Tech

Two things that prevent most account compromises

Unique passwords and a second factor stop the large majority of ordinary account takeovers, and both are free to do.

Tech · EDU Aid Network

Most account compromises are not sophisticated. They are credential stuffing: a password exposed in one service's breach, tried automatically against hundreds of others. It works only when the same password is reused, which is why uniqueness matters more than complexity.

A password manager makes uniqueness practical, because nobody remembers hundreds of distinct passwords. Reputable options exist at no cost, including ones built into operating systems and browsers, and the improvement comes from using one at all rather than from which.

A second factor stops the attack even when a password is known. An authenticator app or a hardware key is meaningfully stronger than codes by text message, because a text can be intercepted by a number transferred away from you — but a text-message code is still far better than nothing.

Priority order if this is being done gradually: email first, because it can reset everything else; then financial accounts; then anything holding identity documents.

What to do next. Turn on a second factor for your email account today, and start a password manager with the accounts that can reset others.
studentaid.gov outranks this page. Rules, figures and dates change between academic years. This is written to help you read the official sources, not to stand in front of them. Start there.
Nothing here is a determination. We cannot tell you what you qualify for, and no website can. The programme and the office that runs it decide that, after you apply.

Still have a question?

Describe what you are trying to work out and a member of the team will answer, or direct you to the office that makes the decision.