
No matter how strong a password is, it can be stolen. 2FA (Two-Factor Authentication) is the final barrier.
Should use code generator apps (Google Authenticator, Authy) instead of SMS OTP because SMS can be intercepted or redirected (Sim Swap). Enable 2FA for all important accounts: Email, Facebook, Banking.