I would like to add more to this
1) always use 2FA for all of your accounts, but make sure to back up the QRs if you missed your mobile devices.
2) Never trust anything in the online world
3) if possible, use LastPass password manager, it will remember your passwords and correct site links ( this will help to prevent phishing attacks ). but you have to trust LastPass anyway