Have them use a u2fa token (that you help them setup) for their important accounts. Those are nearly, if not completely, impossible to phis and they are relatively inexpensive and really simple to use.

