How to protect your account from hackers is filed by most traders under computer housekeeping, somewhere between clearing the browser cache and updating a phone. That filing is the mistake. Every other risk in this business is a distribution: you lose a bit, you lose a bit more, occasionally you have a bad month, and position sizing exists to keep the tail of that distribution survivable. A stolen login is not a distribution. It is a single event that takes the whole balance at once, and no amount of risking one percent per trade does anything about it.
Which means it does not belong in the risk-per-trade conversation at all. It belongs in the controls register, next to the fire extinguisher and the backup of the books. So this is that register, with the exposure sized from the FBI's own published counts, and one piece of arithmetic that settles an argument people have been having for twenty years.
What the Exposure Actually Is
The FBI's Internet Crime Complaint Center publishes an annual tally of what victims report. In the IC3 2025 Annual Report it logged 1,008,597 complaints and 20.877 billion dollars in reported losses, an average of 20,699 dollars across every category it tracks.
Taking the categories that concern a person with money in an online account, and computing the average per complaint by dividing published losses by published counts:

Business email compromise: 24,768 complaints, 3,046,598,558 dollars, an average of about 123,005 dollars each. Data breach: 3,963 complaints averaging about 109,826. Account takeover: roughly 4,700 complaints and 359.7 million dollars, an average near 76,532. Then personal data breach at about 19,493, SIM swap at about 17,885, identity theft at about 5,867.
And phishing, which is the most common thing on the entire IC3 list at 191,561 complaints, averages about 1,127 dollars.
Look at the two ends of that. Phishing is roughly eight times more frequent than business email compromise and costs about 109 times less per event. Any operator who has ever done a cost analysis will recognise the shape immediately, because it is the same shape as trading itself: the frequent event is not the one that decides the year.
The useful way to read it is that phishing is the door and the expensive categories are what walks through it. A control that reduces the number of nuisance emails you receive has done nothing. A control that stops the one email that works is the whole job.
The Control Register
A business writes controls down, assigns them an owner, and reviews them on a schedule. A trading business with one employee is still a business. Here is the register, ordered by how much of the exposure above each item removes.
One, a unique password on every account, generated and stored by a password manager. Not a good password reused, a unique one. The reason is in the numbers already quoted: personal data breach accounted for 67,456 complaints in 2025, and those breaches are not the end of an attack, they are the raw material for the next one. A password that appeared in someone else's breach has already failed, no matter how clever it was.
Two, a second factor that is not a text message. An authenticator app or a hardware key. SIM swap shows only 971 complaints, which is why it gets ignored, but it averages about 17,885 dollars per event, and it exists for exactly one purpose: to take over the phone number that receives your codes. A phone number is not something you possess if a stranger can have it reassigned by a shop assistant.
Three, a dedicated email address for money. One address, used for the broker and the bank and nothing else. Never posted publicly, never used for forums, newsletters or the platform signup that ends up in a marketing list. Most account compromise starts at the email account, because the email account is where password resets land. Securing the broker while leaving the email open is locking the safe and leaving the key on the door.
Four, withdrawal destinations locked to verified accounts. If your broker supports whitelisting withdrawal destinations, or enforces a cooling off period when a new one is added, turn it on. This is the control that converts a total loss into an inconvenience, because it means stealing the login is not sufficient to move the money anywhere useful.
Five, an inventory of everything holding access. API keys, expert advisors, copy trade permissions, third party analytics, that signal service you tried once. Each one is a credential you issued and probably forgot. Businesses review access lists quarterly and revoke what is no longer needed. So should you, and the list will be longer than you expect.
Six, separation of the machine that trades from the machine that browses. A dedicated user account at minimum, a dedicated device or server if the balance justifies it. The point is that the platform holding your money should not share a session with everything else you do online.
None of these are clever. That is the point. Controls are not supposed to be clever, they are supposed to be present, and they are supposed to be reviewed on a date rather than remembered on a feeling.
The Argument That Arithmetic Settles
Now the one piece of this where people genuinely disagree, and where the disagreement is unnecessary because the numbers are decisive.
The question is whether a password should be short and complicated or long and ordinary. Treat it as a search problem: an attacker with a stolen password database, testing candidates offline at a fixed rate, who knows the exact structure of what they are looking for. That last assumption is generous to the attacker, which is the correct direction to be generous in. The figures below are the full keyspace, so the expected time to a hit is half of each one.
At ten billion guesses per second, roughly a commodity graphics rig:
- Eight characters using the full printable ASCII set, every symbol on the keyboard: 7.7 days.
- Ten characters, full set: 190 years.
- Twelve lowercase letters, nothing else: 110.5 days.
- Sixteen lowercase letters, nothing else: 138 thousand years.
At a trillion guesses per second, a serious and well resourced attacker:
- Eight characters, full printable set: 1.8 hours.
- Twelve characters, full printable set: 17 thousand years.
- Sixteen lowercase letters: 1 thousand years.
- Twenty lowercase letters: 631 million years.
The comparison that ends the argument: sixteen plain lowercase letters give 4.361 by ten to the twenty second combinations. Eight characters using every symbol available give 6.634 by ten to the fifteenth. The boring lowercase phrase is larger by a factor of about 6.6 million.
The reason is structural rather than clever. Widening the alphabet at a fixed length multiplies the work by a bounded factor, once. Adding a character multiplies it by the size of the alphabet, again, every single time you do it. Length sits in the exponent, complexity sits in the base, and the exponent always wins eventually. It wins by four characters.
Which is why the advice moved to passphrases: four or five unrelated ordinary words beat an unreadable eight character string, and you can actually remember them, which means you will actually use them rather than writing them on something.
The caveat, and it voids everything above: none of this arithmetic applies to a reused password. A password already sitting in someone else's breach dump has a keyspace of one. Length is irrelevant, complexity is irrelevant, the attacker is not guessing. This is why item one on the register is uniqueness and not strength.
The Incident Runbook, and Why It Is About Hours
Every business has a plan for the day the thing goes wrong. Most trading businesses do not, which is expensive, because the recovery window in this particular failure is measured in hours.
IC3 runs a Recovery Asset Team that contacts receiving banks and asks them to freeze funds before they move onward. In 2025 it ran 3,574 domestic freeze actions freezing 507,042,623 dollars, and 326 international actions freezing 171,970,560 dollars.
Read those two ways, because both readings are true and they point in opposite directions.
On the incidents the process actually reaches in time, it works. In the critical infrastructure subset, where the report publishes both sides of the ledger, 655 incidents with 261,451,001 dollars reported lost had 146,561,094 dollars frozen. That is a 56 percent success rate, which the report states and which I checked by dividing: 56.1 percent.
Across everything reported in 2025, the same process froze 679,013,183 dollars against 20.877 billion dollars of losses. That is 3.25 percent.
Fifty six percent versus three percent. Same process, same staff, same banks. The gap between those two numbers is made almost entirely of elapsed time, because most incidents never reach the process while the money is still catchable. The report's own guidance is blunt: if you discover a fraudulent transfer, time is of the essence, contact your financial institution immediately, request a recall along with any indemnification documents, and file at ic3.gov regardless of the amount.
So the runbook is short, and it should be written down somewhere you can reach without the compromised device:
- Call the bank or broker on a number you looked up independently, not one from any message you received.
- Request a recall of the transfer and ask what indemnification paperwork they need.
- File the report with full transaction details.
- Only then start changing passwords, from a device you trust.
The order matters. The instinct is to secure the account first, and the instinct is wrong, because the account is already compromised and the money is already moving. Freezing beats tidying.
What This Does Not Say
IC3 counts only what victims report to it, so every figure here is a floor rather than a census. The true totals are larger by an unknown amount.
The averages are published totals divided by published counts, which flattens a very skewed distribution into one number. Most incidents are smaller than the average and a few are enormously larger. Read them as a ranking between categories, not as a forecast of what any single incident costs.
The password figures are a keyspace bound under stated assumptions, not a prediction about any real attack. Real attacks rarely brute force anything, they use a leaked password, a convincing email, or a phone call. That is precisely why the register above starts with uniqueness and a second factor rather than with password strength.
And none of this makes an account safe. Controls reduce exposure, they do not remove it. The purpose of writing them down is that reduced exposure survives a busy week, and remembered good intentions do not.
Get the free REX one page business plan, the sheet where the risk limits and the operating controls live in one place instead of in your memory. One email, no spam, unsubscribe anytime.
Get the free business plan →Frequently Asked Questions
What is the single most useful step in how to protect your account from hackers?
A unique password on the email address that receives your password resets, with an authenticator app or hardware key on top. That one address is the master key to everything else, and it is usually the least protected thing a person owns.
Is a text message second factor better than nothing?
Yes, clearly better than nothing. It is also the weakest of the options, because SIM swap exists specifically to defeat it, at an average of about 17,885 dollars per reported event. Use it if it is all your provider offers, and move when you can.
Do I need a separate computer for trading?
Only if the balance justifies the cost, which is the same test you would apply to any other business expense. A separate user account on the machine you already own captures most of the benefit for nothing.
My broker was breached, not me. Does any of this help?
Unique passwords and withdrawal whitelisting still limit the blast radius, and they stop the breach from spreading to your other accounts. Nothing you do at your end fixes a failure at theirs, which is one reason due diligence on the firm belongs in the business plan.
Where did the loss averages come from?
I computed them by dividing the published loss totals in the IC3 2025 report by the published complaint counts in the same report. The full assumptions and caveats are in the disclaimer below.
Is a password manager not a single point of failure?
It concentrates risk into one well defended place, which is a trade rather than a free win. The alternative in practice is reuse, and reuse is the failure mode the numbers above are actually describing.
Where REX Fits
REX Trading Signal treats a trading account as a small business: costs, capacity limits, a set of books, and a list of controls that get reviewed rather than remembered. Free to follow, with an optional Kit, and no promise of a profit anywhere in it.
Security belongs in the operating plan alongside everything else. The one page trading business plan template is where the controls in this article should be written down, the key metrics every trading business should track covers what you review on a schedule, choosing a broker like a business partner is the due diligence that decides how much of this is even in your hands, and how to build a cash reserve for your trading business is the other control for a single catastrophic event.
About the author. Rex writes REX Trading Signal, where a trading account is treated as a small business with costs, capacity limits and a set of books. He is more interested in the constraint that ends the quarter than in the trade that started it.
Disclaimer: This article is general educational content about account security controls for people who keep money in online trading accounts. It is not financial advice, not security consulting, not a recommendation of any broker, password manager, authenticator or product, and not a suggestion to open any particular position. Trading gold, CFDs and leveraged products carries a high risk of losing money rapidly. No entry, stop or target discussed should be treated as a signal. The complaint counts and loss totals are as published in the FBI IC3 2025 Annual Report; the per complaint averages were computed by me by dividing those published totals by those published counts, which flattens a highly skewed distribution into a single figure and should be read as a ranking rather than a prediction. IC3 records only what is reported to it, so all figures are a floor rather than a census. The password figures are keyspace calculations I computed under stated assumptions: an offline attack against a stolen password database, a fixed guess rate of ten billion or one trillion candidates per second, and an attacker who already knows the exact length and character set, which is deliberately generous to the attacker; the times shown are for the full keyspace, so expected time to a hit is half of each. They are an upper bound on brute force effort and say nothing about attacks using leaked, phished or reused credentials, against which they offer no protection at all. The figures are United States crime reporting and the recovery process described is a United States one; your jurisdiction may differ. No gold price is quoted anywhere in this article and no trading results are represented.