Your retirement account is a key tool for saving for your future, and keeping it secure is critical. This article covers steps you can take to protect your account, the security features built into Gusto Retirement, and what to do if you suspect fraud.
You can take several steps to help keep your account safe. The tips below cover the most important ones.
A strong password is the first line of defense against unauthorized access to your retirement account. Gusto Retirement has password requirements in place, but you need to make sure your password does not include easily guessable information, like your birthday or common phrases. Avoid using the same password you use for other accounts.
Consider using a password manager to create and store your passwords. This lets you use a unique password for each of your online accounts without relying on memory.
At Gusto, we require you to set up 2-step verification as an added layer of security in case anyone gains access to your password.
We also strongly encourage you to enable 2-step verification on your primary email account. Your email is often used to reset passwords for other online accounts registered to that address.
Never share your account sign-in credentials or personal account details with anyone, including your beneficiaries. Gusto 401(k) has specific processes in place for beneficiaries who need to request a distribution from your account.
Also, be cautious when discussing your account details in public.
There may be times when you need to send Gusto 401(k) documents that contain sensitive information. Do not send these files by email — we cannot accept them due to security protocols.
Instead, share these documents through the secure Shared files tool. To upload sensitive documents, choose the path that matches how you signed in to access your retirement dashboard.
Sign in to Gusto, go to Benefits, then Active Benefits, find 401(k), select View, then select Manage 401(k).
Go to the Gusto Retirement sign-in page and sign in with your credentials.
Once you're signed in, follow these steps:
Select Documents from the main menu.
Go to Shared files and upload the required information.
Note: 401(k)-specific document uploads (Shared Files) may not be supported when logging in directly from Gusto.
When accessing your retirement accounts, avoid using public Wi-Fi networks that do not require a password to connect. These networks can allow bad actors on the same network to intercept your data. Instead, use a secure, private internet connection or mobile data whenever possible.
We also recommend only signing in to financial accounts on devices you trust. If you need to use a shared or public computer, make sure you fully sign out after each session. Access to your 401(k) account will expire after a period of inactivity, but signing out as soon as you are done can help prevent someone else from accessing your account or information.
Whenever there are changes to your account or a request for funds is made, we will send an automated message to the primary email address on file. If you get an email about an action you did not take, or if you notice suspicious activity on your account, contact us right away.
You should also confirm your personal contact information stays up to date so you continue to get these and other important account notices.
We have several security features in place to help protect your retirement savings and personal information.
When you claim your retirement account or sign in, you may be asked to verify your email by clicking a link or providing a 6-digit code sent to your registered email. You will also be asked to verify a code when signing in if you enabled 2-step verification using SMS or an authenticator app.
When signing in, we may occasionally ask you to update your password to a new, unique password you have not used before. We do this to make sure users have strong passwords for their retirement accounts.
Attackers often try to gain access to online accounts using credentials stolen in security breaches of other password-protected sites. This is called “credential stuffing.” For this reason, using a unique, strong password for each of your online accounts and enabling 2-step verification are increasingly important.
We provide a system-generated password you can use when connecting third-party financial management apps — like Wealthfront, Quicken, or NerdWallet — to your retirement account. Using this password instead of your actual account credentials adds an extra layer of security by limiting third-party access to basic information, like balances and transaction history. Learn how to access your unique third-party password.
If you have a financial app connected to your retirement account, it may occasionally trigger a verification request by email, SMS, or an authenticator app when it tries to update your information. If you get a verification code and are not actively trying to sign in, this is likely the reason.
If you have not connected any financial services to your retirement account and you get an unexpected verification code, reset your password as soon as possible. This may indicate someone is trying to access your account without authorization.
To learn more about how Gusto Retirement protects your information, review our Security Policies and Protocols or our Privacy Policy.
If you believe you have been the victim of fraud or notice suspicious activity in your retirement account, change your password right away. Then, contact us immediately so we can investigate further and take steps to protect your account.