Start with a username that does not reveal who you are
A strong username keeps your real identity separate from your online accounts. The best usernames do not include your actual name, birth year, address, or any information someone could find in a public record or social media profile. If your name is Sarah Chen born in 1992, a username like "SarahChen92" or "SChen1992" tells a stranger exactly who you are and when you were born — useful information for someone trying to guess your password or impersonate you.
Instead, create something that means something to you but reveals nothing about you to others. "BlueJellyfish47" or "QuietMountain" works because it is memorable to you but tells a stranger nothing they can verify. The goal is to make yourself harder to target, not impossible — just harder than the person next to you.
Key Takeaways
- Never use your real name, birth year, address, phone number, or any information visible on your social media profiles in your username.
- Choose something random or personal but unverifiable — a combination of words, numbers, or both that only you would pick.
- Use different usernames for different accounts so that if one site is breached, attackers cannot use that username to target your other accounts.
- Check the username against your email address and social media handles to make sure you are not accidentally creating a pattern that connects them.
- Once you choose a username, do not share it in public forums, comments, or messages unless that account is meant to be public.
Use a different username for each account
The single most important rule is to use a different username on each site. When a website is breached — and many are — attackers get the username and password together. If you use the same username everywhere, they can try that username and password on your bank, email, social media, and shopping accounts all at once. If you use different usernames, they can only attack the one account they have credentials for.
This does not mean you need to memorize ten different usernames. Write them down in a password manager like Bitwarden, 1Password, or KeePass, which stores usernames and passwords together and fills them in automatically. The password manager remembers them; you do not have to.
Make it random or personal but not traceable
A good username is either random or personal in a way that only you would know. Random usernames are harder to guess: "Mongoose7Violet" or "Prism284Desk" tell an attacker nothing. Personal usernames work too, but they have to be truly private — the name of a childhood pet, a street you lived on as a child, a book only you read — something that does not appear in your social media, your resume, or any public record.
The mistake most people make is choosing something that feels personal but is actually public. Your favorite movie, your college mascot, your hometown — these are all things people can find out about you. If you want to use something personal, pick something that only a few people in your life know: the name of your first stuffed animal, the street your grandmother lived on, the name of a friend from elementary school.
Check that your username does not connect your accounts
Before you use a username, search for it online. Type it into Google, check it on Twitter and Instagram, and see if it appears anywhere. If the same username already exists on multiple sites, and those sites are connected to you, you have accidentally created a trail that links your accounts together. Someone who finds you on one site can now find you on all of them.
The goal is to make sure your username on your bank account, your email, your work accounts, and your social media are all different and do not point to each other. Your email address is often public (people need it to contact you), so your email username and your social media username should be different. Your banking username should be different from both.
Avoid usernames that are too common or too straightforward to guess
Do not use "Admin", "User", "Test", "Password", or any word that appears in a dictionary without numbers or other characters mixed in. These are the first things attackers try. Do not use straightforward number patterns like "123456" or "111111" either.
A username like "Admin2024" is still weak because "Admin" is a common word and "2024" is the current year — both things an attacker will try. A username like "Mongoose7Violet" is stronger because it combines two unrelated words with a number in between, and the combination is not a word or phrase anyone would guess.
Keep your username private once you choose it
Once you have created a username, do not share it in public comments, forum posts, or messages unless that account is meant to be public (like a social media account where the whole point is for people to find you). If you post your username in a comment on a website, in a Discord server, or in an email to someone, you have just made it public. An attacker who sees that username can now try to use it on other sites.
The only people who should know your username are you and the website where you created it. Your password manager knows it too, but that is stored on your device or in an encrypted vault, not visible to anyone else.
What to do if you think your username has been compromised
If you learn that a website you use has been breached, or if you see your username appearing in places you did not post it, change your password on that account when ready. You do not necessarily have to change the username itself — changing the password is the urgent step. However, if the username is tied to sensitive accounts (email, banking, work), consider creating a new account with a different username and transferring your data over time.
You can check whether your email address has appeared in known breaches by visiting Have I Been Pwned (haveibeenpwned.com), a free service that searches public breach databases. This tells you which sites have been compromised, but it does not tell you whether your username specifically was exposed — only that your email was. Still, it is useful information to know.
Frequently Asked Questions
Should I use numbers or special characters in my username?
Numbers are fine and make a username stronger. Special characters like @ or # are usually not allowed in usernames, so check what the site accepts. A mix of letters and numbers — "Mongoose7Violet" — is stronger than letters alone because it is harder to guess.
Can I use my email address as my username?
Many sites require you to use your email address as your username, and that is fine for those sites. The problem is when you choose to use your email address as your username on sites that let you pick something else. Your email is often public, so using it as your username connects all your accounts to one identifier.
What if the username I want is already taken?
Add a number, underscore, or word to the end: "Mongoose7Violet" instead of "MongooseViolet", or "Mongoose7Violet42" instead of "Mongoose7Violet". The goal is to make it unique to that site while keeping it random enough that an attacker cannot guess it.
Do I need to change my username regularly?
No. A strong username that is different on each site does not need to be changed regularly. Change your password regularly (every few months, or when ready if a site is breached), but your username can stay the same as long as it is not public and not connected to your other accounts.
Is it okay to use the same username if I add different numbers to it?
No. "Mongoose7Violet1" and "Mongoose7Violet2" are still recognizably the same username, and an attacker who finds one can guess the others. Use completely different usernames on each site — different words, different numbers, different combinations.