Adding a bit to the above …

Consider 2FA in your vital accounts meaning the site sends a text message link to your phone (assuming you control that device) or to your secret non public email.

Best if your login is not your visible handle.

Also valuable is the site always sends you a message noting your login and also displays your last login. Site notifies you failed password attempts, addy changes and other account activity.

Always best practice to have backup accounts unknown to public’s.

There are additional security methods and