Protecting an online game account: the options compared

Which account protections are worth the effort for an online game? This page compares six common measures on set-up effort, benefit and limitation.

Quick answer

The strongest practical protection for a game account is a unique passphrase, kept in a password manager, combined with multi-factor authentication where the game offers it, and a secure email account behind it all. Each measure is covered below with its effort and benefit.

This page is general guidance about account habits. It is not a security assessment of any device or service, and nothing on this page checks or scans your computer.

Why game accounts are worth protecting

An online game account can hold more than a username. It may store purchased items, years of progress, a saved payment method and links to other accounts. That makes it worth taking over, and game accounts are a familiar target of scams. Scamwatch, run by the National Anti-Scam Centre, describes scam types and how to report them, and the Australian Cyber Security Centre publishes practical guidance on securing accounts. The measures compared here follow the general direction of that guidance.

The measures compared

Account protection measures compared on effort and benefit
MeasureEffort to set upWhat it protects againstLimitation
Unique passphraseLowGuessing, and leaks from other servicesCan still be phished
Password managerModerate, onceReuse, weak passwords, some fake sitesThe manager itself needs a strong passphrase
Authenticator appModerateUse of a stolen password aloneCodes can be phished in real time
SMS codesLowUse of a stolen password aloneWeaker than an app if the phone number is taken over
Securing the email accountModeratePassword resets by an attackerNeeds the same measures applied to it
No saved payment methodLowPurchases on a compromised accountLess convenient when you do buy

Unique passphrases

A passphrase made from several unrelated words is easier to remember than a short, complex password and harder to guess. The more important property, though, is uniqueness. When a service is breached, attackers try the leaked username and password on other services; this is known as credential stuffing. If your game account has its own passphrase, a breach elsewhere does not reach it.

Password managers

A password manager stores a different password for every account behind a single strong passphrase. It removes the need to remember or reuse passwords and, because it fills in details only on the site it saved them for, it can make a convincing fake login page easier to notice. The main cost is the initial set-up and the need to protect the manager itself with a strong passphrase and multi-factor authentication.

Multi-factor authentication

Multi-factor authentication asks for a second proof of identity after the password, such as a code from an authenticator app, a code sent by SMS or a physical security key. It means a stolen password alone is not enough to sign in. Authenticator apps are generally considered stronger than SMS codes, because a phone number can be transferred to an attacker's SIM card. Use whichever method a game offers; any is better than none. Keep the backup codes the service gives you somewhere safe, as they are the usual route back in if your phone is lost.

The email account behind it all

Most game accounts are tied to an email address, and confirming that address is usually part of registration. Whoever controls the email account can usually reset the game account's password. That makes your email account the most important one to secure: give it a unique passphrase and turn on multi-factor authentication. If you are creating a new game account, make sure the email address you use is one you check and control.

Recognising a common scam pattern

Many scams aimed at players follow the same outline. A message, post or website offers free in-game currency, rare items or an account upgrade, and asks you to log in through a link or share your password. Genuine game publishers do not ask for your password in a message. If you are unsure whether a message is real, do not use its link: go to the game's website or launcher directly.

What to watch out for

  • Offers of free premium currency or items in return for logging in somewhere.
  • Messages from "support staff" asking for your password or a sign-in code.
  • Third-party programs promising cheats, boosts or unlocked items.
  • Requests to move a trade or payment outside the game's own system.

If you think an account has been taken over

  1. Secure your email first. Change its passphrase and check that the recovery details are still yours.
  2. Use the game's official recovery process from its own website, not from a link in a message.
  3. Change the passphrase on any other account that used the same password.
  4. Contact your bank if a payment method was saved and you see transactions you do not recognise.
  5. Report it. Scamwatch accepts scam reports, and the ACSC's website explains how to report cybercrime.

Sign-in codes and backup codes

Two kinds of code cause confusion. A sign-in code is the short, temporary code an authenticator app or SMS provides each time you log in; it should never be shared with anyone, including someone claiming to work for the game. A backup code, sometimes called a recovery code, is a longer, single-use code issued when you turn on multi-factor authentication, intended for when you lose access to your phone. Store backup codes offline or in your password manager, not in an email to yourself.

Keep the phone number and recovery email on each account up to date. They are the routes a service uses to confirm your identity, and an outdated one can make recovery slow or impossible.

A message asking you to read out or forward a code you have just received is one of the clearest signs of a scam. Legitimate support processes do not need your codes, because the service can verify you in other ways.

Shared and family computers

Where several people use the same computer, a few habits keep game accounts separate. Give each person their own operating-system account, so that saved logins and launchers do not cross over. Avoid letting a browser or launcher remember a password on a shared account. If a younger player uses the computer, the family settings described on the family settings page work best when each person signs in as themselves.

On a computer outside your home, such as at a library or a friend's house, sign out of the game and its launcher when you finish, and do not tick options that keep you signed in. If you think a login may have been saved on a computer you no longer use, change the passphrase from your own device.

A set-up checklist for a new game account

  • Register on the vendor's own website or launcher, reached directly.
  • Use an email address you control, protected by multi-factor authentication.
  • Create a unique passphrase and store it in a password manager.
  • Turn on multi-factor authentication in the game account if offered, and save the backup codes.
  • Decide whether to save a payment method; leaving it off adds a step before any purchase.
  • Review the account's privacy and chat settings.

Related reading