Account security and two-factor authentication
Protect your account and sessions before anyone can reach orders or customer data.
Compliance and scale
Your store login is the key to everything a competitor or a scammer would love to reach: every customer's name, phone number, and home address, your full order history, and the payout details that decide where your money lands. If someone takes over that one account, they can read your buyers' personal data, message your customers pretending to be you, refund themselves, or quietly change the bank or InstaPay number your settlements go to. Securing your own account is therefore not an IT chore for later; it is the first line of defence around your revenue and around every shopper who trusted you with their details.
The good news is that account takeover almost never involves clever hacking. It happens because a password was reused from Facebook or Gmail and leaked, because someone stayed logged in on a phone they later sold, or because a merchant typed their credentials into a fake login page sent over WhatsApp. This lesson covers the four habits that close those gaps for your own account: a strong unique password, two-factor authentication, watching your active sessions, and never sharing your login. Controlling what your staff can each access is a separate topic with its own lesson, linked below.
Use a strong, unique password
Most account takeovers in Egypt start with a password that was reused somewhere else and later leaked in a breach. Many merchants run the store, their personal Facebook, their Gmail, and Instagram from the same phone with the same password, so one leak anywhere hands an attacker the store too.
- Make it unique to this account. Never reuse the password from your email, social accounts, or another store. A breach on any of those should never touch your storefront.
- Make it long, not just complex. A passphrase of several unrelated words is far harder to crack than a short string with one symbol, and far easier to remember.
- Use a password manager. It generates and stores a different strong password per service, so you only memorise one master password instead of reusing a weak one everywhere.
- Change it immediately if you suspect exposure. If you ever typed it into a suspicious link or a shared device, treat it as compromised and reset it right away.
Turn on two-factor authentication
Two-factor authentication (the second step after your password, sometimes called two-step verification) is the single biggest upgrade you can make. Even if your password leaks, an attacker is stopped at the second factor, which only you hold. Storix supports this for your account, and enabling it should be your first action after reading this.
- Prefer an authenticator app over SMS. App codes are tied to your device, not your phone number. SMS is vulnerable to SIM-swap fraud and to the number churn common in Egypt, where a lost or recycled line can hand codes to someone else.
- Save your backup codes somewhere safe. Store the one-time recovery codes offline — written down or in your password manager — so a lost or reset phone never locks you out of your own store.
- Never read your code aloud or forward it. A code sent to you is for you alone. Treat any request to "just send me the verification code" as fraud, no exceptions.
Watch your active sessions
Your account stays signed in on every device you have ever used it on, and each of those is a door that may still be open. A laptop you sold, a relative's phone you borrowed to check an order, or a quick login from a friend's computer or a café can all remain active long after you have walked away. Reviewing your active sessions periodically and signing out the ones you do not recognise closes those doors before anyone walks through them. After a lost or stolen phone, sign out all sessions immediately and then sign back in only on the device in your hand. Make this a habit at month-end alongside your other admin checks, so a forgotten session never becomes the way your customer data leaks.
Never share your login
It is tempting, when a partner or an assistant needs to help, to just hand over your password — but shared logins are how accountability and security both collapse. With one shared login you cannot tell who changed a price or refunded an order, you cannot remove one person's access without locking everyone out, and two-factor authentication becomes meaningless once the code is being passed around a group chat. Give each person who works on the store their own access with the right level of permission instead; that is exactly what the team roles and permissions lesson walks you through. Be just as firm with strangers: Storix and your courier will never ask for your password or your verification code over a WhatsApp or Instagram message, and any "verify your store now" link pushing you to a login page is a phishing attempt designed to steal exactly those details.
Related lessons
- Privacy and consent basics — why a locked-down account is what actually protects the customer data you are responsible for under Egypt's data-protection rules.
- Incident response runbook — the steps to take fast if you ever suspect your account or store has been breached.