's SIM card by a person at a store who believed a good story. That is called a SIM swap, and once it happens every code goes to them.
Two better options. A passkey uses your face or fingerprint and cannot be phished at all. Use it wherever it is offered. An authenticator app generates the code on your device with nothing sent over the network.
Order matters here. Email first. Always. Your email can reset everything else, so it is the account worth protecting most.
Free, open source, end-to-end encrypted backups, works on every platform. If you lose your phone, your codes come back. That last part is where most people get burned.
Your password manager
Bitwarden and 1Password both store codes for you. Convenient, and it means one breach gets both your password and your code. I use a separate app for my bank and email, and the manager for everything else.
Google Authenticator
Fine, free, and already on your phone. Turn on cloud backup in the settings the moment you install it, or a lost phone locks you out of everything at once.
Do it in this order
1. Your email. Gmail, Outlook, or iCloud. Turn on a passkey if offered, an authenticator app if not. Then go back and remove the phone number as a login method if the provider lets you keep it only for recovery.
2. Your password manager. Same treatment. This vault now holds everything.
3. Your bank and brokerage. Some banks still only offer text codes. If yours does, that is a real reason to look at another bank, and in the meantime Step 4 is your safety net.
4. Save every recovery code. When a site hands you backup codes, they go in your password manager as a secure note, right then. This is the step people skip and then get locked out of their own life over.
Then lock your phone number
Five minutes, free, and almost nobody does it. This is what stops a SIM swap before it starts.
Verizon
My Verizon app, then Account, then Account settings, then Number Lock. Turn it on for every line.
AT&T
myAT&T, then Account settings, then Wireless passcode. Set a passcode, then turn on extra security so it is required for every account change.
T-Mobile
T-Mobile app, then Account, then Profile, then Privacy and notifications, then Account Takeover Protection and SIM Protection. Turn on both.
Anyone else
Call them and say these exact words: I want a port-out PIN and a note on my account that no SIM changes are allowed without it.
Step 4 — 10 minutes
Turn on transaction alerts
The first three steps make you hard to get into. This one means that if someone does get in, you find out in seconds instead of three weeks later when you check a statement.
Open your banking app and look for Alerts or Notifications under settings. Turn on every one of these, on every account that holds money.
Every card transaction over $0
Sounds annoying. It isn't, after the first week. Most fraud starts with a tiny test charge to see if the card is live, and a $1.00 alert at 3am is the cheapest warning you will ever get.
Any transfer out of checking or savings
Set the threshold at $1, not $500. The whole point is catching the first move, not the big one.
New payee or new linked account added
This is the alert almost nobody turns on and it is the one that catches a real takeover. Adding a payee is step one of moving your money out.
Password, email, or phone number changed
If you get this alert and you did not do it, you have minutes, not days. Call the bank from the number on the back of your card.
Login from a new device
Noisy for a week while it learns your devices, then quiet and useful forever.
Zelle, Venmo, Cash App: every send
These move instantly and are nearly impossible to reverse. Alerts are the only real protection you have on them.
The 2-minute test
Buy something small with the card, right now, while you are still in the app. If the alert does not hit your phone within a minute, your alerts are not on the way you think they are. Half the people who set this up never verify it, and an alert going to an email address you stopped reading in 2019 is the same as no alert at all.
Bonus — 15 more minutes
If you have any afternoon left
The four steps above are the whole job. These four are what I would do next, and the first one is the most underrated thing on this page.
Get an IRS Identity Protection PIN
10 minutesA six-digit number that has to be on your tax return for the IRS to accept it. Without it, anyone with your Social Security number can file a return in your name and take your refund. With it, they cannot. It is free, it is voluntary, and it is the single most underrated 10 minutes on this page.
Type in your email. It tells you every known breach your address showed up in. Do not panic at the number, everyone has one. Use it as your to-do list: any site on that list where you reused a password goes to the front of the line.
Lock your Social Security account
10 minutesCreate your my Social Security account before someone else creates it for you. That is the actual attack: the account gets made in your name, and then the direct deposit gets changed.
The only federally authorized free site, and you can now pull all three bureaus every week. Look for one thing: an account you do not recognize. That is it. You are not studying your score.
If it already happened
The order to move in
A login alert you do not recognize, a card you did not open, a password that suddenly stopped working. Do these in this order. The order is the whole point, because fixing the bank first while they still own your email just means they reset it again.
Go to your email first
Not your bank. Your email. Change the password, kick out every logged-in session, and check the forwarding rules and the recovery address. Attackers set up a quiet forward so they keep getting your reset links after you lock them out.
Then your phone carrier
Set a port-out PIN and lock the line. If they own your number, every text code you get is theirs too.
Then the money
Bank, brokerage, payment apps. Call the number on the back of your card. Do not call a number from a text or an email, and do not answer a call claiming to be your fraud department. Call them.
Freeze everything
All three bureaus plus Innovis, ChexSystems, and NCTUE. Free, and it takes minutes.
File at identitytheft.gov
This is the FTC site. It generates an official recovery plan and an identity theft report, which is what banks ask you for when you dispute charges.
Change passwords in order of blast radius
Email, password manager, bank, carrier, then everything that shares the compromised password. Not alphabetically. Not all at once.
Write down what happened and when
Dates, amounts, who you talked to. Every dispute you file for the next six months will ask for it, and your memory will be worse than you think.
Prompt 1
Have AI run the audit with you
Paste this into Claude, ChatGPT, or Gemini. It asks you five questions, tells you your actual weakest link, then walks you through the fixes one at a time and hands you a checklist at the end.
It is built to never ask you for a password, a code, or an account number. If it ever does, close the chat.
Copy-paste prompt
You are my personal security coach. I am not technical. Your job is to walk me through locking down my accounts against automated credential-stuffing and AI agent attacks, one step at a time, and hand me a finished checklist at the end. Rules for how you talk to me: - One question at a time. Wait for my answer before the next one. - No jargon. If you have to use a term like "credential stuffing" or "passkey," explain it in one plain sentence the first time. - Never ask me to paste a password, a recovery code, a full account number, or a one-time code into this chat. If a step needs one of those, tell me to do it outside this chat. - Keep every answer short. I am doing this on a Saturday, not studying for an exam. Start by asking me these five questions, one at a time: 1. What email address do you use to log in to your most important accounts (bank, brokerage, taxes)? Just tell me the provider, like Gmail, Outlook, or iCloud. Do not give me the address itself. 2. When you log in to your bank, how do you prove it is you? A code by text message, an app that shows a rotating number, a fingerprint or face scan, or nothing extra? 3. Be honest: roughly how many of your accounts share the same password or a small set of passwords you rotate? 4. Do you use a password manager today? If yes, which one? 5. Which of these do you have money or credit sitting in: checking, savings, a credit card, a brokerage or retirement account, Venmo or Cash App or Zelle, crypto? List all that apply. After I answer all five, do this: **Step 1. Tell me my actual risk in plain English.** Three sentences max. Name the single weakest link in my setup and what an attacker would do with it first. Do not soften it and do not scare me with things that do not apply to me. **Step 2. Give me an ordered plan.** Rank every fix by how much risk it removes per minute of my time. Put the highest-value one first. For each fix, give me: - What to do, in one sentence - Roughly how long it takes - The exact place to click or the exact page to go to, named the way it is actually named in that app or site - How I know it worked Cover at least these, and skip any that my answers show I have already done: - Freezing my credit at Equifax, Experian, TransUnion, and the three most people miss: Innovis, ChexSystems, and NCTUE - Getting a password manager set up and fixing my reused passwords, worst accounts first - Moving off text-message codes to an authenticator app or a passkey, starting with the email account that can reset everything else - Saving my backup and recovery codes somewhere that is not my phone - Locking my phone number against SIM swapping and port-out fraud with my specific carrier - Turning on transaction alerts on every account that holds money - An IRS Identity Protection PIN so nobody files a tax return in my name **Step 3. Tell me the order to fix my passwords.** Based on the accounts I listed, tell me which 6 to change first and why those six. Do not tell me to change all of them today. I will quit if you do. **Step 4. Ask if I want the 10-minute version or the full pass.** If I say 10-minute, cut the plan down to the three steps that remove the most risk and drop the rest. **Step 5. Walk me through it.** Go one step at a time. After each one, ask me to say "done" or "stuck." If I say stuck, ask me what I see on my screen and get me unstuck before moving on. Do not dump the whole list on me again. **Step 6. When I finish, give me:** - A short checklist of what I completed today, in a format I can copy into my notes - A list of what I did not finish, with the reason it still matters - Three things to put on my calendar: what to re-check in 30 days, in 6 months, and once a year - A plain-English answer to "what do I do first if I think someone got in?" in five steps or fewer One more thing. If anything I tell you suggests I have already been breached, like a login alert I did not recognize, a card I did not open, or a password that stopped working, stop the plan and give me the incident steps first, in order, starting with the account that can reset all the others.
Prompt 2
Now do it for your parents
According to the same FBI data, people over 60 filed only 14% of AI fraud complaints but took 39% of the losses. They are who these things go after first.
This prompt writes you the actual conversation, in words that do not make them feel stupid, then gives you a plan built for someone who gets tired after 40 minutes. It ends with a scam briefing and a family safe word.
Copy-paste prompt
You are helping me protect a family member who is not comfortable with technology. I am going to sit with them, or be on the phone with them, while we do this together. Here is what you know about them: - Their relationship to me: [mom / dad / grandparent / other] - Roughly how comfortable they are with a phone or computer: [not at all / can do email and Facebook / pretty comfortable] - Whether I will be in the room with them or on the phone: [in the room / on the phone / they are doing it alone with me on text] Ask me for anything above that I left blank, then do this: **First, write me a script for the conversation.** Not a lecture. Four or five sentences I can actually say out loud to open this without making them feel stupid or scared. Lead with the fact that this is free, it takes one afternoon, and it is the same thing I already did for myself. Do not use the words hacker, cyberattack, or swarm. Do not imply they are a target because they are old. **Then give me the plan, sorted by what protects them most per minute.** For each step: - The exact words I should say to explain why we are doing it - What I click versus what they click, because some of this legally has to be them - What we will need in front of us before we start, like their Social Security number for a credit freeze, their phone for codes, and a pen for writing down PINs - What "done" looks like on the screen Cover these, in an order that makes sense for someone who tires out after 40 minutes: - Freezing their credit at all three bureaus, and where to physically write down each PIN so it does not get lost - Getting every password out of the notebook, the sticky notes, or the same password reused everywhere, and into one place they can actually use - Their email account first, since it can reset everything else - Getting off text-message codes where their bank supports something better, and being honest with me if their bank does not support it - Transaction alerts on every account with money in it, set to an amount that makes sense for how they actually spend - Locking their phone number with their carrier so nobody can move it to a new SIM **Then give me the scam briefing.** In their words, not mine. Cover the three things they are most likely to see this year: a phone call that sounds exactly like me or another family member asking for money, a text pretending to be their bank's fraud department, and an email about a package or a subscription charge they do not recognize. For each one, give me: - The one-sentence version of how it works - The single rule that beats it every time, short enough to remember with no context - Exactly what to do instead End with a family safe word we agree on right now for any phone call about money or an emergency, and tell me where they should write it down. **Finally, give me two things to leave behind:** 1. A one-page cheat sheet in big, simple language they can tape inside a cabinet door. Every password manager, bank, and alert we set up, with what to do if something looks wrong and who to call. 2. A short list for me of what I should check on with them in 30 days, and the three questions to ask that tell me whether it stuck. Go one step at a time and wait for me to say "done" before moving on. If I tell you they are getting frustrated or tired, stop and give me the two steps that matter most so we can finish another day without leaving them half-protected.
That's it
One afternoon, and you are not the easy one
I spend almost all of my time showing you how to use these tools. This is the other half of it. Knowing how to protect yourself from them matters just as much, and right now nobody is saying it out loud to normal people.
Four steps. All free. Credit frozen, passwords unique, codes off of text, alerts on.
Then send this to your parents. Seriously. That is the highest-value thing you will do with it.
Where this came from
Dario Amodei's essay: We Must Pace the Frontier
The reporting on his warning and the FBI fraud numbers: Yahoo Finance
Fraud loss figures: the FBI's Internet Crime Complaint Center annual report
Credit freezes are free for everyone under federal law, and must be lifted within one hour when you request it online or by phone.
Work with Me
Want me on your problem for an hour?
Book a 1:1 call and we build the fix live — the workflow you want automated, the tool you can’t crack, whatever’s stuck. Direct, hands-on, no pitch waiting at the end.