Short answer: Secure four things, in this order: the email address clients pay to, your payment platforms, your marketplace profiles, and any client accounts you have been given access to. Use an authenticator app everywhere, a passkey where offered, and never accept a client’s password over chat — ask for proper delegated access instead. Your reputation is the asset; a compromised account damages it faster than a bad review ever could.

Why freelancers are targeted more than they realise

A freelancer sits in an unusual position: small enough to have no IT department, connected enough to hold keys to other people’s businesses.

If you manage a client’s social accounts, ad accounts, website or store, your laptop is the softest route into an organisation that may spend serious money on its own security. Attackers know this. Agencies and contractors have been the entry point for a long list of business compromises.

Then there is the direct financial angle. Your email address is public on your portfolio. Your payment platform is guessable. Your invoices are predictable. That is enough for invoice fraud, where a client receives a convincing message from “you” with new bank details — and you find out weeks later when you chase a payment that was already made to someone else.

Priority 1: The email address on your invoices

Everything routes through here. Password resets, client communication, marketplace notifications, payment confirmations.

Priority 2: Where the money lands

Payment platforms, banking, and anything holding a balance.

Priority 3: Marketplace profiles

Upwork, Fiverr, Freelancer, Toptal, 99designs — your reviews and job history live here, and they are not portable. Losing the account means starting over.

Enable 2FA on each, and check the email address on file is the protected one from priority 1. Also watch for the standard marketplace scam: a “client” who wants to move the conversation off-platform immediately. That is not just a payment-protection issue — off-platform is where the malicious file and the fake login page arrive.

Priority 4: Client accounts you have access to

This is where professional practice matters more than personal security hygiene.

Never accept a client’s password. It is bad for both of you: you inherit liability for anything that happens, and they lose any audit trail. When a client offers, redirect them:

Where a client genuinely has a single shared login with no delegation — some older tools, some suppliers — use a shared password manager vault holding both the password and the TOTP secret, so nobody is forwarding codes over WhatsApp. The pattern is in 2FA for small teams.

And write the offboarding into your contract. When a project ends, access is removed, shared passwords are changed, and any shared 2FA is re-enrolled — because a TOTP secret you scanned still generates valid codes long after the password changes.

Your laptop is part of the security perimeter

Freelancers receive files from strangers for a living, which is a genuinely difficult position.

A 45-minute setup you only do once

  1. Password manager installed, with its own strong master password and 2FA.
  2. Passkey or authenticator app on your primary email; SMS removed.
  3. 2FA on every payment platform, with backup codes saved offline.
  4. 2FA on every marketplace profile.
  5. Authenticator app backed up on a second device — how to back it up.
  6. Client access converted from shared passwords to delegated accounts, one client at a time.
  7. A line in your onboarding email stating your bank details never change by email.

Frequently asked questions

A client insists on giving me their password. What do I say?

“I’d rather you add me as a user — it means you can remove my access instantly when we’re done, and you keep a record of who changed what.” Framing it as their protection works better than framing it as yours.

How do I handle 2FA on a client account I manage?

Ideally you never touch it — they hold it, you have your own delegated login. Where you must share, use a shared password manager vault, never chat messages.

What if a client’s account gets compromised while I have access?

Tell them immediately, document what access you had and when, and help with recovery. Silence turns a security incident into a professional one.

Is a VPN necessary for freelancing?

Not for security in the way people imagine. HTTPS already protects your traffic. Your real risks are phishing, malicious files and account takeover — none of which a VPN addresses.

Should I use one email for everything?

Use one professional address for clients and money, well protected, and separate personal accounts. Consider a dedicated recovery address that you never publish anywhere.

What is the single highest-impact change?

A passkey or authenticator app on your primary email, plus checking it for forwarding rules. Everything else in your professional life resets through that inbox.

The bottom line

Freelancers carry business-grade risk with consumer-grade tooling. The fix is not complicated: protect the email, protect the payouts, refuse shared passwords, and be careful what you open. Forty-five minutes once, then a quarterly check — and the thing you are really protecting, your reputation with clients, stays intact.

New to any of this? Start with what an authenticator app is, then work down the priority list above.

Leave a Reply

Your email address will not be published. Required fields are marked *