Bank Hapoalim Cyber Expert Outlines Five Habits to Protect Digital Identity
Harel Krause, Cyber Awareness Lead at Bank Hapoalim, shares five essential digital habits to prevent identity theft, including using password managers, adopting passkeys, and avoiding phishing links.

Daily habits such as reusing passwords, clicking on unverified links, and sharing personal information make it significantly easier for cybercriminals to steal credentials, breach accounts, and impersonate individuals online. As more of our lives transition online, understanding how to minimize exposure and protect our digital identity has become critical.
Harel Krause, Cyber Awareness Lead at Bank Hapoalim's IT and Cyber Defense Division, outlines five simple habits that can safeguard personal data and financial accounts.
Convenience vs. Security
Harel Krause explains:
"Our digital lives are currently scattered across dozens of apps, websites, and various services. To save time and simplify our routines, most of us repeat the same habits: using the same email address for every registration, recycling familiar passwords, and uploading personal information to the web almost without thinking.
While this convenience eases daily life, it also creates a reality where the data trails we leave behind make it easy for others to track us, impersonate us, and gain access to our most sensitive accounts. It is impossible to prevent every online threat, but adopting five small habits can make all the difference."
Five Essential Habits for Digital Protection
-
Switch to a Password Manager. Using the same password across multiple services creates a dangerous domino effect. If a password is leaked on one platform, it can grant attackers access to all other accounts. Instead of saving passwords in browsers or recycling them, utilize a dedicated password manager. This allows you to generate and store unique, complex passwords for every account in an encrypted vault, requiring you to remember only one master password.
-
Adopt Passkeys Wherever Possible. An increasing number of services now support Passkeys instead of traditional passwords. Authentication is completed using the device's built-in security mechanisms, such as fingerprints, facial recognition, or a local PIN. Unlike passwords, which can be stolen or phished, a passkey does not require typing credentials that can be intercepted or shared.
-
Enable Two-Factor Authentication (2FA), but Avoid Auto-Approvals. Two-factor authentication adds an extra layer of defense if a password is compromised. However, attackers frequently exploit this mechanism through "MFA fatigue" attacks—sending repeated login approval prompts hoping the user will eventually click "approve" out of habit or to stop the notifications. If you receive an unsolicited login request, deny it immediately and review your account activity.
-
Do Not Click on Links in Urgent Notifications. Messages impersonating banks, credit card issuers, delivery companies, or government agencies are common vectors for credential harvesting. These alerts typically manufacture a false sense of urgency, such as an outstanding debt, a pending package, or an imminent account suspension. Instead of clicking the provided link, navigate independently to the official website or app to verify the claim.
-
Think Twice Before Sharing Personal Documents. Photos of ID cards, driver's licenses, boarding passes, or official documents expose far more sensitive data than they appear to. Even seemingly minor details can be aggregated by fraudsters to facilitate identity theft or bypass security questions. Before uploading any document or image, carefully inspect what information is visible and evaluate if sharing it is necessary.





