Comments

Doug July 22, 2026 7:54 AM

I read articles like this and shudder. I’m married and nearly all of our financial accounts are shared. Trying to figure out a security schema that works for two people who have vastly different understandings of security and risk is not trivial.

Billy Jack July 22, 2026 8:02 AM

I received an e-mail last night from a former customer of mine. The only explanation I can think of is that he or his wife gave out their gmail address and password to someone spoofing something called paperlesspost.

I got his telephone number from one of the early morning coffee drinkers a few minutes ago and am getting ready to call him to warn him and suggest that he contact his bank and credit card companies and that he should probably start changing passwords. If I can’t get hold of him, I’ll probably drive out to his house in a bit to talk to him in person.

It would surprise me if he didn’t use the same weak password on everything.

Rontea July 22, 2026 8:49 AM

This is why layered security and zero-trust practices are absolutely essential in our connected world. A single point of failure—your core account, your phone number, your email—can cascade into a total compromise if it’s the foundation for everything else. Social engineering is powerful because it exploits human trust, and spoofed calls or texts can look perfectly legitimate in the moment.

Two key takeaways: diversify your digital keys and never authenticate inbound. Call your bank or provider directly using a verified number, and treat unsolicited messages—even those that look official—as suspect. One proactive measure today can prevent a full-scale loss tomorrow.

Steve July 22, 2026 9:00 AM

@Doug

Haha, I hear that. I managed to go over the severe ramifications of poor security and when she got it and asked what to do I went over the biggest must/must not ensuring she understood everything along the way. I asked questions to verify her understanding on each point. Now if she runs into anything she asks. 🙂

The thing to overcome is the considerations on looking at seemingly hard to understand things. So I had to find some outcome which was not acceptable to her and working with her as a team member to overcome the threat she was not willing to have, it then became easy to consult her understanding and willingness to do / not do things. All done on a gradient that she could handle.

And as you know security is a balancing act. 🙂

Concerned July 22, 2026 9:51 AM

With the ability to voice clone within three seconds using current machine learning / DSP techniques, I’m afraid even point #3 is no longer fool-proof: “3. Never move a meaningful sum until you have heard the person’s voice.”

One idea was to have a secret phrase / password between you and your loved ones to “authenticate” them, when calling in emergencies like this.

Winter July 22, 2026 11:25 AM

Passwords are broken beyond repair. Many MFA’s are starting to be circumvented.

We will probably go to a situation where we will each have to carry a hardware key to identify.

Wannabe Techguy July 22, 2026 1:06 PM

@ Winter
Yep, I’ve been using a Yubikey for a few months now. Some sites as a second factor, others in place of a password. I’m still waiting for my Credit Union to let me start using it. The only options now are the usual three. Not much of a choice IMO. I don’t own a smartphone either.

lurker July 22, 2026 1:39 PM

He’s a pilot. Maybe lulled into complacency, because the things that matter get ticked off a checklist before flight.

This is a routine, familiar request, the kind your bank sends all the time. I replied no.

Ah, no. My bank never sends requests like that, they never conduct transactions by phone, and they frequently remind customers that they don’t.

Maybe it was better in Revelation 13:16,17 where everybody had the same password, and it was carried in plain sight.

Clive Robinson July 22, 2026 2:16 PM

@ Bruce, ALL,

With regards,

“But the real story here is how, for many of us, the security of most of our accounts hangs on the security of our email accounts.”

As you are aware quite some years ago I had an old GMail account to do a very limited amount of “social” activity coordination.

That has long since been discontinued and I no longer have any kind of “personal Email” and I absolutely do not do any kind of “On-line” financial, medical or other personal or private business.

I’ve been warning people for years not to do anything on line of personal consequences…

As usual I got the “paranoid” label but as time shows I was just “ahead of the curve” where quite a few people now wish they had been when they got taken…

The last time I checked the UK was getting more financial crime per head of population than any other Western Economy…

NobodySpecial July 22, 2026 2:57 PM

You’re only paranoid until hindsight shows you to be prophetic.

A little paranoia can be a healthy thing; the trick is to not let it take over your life to the point where you can’t live that life.

DIspair July 23, 2026 12:56 AM

@Clive

I absolutely do not do any kind of “On-line” financial, medical or other personal or private business.

Many institutions will setup accounts for you using your abandoned email as the user name and whatever the UK uses instead of SSN as your password. It doesn’t matter if you want them, it doesn’t matter if you asked, it’s for your convenience.

For certain odd transactions I want to have to go into the bank and be ided and finger printed. But the bank says that’s not convenient so email becomes the keys to the kingdom, whether I want it or not.

Glad July 23, 2026 2:34 AM

He is pilot, probably one of the worst pilots in the world.
This case shows that he is not too smart, I would say he is an idiot.

Chris Becke July 23, 2026 4:30 AM

There are clearly privacy concerns to navigate but the government is the ultimate source of truth when it comes to identity.

As such, bring your countries Post Office kicking and screaming into the future and make them the OAuth / Identity provider of final resort. They are the one organization with an actual “unassailable” paper and presence based process which provides a chain of evidence to unlock the rest of your digital identities safely.

Clive Robinson July 23, 2026 12:43 PM

@ Chris Becke, ALL,

With regards,

“government is the ultimate source of truth when it comes to identity”

“Truth No”, “Authority Yes”… As Dame Stella Rimington first female head of the UK’s MI5 observed,

My angle on ID cards is that they may be of some use but only if they can be made unforgeable – and all our other documentation is quite easy to forge.

“If we have ID cards at vast expense and people can go into a back room and forge them they are going to be absolutely useless.

http://news.bbc.co.uk/1/hi/uk_politics/4444512.stm

She was politely pointing out that the UK Government had a long history of forging ID documents not just for MI5 but the Met Police Special Branch and others, and had frequently been caught out at it.

So when it comes to,

“Dark men, doing dark deeds, in dark rooms, out of the light of truth and honesty…”

They may have the “authority” but rarely do they have truth or honour.

Clive Robinson July 23, 2026 1:32 PM

@ NobodySpecial,

“You’re only paranoid until hindsight shows you to be prophetic.”

Let’s say “predictive” rather than “prophetic”.

Nearly everything I warn of is based on simple logical steps that anyone can make for themselves with seldom any premise above “how would a scrote on the take” think about it…

The problem, is the crooks tend to be both more “focused” and faster on the uptake than the average jo(e).

A case of “old wine in new bottles” the crime is the same, the technology is new…

Clive Robinson July 23, 2026 1:44 PM

@ DIspair,

With regards,

“I want to have to go into the bank and be ided and finger printed. But the bank says that’s not convenient so email becomes the keys to the kingdom, whether I want it or not.”

Quite some years ago now our host @Bruce went into how banks and others “externalise risk” onto their clients and merchants.

To say the word “despicable” would be an understatement but when you are seen as “to big to fail” you also get seen as “to big to fight” thus they get away with it…

Toby July 23, 2026 1:59 PM

So then what can be done. This post could be eminently more useful if it would link to done solid advise. Obviously responding to unsolicited text messages is bad. As for passwords i don’t rely on Apple but have a third party password manager. How could they even get into the Apple account with a simple text message? It seems to me (but please correct me) that Apple two factor ID requires more than that.

Billy Jack July 24, 2026 6:43 AM

I have been playing with passkeys and have come to a horrifying conclusion.

If you have an account with passkeys available and an attacker can log in, they could add a passkey and link it to their own device. After that, they would continue to have full access to the account even if the you change the passwords.

You could think that you fixed the issues from an attacker and not realize that he still has full access to the account. Until this morning, I never considered the idea that I need to check all of my accounts on a regular basis to look for unauthorized passkeys.

I was wishing my local bank offered passkeys until I thought of this. Now I hope that they don’t offer passkeys in the future unless there is some way to lock the account to keep an attacker from adding a passkey for himself.

Now, I am not at all sure that passkeys are an improvement in security.

Am I wrong about this?

Ferentarius July 24, 2026 1:59 PM

@lurker

In the age of Revelation, men bore their signs openly, unafraid of the gaze of heaven or the judgment of their fellow man. Today we hide behind numbers and screens, thinking ourselves safe, yet we are more enslaved than those who carried their mark in the daylight. The tragedy is not that everyone had the same password, but that now we guard our little secrets as if they were kingdoms, forgetting that nothing is hidden from eternity.

Paul July 24, 2026 4:31 PM

@Billy Jack

While you are correct about adding a passkey and being able to connect to the account even if the password has been changed. Some sites will send an email alert when a new security control has been added.

Also without passkey enabled an attacker could get your password, change it an totally lock you out of the account. There is also the risk of shoulder surfing as a means of obtaining a password.

In my mind the real risk to passkeys is how do I log in to my account if I loose or destroy the device used to store the passkey.

Billy Jack July 24, 2026 8:25 PM

@Paul,

Those are some of my concerns, too.

From what I have read, it is somewhat common for scammers to watch the e-mails for a while looking for something that they can use. While some might change the passwords quickly, other would presumably wait a while.

The ability to log in if the device is lost, destroyed, or stolen is a concern, too. I avoided passkeys for a while for this reason. After trying them for a few days, the ones I tried still let me log in with username and password. Also with passkeys, multiple passkeys are permitted in those cases that I looked at. So if they got the passkey for one device, the passkeys for other devices would still be valid and permit a login.

One thing that I am considering is to try to set up an old cell phone to be able to handle passkeys. I had already thought about setting it up to use as a portable voip only phone connected via wifi.

And, for what it’s worth, since I no longer need to remember my passphrases, I am increasing my passphrases from six or seven semi-random words to ten random capitalized words separated by hyphens and with a random number after each word.

If the accounts are hacked as with the pilot in the article, it would clearly be a good idea to not only change passwords, but to also check to see if it has any new and unexplained passkeys.

One thing that bothers me about Google is that they give multiple ways to verify your identity. A hacker could presumably request a password change and then call the owner of the account on his cell phone, pretend to be Google security, and many people would happily give them the code. I would be happier if I could restrict which methods could be used. The first thing I would disable would be text messages because they are so untrustworthy.

Billy Jack July 24, 2026 10:26 PM

By the way, at least one of the sites where I added passkey gave no notice that a passkey had been added. The only notice I got was when I then increased the passphrase to 10 words separated by hyphens with a random digit after each word.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.