Updated SEC Investor Bulletin on Securing Online Investment Accounts
Summary
The SEC's Office of Investor Education and Assistance has issued an updated Investor Bulletin consolidating current cybersecurity guidance for individual investors protecting online investment accounts. The bulletin addresses modern authentication methods including passphrases, passkeys, biometric safeguards, and two-step verification, along with practical security measures such as account alerts, password hygiene, and public Wi-Fi precautions. The guidance was issued in accordance with Executive Order on Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens dated March 6, 2026.
“Two-step verification is a practical way to add further security to your account by requiring a second factor to your username and password/passphrase sequence.”
About this source
GovPing monitors SEC Investor Alerts & Bulletins for new securities & markets regulatory changes. Every update since tracking began is archived, classified, and available as free RSS or email alerts — 9 changes logged to date.
What changed
The SEC's Office of Investor Education and Assistance published an updated Investor Bulletin on April 23, 2026, consolidating modern authentication and security practices for individual investors with online investment accounts. The bulletin addresses passphrases (longer character sequences of random words), passkeys (private-key authentication stored on devices), biometric safeguards (fingerprint, facial, or voice recognition), and multi-factor authentication as recommended security controls. It also covers practical measures including account alerts for login attempts, transactions, and personal information changes; password hygiene (unique passwords per account, regular changes, no sharing); and precautions for public computers and Wi-Fi connections.
The bulletin is informational and does not impose new compliance obligations on registered entities. Compliance teams at broker-dealers and investment advisers may use this bulletin as a reference when educating retail customers on account security best practices, though the guidance carries no legal force and no enforcement implications.
Archived snapshot
Apr 24, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
April 23, 2026 In accordance with the President’s Executive Order on Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens dated March 6, 2026, the SEC’s Office of Investor Education and Assistance is issuing this Updated Investor Bulletin to help individual investors protect their online investment accounts from fraud. Investors should always take steps to safeguard their personal financial information (e.g., Social Security number, financial account numbers, phone number, e-mail address, or usernames and passwords for online financial accounts). These online security tips can help ensure that your online investment accounts remain secure.
Consider using a “strong” passphrase, instead of a password, if available. Passphrases are passwords that consist of a series of words strung together that create a phrase. Some investment accounts allow the use of passphrases, which generally require a longer character count than a password. A strong passphrase should consist of random words, using characters that include symbols, numbers, and both capital and lowercase letters. A strong passphrase should not use common phrases from literature, music, or other media. A strong passphrase also should not use personal information such as your name or birthday, or only words found in a dictionary. As with passwords, make sure you secure your passphrase, never share it via e-mail, text messages, or over the phone, and change it regularly.
If you can’t use a passphrase, pick a “strong” password, keep it secure, and change it regularly. Select a strong password for your investment account. A strong password is one that is not easy to guess and generally uses 12 or more characters that include symbols, numbers, and both capital and lowercase letters. A strong password should not use words found in a dictionary or personal information such as a name or birthday. Make sure you secure your password and never share it via e-mail, text messages, or over the phone. You should change your password regularly.
What are passkeys? Some investment account websites have started using what is known as a “passkey.” Passkeys are not passwords. They do not have to be remembered, reset when you forget, and, more importantly, are not subject to being stolen. Instead, if you opt into using a passkey, the investment account stores a “private key” on your device which is paired with the investment account. Not all investment account websites or devices support passkeys, however.
Use two-step verification or “multi-factor” authentication, if available. Your investment firm may offer (or require) a two-step verification process for access to your account. Two-step verification is a practical way to add further security to your account by requiring a second factor to your username and password/passphrase sequence. With a two-step verification process, each time you attempt to log into your account from an unrecognized computer, your investment firm sends a unique code to either your e-mail or mobile device. Before you can gain access to your account, you must enter this code and your password.
Instead of a unique code sent to you by text message or email, however, some websites also offer the use of a third-party authenticator app. You download the app to your device. When you sign into your investment account, a unique code can be provided in the authenticator app or you may be asked to confirm your sign-in in the authenticator app.
Turn “on” account alerts. One of the easiest ways to protect your online investment account and monitor it for fraud is to turn “on” account alerts. Depending on how your online account works, these alerts will send you an e-mail and/or text message when certain activities occur in your account. Some examples of these alerts include:
- Account logins
- Failed account login attempts
- Password changes
- Personal information changes (address, e-mail or phone number)
- Securities transactions (placing orders to buy or sell investments)
- Transfers of money or securities in or out of the account
- Adding or deleting an external financial account where you can transfer money or securities to or from (e.g., bank account, investment account) The availability and types of account alerts vary depending on your investment firm. Contact your investment firm to find out which online account alerts are available and how you can turn them “on” for your account.
Add biometric safeguards, if available. Your brokerage firm or investment adviser may offer biometric safeguards for your online investment accounts, especially for access through mobile devices. Biometric safeguards for an investment account may include fingerprint, facial or voice recognition, or iris scanning. These safeguards may be used with or instead of a password/passphrase to access your investment accounts. Contact your investment firm to determine if they offer these safeguards for your accounts.
Use different passwords for different accounts. Avoid using the same password for different online services, particularly for financial accounts. Using a single password for different online financial accounts is the equivalent of using a single key for your car, house, and mailbox – if the key is lost or stolen, you potentially give away access to everything. While using multiple passwords increases the difficulty of managing passwords, it significantly improves security.
Avoid using public computers to access your investment accounts. Avoid accessing your investment accounts on a public computer, such as in a hotel business center or a library. If you must use a public computer to access your account, remember:
- Avoid using public computers that require you to enter personal information in order to gain access.
- Never walk away from a public computer while using it to look at investment or other financial account information. Leaving data up on a screen and walking away can enable potential onlookers to obtain your sensitive information.
- Disable password saving, and delete history files, caches, cookies, and temporary Internet files.
- When finished, log out of the account completely by clicking the “log out” button on the investment account website to terminate the online session. Closing or minimizing a browser application or window does not necessarily log you out of the account.
- Always change any passwords you have used on a public computer. Use caution with wireless (or “Wi-Fi”) connections. If you use a wireless connection to the Internet (including a wireless home network) to access your online investment accounts, make sure your computer or mobile device is secure and has current software updates, anti-virus software, and a firewall enabled. You can learn more about security issues relating to wireless networks on the website of the Wi-Fi Alliance at http://www.wi-fi.org/discover-wi-fi/security.
If you access your account on a public wireless connection, such as at a coffee shop or airport, you should use extra caution. It is very easy to “eavesdrop” on internet traffic, including passwords and other sensitive data, on a public wireless network. If you use a public wireless network, remember:
- Do not type your password unless the website you are accessing uses a secure connection. The easiest way to determine whether a website is secure is to look in the address bar. If the page’s web address begins with “https” instead of “http,” then it is a secure connection.
- Turn off file sharing. With some operating systems, by default all of your local files are wide open to any other device connected to the same network. Make sure this feature is turned off when accessing information over a public wireless network. You can usually find instructions for turning file sharing on and off in your operating systems’ help menu.
Make sure the settings on your computers and mobile devices will not automatically connect to any available Wi-Fi connection. This will protect you from security risks in public spaces.
Update your devices and check your privacy settings.Make sure the software and software application (apps) on all your mobile devices and computers remain up-to-date with the latest software fixes and security patches.
Most software and apps have privacy settings for users which let you determine how much and what types of information are shared and stored. Always choose the least amount of data-sharing possible. **For any software and apps (including internet browsers), make sure they do not automatically save your account username and password.
Be extra careful before clicking on links sent to you. You should always verify that e-mails or text messages containing links regarding your investment accounts come from legitimate sources. Clicking on a malicious link could:Link to a website designed to trick you into providing sensitive account information that can be used to steal your money or identity.
Cause malicious software (e.g., computer viruses, worms, Trojan horses, or spyware) to automatically infect your computer or mobile device and allow fraudsters to obtain sensitive account information.
To guard against dangerous links, remember the following:Do not click on a link that was sent to you by a business or entity you do not know. Perform an online search for the business or go directly to the business’s website to determine if the link is legitimate.
Do not click on a link that was sent to you by a business you use or know. Investors should confirm the legitimacy of the link by either going directly to the business’ website or calling the business with a confirmed telephone number.
Special tips for using mobile devices: Many mobile devices, such as smartphones, tablets, or laptops, have apps that allow users automatic access to their investment accounts. Unauthorized access to these mobile devices could compromise these accounts. If you have a mobile device that is linked to your investment accounts, consider the following tips:Secure your mobile devices. Turn on your mobile device’s password protection and automatic locking features. These features will automatically lock your mobile device after the device has been inactive for a specified period of time. Once locked, a user must enter a password before accessing the mobile device. Some mobile devices also feature biometric safeguards for accessing a locked device, such as fingerprint and facial recognition.
Turn off automatic Wi-Fi settings. Make sure your mobile device’s Wi-Fi settings will not automatically connect your mobile device to any available Wi-Fi connection. This will help protect you from security risks in public spaces.
Enable remote location and device wiping apps. These apps allow you to locate a lost mobile device, or remotely wipe all data from a lost or stolen mobile device.
Install anti-virus or anti-malware protection. Just like your desktop computer, do not forget to protect your mobile devices from the growing number of virus and malware threats targeted at mobile devices.
Special tips for storing personal financial information in the cloud (online data storage services): EXERCISE CAUTION BEFORE STORING ANY PERSONAL FINANCIAL INFORMATION IN THE CLOUD. You should consider keeping documents containing your sensitive personal financial information (e.g., account numbers, passwords, and PINs) stored offline. If you decide to store any personal financial information in the cloud, carefully consider the following tips:Research the provider. Check the reputation and background of any cloud service provider before uploading any of your personal financial information to a cloud account. You can find background information on cloud service providers through general online searches, press articles, online review websites, and social media.
Look for two-step verification. Many cloud service providers offer a two-step verification process to access the information stored in your cloud account. This provides an extra layer of security to the information stored in your cloud account.
Protect your documents with encryption and/or passwords. Verify that the cloud service provider encrypts all of the information you store in your cloud account. Encrypting information in the cloud helps to safeguard your information if it is stolen from your cloud account. As an extra safeguard, consider either encrypting or adding password protection to sensitive documents before uploading them to a cloud service. Check the software and apps used to create various documents to see if they provide you with tools to encrypt or add password protection to documents. If not, you may also find third-party software and apps that provide these tools.
Carefully review the provider’s security policies. Read and understand the cloud service provider’s security policies for any information you store in your cloud account.
Regularly check your account statements and trade confirmations. Always remember to check your investment account statements and trade confirmations for any suspicious activity. For example:Check for any discrepancies, such as misspelled names or inaccurate account information (e.g., address, phone number, e-mail address, or account number).
Confirm that you authorized all of the transactions that appear in your account statements and trade confirmations.
If you see any mistakes or unauthorized transactions, contact your investment firm in writing immediately. Your written complaint may be the only way to prove that you complained to the firm about the mistakes or unauthorized transactions. Also, remember to keep written records of any communications you have with your investment firm regarding these mistakes or unauthorized transactions.
Additional Resources
Updated Investor Alert: Don’t get “-ished” – Tips to Protect Your Investment and Financial Accounts from Phishing, Smishing, and Vishing Scams
Updated Investor Alert: Identity Theft, Data Breaches and Your Investment Accounts
Investor.gov: Protect Your Social Media Accounts
SEC Publication: Online Brokerage Accounts: What You Can Do to Safeguard Your Money and Your Personal Information
FINRA Investor Alert: Customer Account Takeovers: What They Are and How to Protect Yourself
FTC’s Online Privacy and Security website
Call OIEA at 1-800-732-0330, ask a question using this online form, or email us at Help@SEC.gov.
Visit Investor.gov, the SEC’s website for individual investors.
Receive Investor Alerts and Bulletins from the Office of Investor Education and Assistance (“OIEA”) by email or RSS feed.
This Updated Investor Bulletin represents the views of the staff of the Office of Investor Education and Assistance. It is not a rule, regulation, or statement of the Securities and Exchange Commission (“Commission”). The Commission has neither approved nor disapproved its content. This Updated Investor Bulletin, like all staff guidance, has no legal force or effect: it does not alter or amend applicable law, and it creates no new or additional obligations for any person.
Featured Content
Jumpstart Your Child's Financial Future
Learn how to enroll in a Trump Account today!
Use Financial Tools and Calculators
Access RMD, compound interest and savings goal calculators plus other financial tools.
Learn About Tax-Advantaged Accounts
401(k) plans, IRAs, HSAs, 529 plans, Trump Accounts, and others offer tax benefits.
Test Your Investing Knowledge
Participate in National Financial Literacy Month by taking our financial independence investing quiz!
Related changes
Get daily alerts for SEC Investor Alerts & Bulletins
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from SEC.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when SEC Investor Alerts & Bulletins publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.