I've never had any accounts "hacked" what I have done though is lock myself out with these security options, how ironic right? I have however had people try to get into my accounts. Some is trying to get into my epic games account. My cointiply account has nothing in it even and someone keeps trying to get in. Noone got into either of these though. The password just kept resetting and sending to my email. No attempt has been made to get into my gmail account which I have owned for over 10 years now I think.
I basically just read a guide and used my common sense by thinking from a hackers perspective. So no personal links to anything like birthdays or hobbies just like the OP has said.
I never use the same password over even use partly the same password. Each are unique I use bout 16 characters and use upper and lower case, numbers, symbols. I mix these up so I don't have two numbers together and I I try not to repeat a character.
Here are some examples of a password I would make.
J6f&E1p3%8*G2L*F#7
I also can't understand when I see bounty hunters asking managers to change their address because it was hacked. I think it must be phishing. Always verify any website you want to enter login info on using a whois website. Make sure the websites match up. If they don't then you will lose your account due to phishing. My eth account passwords are very long like a private key and I encrypt the place where I copy-paste the password from. I use nod32 antivirus. I always check and match the clipboard too. I do this at least 3x I also keep 3x backups of my personal info. 1 an usb the other 2 on external hdds. The folder in ecrypted and password protected using 7zip. I keep the password to the 7zip file written down in 3 different places 1 being my safe.
I am not saying I will never be hacked. What I am saying is that it would be very very difficult even with the best social engineering. Since everything is completely random not even I know my passwords or even part of them.
I am also pretty sure that being careful will take care of 99% potential hack attempts.
One last thing I do is I link my accounts with F2A and I link my accounts to my phone number or to IP address.
The IP address works very well. No other IP but mine can login to my website for example. They can try use a vpn it won't work since the need the exact IP.
Very nice guide.
Btw I looked through the posts here and there quite a few nice ones so I gave 3 of you some merits since you deserve them. I try to give them to nice posts I see and help people out.
https://bitcointalk.org/index.php?topic=996318.0