Banking, payment and investment logins are the highest-stakes passwords you have, because a takeover means direct access to money. Most attacks don't guess the password; they trick you into giving it away through a text message that claims a payment failed, a fake bank website, or a caller pretending to be from the fraud team. Once criminals have the password, they only need a one-time code to finish the job.

Use a random password of at least 16 characters that you have never used anywhere else, or the longest one your bank allows. Some banks still limit length or symbols; in that case, use the maximum allowed and rely on two-factor protection. Store it in a password manager, which also refuses to autofill on a look-alike website and is a useful warning sign of phishing.

Turn on the strongest sign-in protection your bank offers, such as app approval, a passkey or a hardware key, and enable alerts for logins and payments. Always type your bank's address yourself or use its official app, never a link in a message, and remember that your bank will never ask for your password or a one-time code by phone, text or email.

Try the generator

22

Your settings are remembered on this device only. Privacy Policy.

Example password patterns

1

Two random words joined with a hyphen, plus a 2-digit number and a symbol — e.g. Word-Word##!

2

A short phrase you'll remember (4 words), separators between each word, no spaces — e.g. Word_Word_Word_Word

3

Acronym from a movie quote or song line + the year you first heard it + a symbol — e.g. FirstLettersYYYY!

4

Three uncommon words concatenated, with a digit and a symbol — e.g. WordWordWord#9

5

Mix of casing and one substitution per word (don't overdo it — substitutions don't add much entropy) — e.g. wOrd-wOrd-99!

6

Let our generator pick the whole string — the most secure option. Click Generate above.

Frequently Asked Questions

My bank limits password length. Is my account still safe?
It can be, as long as you use the longest random password allowed and turn on your bank's two-factor protection. Banks also monitor for unusual logins and lock accounts after repeated failed attempts, which limits online guessing. The bigger risks are phishing and reuse, so never enter the password anywhere except your bank's real app or website.
Will my bank ever ask for my one-time code?
No. Banks send one-time codes so that you can confirm an action you started yourself. Anyone who calls, texts or emails asking you to read out a code, even if they claim to be from your bank's fraud team, is trying to take over your account. Hang up and call the number on the back of your card instead.

Related Tools

Continue your security workflow with these tools