> If an account was hacked: change your email password first. Email is the master key — whoever controls it can reset every other account you own. Then turn on two-factor authentication, then work through your other accounts.
In This Chapter
- Why this chapter matters more than it looks like it should
- Passwords
- Phishing and scams
- Identity theft
- Privacy
- Subscriptions
- Your digital footprint
- AI safety
- 🎓 GOING DEEPER: Device hygiene
- 🎓 GOING DEEPER: Helping someone else without taking over
- 🌍 OUTSIDE THE US
- Common mistakes
- Key numbers
- Chapter recap
- Do this right now (30 minutes)
- This week (3 hours)
- This month (4 hours)
- Reflection
Chapter 32 — Digital Life: Passwords, Privacy, Scams, and Subscriptions
🆘 WHAT TO DO RIGHT NOW
If an account was hacked: change your email password first. Email is the master key — whoever controls it can reset every other account you own. Then turn on two-factor authentication, then work through your other accounts.
If you sent money to a scammer: call your bank immediately. Speed is everything. Then report at reportfraud.ftc.gov and ic3.gov. Do not pay anyone who promises to recover it — recovery services targeting scam victims are almost always the same operation coming back.
If you're being sextorted (someone threatening to share intimate images): do not pay, do not send more. Paying escalates it. Save evidence, block them, report to the platform and to ic3.gov. If you're under 18, NCMEC's Take It Down (takeitdown.ncmec.org) helps remove images. 1-800-843-5678. This is a crime committed against you, and law enforcement treats it that way.
If you reused one password everywhere: that is the single largest security risk most people have, and it is fixable in one afternoon. Skip to "Passwords."
If you're getting urgent calls or texts about money: hang up and call the organization back on a number you looked up independently. That single habit defeats most phone scams.
Why this chapter matters more than it looks like it should
For anyone under about thirty-five, the realistic financial risks are not "picking the wrong index fund." They're: a reused password leading to a drained account, a phishing email leading to identity theft, a romance or investment scam, and $2,000 a year of subscriptions nobody remembers signing up for.
Those are all preventable, and the prevention takes about one afternoon.
There's also a second thing this chapter is about, which is quieter: the accumulated record of your online life is now a thing employers search, insurers analyze, data brokers sell, and — in an increasing number of contexts — courts subpoena. Managing it deliberately is a life skill in the same way managing your credit report is.
Who is actually coming for you
The mental picture most people have is a person in a hoodie who chose them specifically. That's not what happens. What happens is a script and a call center. A script takes a hundred million stolen email/password pairs and tries them against a hundred sites overnight, at no cost. A call center dials a hundred thousand people a day and reads from a printed page when someone answers. Neither one picked you. You were in a spreadsheet.
That's good news, because it tells you what defense looks like. You are not trying to beat an expert who has decided to ruin you. You're trying to be slightly more expensive than the next person on the list. A unique password stops the script cold. A ten-second pause and a callback stops the call center. That's most of it.
There's a smaller category — a stalker, an abusive ex, a family member who knows your passwords — where you are the target and the defenses have to be more thorough. The sections on account recovery and image abuse below are written with that in mind, alongside Chapter 35.
Passwords
The problem
Reusing passwords is the single biggest security mistake most people make.
Here's why it's so damaging. Companies get breached constantly — billions of credentials have been exposed. Attackers take those username/password pairs and try them automatically against every major service. This is called credential stuffing, it's fully automated, and it works because most people reuse passwords.
So a breach at a forum you used once in 2016 becomes access to your email, which becomes access to everything.
Notice what that sentence does not require. It doesn't require your bank to be hacked. It doesn't require you to click anything. It doesn't require anyone to know your name. The weakest site you ever signed up for sets the security of every account that shares its password.
Small variations don't help. Fenway2019! and Fenway2020! and Fenway!Netflix look different to you and identical to the software, which mutates passwords automatically — appending years, incrementing numbers, swapping the site name in. If you have a "system," the system is the password, and it's already public.
Check whether you've been breached: haveibeenpwned.com. It's run by a well-known security researcher, it's free, and it never asks for your password. Most people turn up in five to thirty breaches and had no idea. Check every address you've ever used, including the one from high school — a breach from 2013 still matters if you're still using that password anywhere. Stolen credentials don't expire; they get resold for years.
⚠️ THE TRAP: security questions
"What was your mother's maiden name? What street did you grow up on? What was your first pet's name?"
These are not secrets. They're public records and Facebook posts. Maiden names are in genealogy databases. Street history is on every people-search site. Your first pet is in a photo caption. High school, birth city, and your first car are all in data broker profiles anyone can buy for $20.
These questions were designed before that was true and never updated, so they now function as a backdoor around your good password. Customer service agents also use them to verify callers, which is exactly how account-takeover-by-phone works.
What to do instead: lie. Treat every security question as a second password. Answer with a random string from your password manager and save the question and the fake answer in the notes field. There is no rule that the answer has to be true.
And those quizzes that go around asking for your first concert, your childhood street, your first car? Look at that list again.
The solution: a password manager
One tool solves this completely.
A password manager generates a unique, random, long password for every account, stores them encrypted, and fills them in for you. You remember one master password.
Options: - Bitwarden — free tier is genuinely complete, open source, audited. The right default recommendation. - 1Password — excellent, $36/year, best-in-class interface and family sharing. - Apple Passwords / Google Password Manager — free, built in, and much better than nothing. Weaker if you use multiple ecosystems. - KeePassXC — free, offline, local storage only, for people who don't want cloud sync.
Avoid: storing passwords in a browser without a master password, a spreadsheet, a notes app, or a piece of paper in your desk (though a paper list in a locked safe at home is genuinely better than reuse — the realistic threat to most people is remote, not a burglar).
Note: LastPass suffered significant breaches in 2022 in which encrypted vaults were stolen. If you still use it, migrating is reasonable.
Setting it up
1. Choose a strong master password. This is the one you must remember.
Use a passphrase: four or five random words. correct-horse-battery-staple style. Long and memorable beats short and complicated — Tr0ub4dor&3 is both harder to remember and easier to crack than a five-word passphrase.
Here's why, because understanding it means you'll never be talked out of it. Cracking software guesses in the order humans actually choose: dictionary words, then dictionary words with a capital in front and a number and a ! on the end, then leetspeak substitutions (a→@, o→0, e→3), then all of it combined. Every "complexity rule" a website taught you is a rule the cracking software already knows. What it can't shortcut is length plus randomness. Six random words is astronomically harder to guess than eleven characters of clever human substitution, and you can actually remember it.
Let the manager generate it — Bitwarden, 1Password, and KeePassXC all have a passphrase generator. A phrase you invented yourself is not random; human word choice clusters hard, and song lyrics, movie quotes, and Bible verses are all in wordlists. Five or six words, hyphenated. Then say it out loud twenty times and type it twenty times — that's the whole memorization process, and muscle memory takes over within a week.
Write the master password down once and put it in a safe (Chapter 30) or give a sealed copy to someone you trust. Losing it means losing everything: a properly designed password manager cannot recover it for you, and no amount of calling support changes that.
Save the recovery code with it — Bitwarden's recovery code, 1Password's Secret Key and Emergency Kit. It's separate from the master password and you'll need it to add a device if you're locked out.
And set up emergency access. Most managers let you name a trusted person who can request access after a waiting period you choose, during which you can deny it. The digital version of "somebody has to be able to find things if I'm hit by a bus" (Chapter 30).
2. Turn on two-factor authentication on the password manager itself.
3. Import your saved browser passwords.
4. Change the important ones first, in this order: - Email — the master key - Banking and financial - Phone carrier account (see SIM swapping below) - Anything with a stored payment method - Social media - Everything else, gradually — you can do it as you log in over the following months. You do not have to do all 200 in one sitting.
5. Use the manager's audit feature to find reused and weak passwords. Bitwarden calls it Reports; 1Password calls it Watchtower. It will tell you how many times you reused one password and which of your accounts are in known breaches. The number is usually shocking and that's fine — it's a to-do list, not a verdict.
6. Install it everywhere — browser extension, phone app, and autofill turned on in your phone's settings. A manager you have to copy and paste from is one you'll abandon in three weeks. Autofill also has a security bonus: it won't offer your bank password on a fake bank site, because the domain doesn't match. When the manager declines to fill, that's a warning worth heeding.
What this looks like in practice
Dani, 26, gets an Instagram notification at 2 a.m.: password changed, email changed. She can't get back in.
What actually happened, in order. In 2019 she signed up for a fan forum with Dani.Salcedo1998!. The forum was breached in 2021 and the dump was traded online. Years later a script tried that pair against 200 sites and hit on her old Yahoo address — still the recovery email on her Instagram. From that inbox the attacker searched "verification," "reset," and "invoice," found her Instagram and her food-delivery account, reset both, changed the email on file, and turned on 2FA with their own number. Then they ran a crypto pitch at her 4,000 followers.
Total attacker effort: about nine minutes of a person's time, on top of a script that ran itself. It cost her eleven days of recovery, two friends who sent money to the "investment," and $340 in food orders in another state before the card was frozen.
What would have prevented all of it: a unique password on the Yahoo account, or 2FA on it, or deleting it and removing it as a recovery address five years earlier. Any one of the three, alone.
That abandoned email address you haven't logged into since college is not harmless. It's a spare key to your house, left under a rock. Secure it or close it — and before you close it, remove it as the recovery address everywhere it's listed.
Two-factor authentication (2FA)
A second step beyond your password. Turn it on everywhere it's offered, especially email, banking, and your phone carrier.
In order of security:
- Hardware security key (YubiKey and similar, roughly $25–55 as of 2025) — the strongest available and essentially immune to phishing, because the key checks the site's real domain before it will respond. A fake login page can't extract a code, because there's no code to type. Buy two and register both — one on your keyring, one in your safe.
- Passkeys — the emerging replacement for passwords entirely. Same phishing-resistant math, but the key lives in your phone, laptop, or password manager and unlocks with your face or fingerprint. Use them where offered. More below.
- Authenticator app (Aegis, Ente Auth, Google Authenticator, or your password manager) — free, works offline, defeats credential stuffing completely. It does not defeat a real-time phishing site that asks for the code and relays it instantly, which is now common — so "never click links" still matters even with an app.
- SMS codes — the weakest form, and still far better than nothing. Vulnerable to SIM swapping, and useless with no signal. But it stops 100% of automated credential stuffing, which is what's most likely to happen to you. If SMS is the only option offered, turn it on.
Email-based codes are only as strong as your email account. Everything routes back to email — that's the next section.
The realistic setup: authenticator app on everything, a hardware key on email and your main bank if you can spend $50, SMS only where nothing else exists — and a carrier port-out lock either way.
Passkeys, specifically
A passkey replaces the password rather than adding to it. When you create one, your device generates a matched pair of keys: one stays locked on your device, one goes to the website. Logging in means your device proves it holds the private half. Nothing secret is ever typed, sent, or stored on the company's servers, which means a breach at that company can't leak your credentials and a fake site can't collect them.
Where they work: Google, Apple, Microsoft, Amazon, PayPal, and a growing list — look for "passkey" in an account's security settings.
The honest caveats: recovery is the weak spot, because a passkey stored only in iCloud Keychain or Google Password Manager is only as protected as that account — which is usually protected by a password. Storing passkeys in a cross-platform password manager instead is the cleaner answer. Almost every site also keeps the password as a fallback, so a passkey raises your floor without removing the old risk. And register a second method, because one passkey on one phone is a lost phone away from a locked account.
⚠️ THE TRAP: SIM swapping
An attacker convinces your mobile carrier to transfer your number to their SIM — using social engineering, a bribed employee, or stolen personal data. Then every SMS code goes to them, and they reset your email, then your bank.
This has been used to steal very large sums, particularly from people known to hold cryptocurrency.
Prevention: - Call your carrier and add a port-out PIN or a "port freeze" / "number lock." Ask for it by name. This is the single most effective step and takes ten minutes. - Use an authenticator app or hardware key instead of SMS wherever possible. - Don't publicize crypto holdings. - Add a separate PIN to your carrier account.
Save your backup codes. Every service gives you eight or ten one-time recovery codes when you enable 2FA. The screen appears once. Most people click past it.
Do this instead, in about forty seconds: copy the codes into the notes field of that account's entry in your password manager, and hand-write one copy for the envelope in your safe (Chapter 30). Storing them only inside the account they unlock is not storage; it's a circle.
People lock themselves out permanently by losing a phone with no backup codes — permanently, as in the account is gone, because a service that could restore access to someone claiming a lost phone could restore it to an attacker claiming the same. That trade-off is deliberate. When you replace a phone, move your authenticator app before you wipe the old one. Aegis, Ente Auth, and 2FAS have export features; Google Authenticator syncs to your Google account. Turn that on now, not the day you drop your phone in a lake.
The account recovery problem
Here is the thing that reframes everything else in this chapter:
Your accounts are only as secure as the weakest way to get back into them.
You can put a hardware key on your bank account, and it doesn't matter if the bank's "forgot password" flow emails a reset link to a Hotmail address you last checked in 2014. Attackers don't attack the front door you reinforced. They attack the recovery path, which almost nobody ever looks at.
So audit the recovery path. Twenty minutes, and almost nobody does it.
For your email and your top five accounts, open Security settings and check all four:
- Recovery email address. Still an account you control and have secured? Old work addresses, dead school addresses, and an ex-partner's shared account are the three classic disasters.
- Recovery phone number. Still yours? A number you gave up gets reassigned to a stranger, usually within months. That stranger now receives your reset codes.
- Active sessions and devices. Every major service lists where you're signed in. Sign out of anything you don't recognize — and anything you do recognize but no longer own.
- Forwarding rules, filters, and connected apps. This is the one attackers actually use. A compromised inbox usually gets a quiet rule added: forward everything to X, then mark as read and archive. You'd never notice. Check Gmail's Settings → Forwarding and POP/IMAP and Filters, or Outlook's Rules.
Then give email the strongest protection you have. Not your bank — email. Whoever holds your email can reset your bank at leisure.
An advanced move: create a second, boring email address used only as the recovery address for important accounts. Never email anyone from it, never sign up for anything with it. Nobody knows it exists, so nobody targets it.
💸 WHEN YOU CAN'T AFFORD THE RIGHT OPTION
Almost nothing that genuinely matters in this chapter costs money. That is unusual in this book, and worth saying plainly.
Free, and it's the whole core of the chapter: - Bitwarden's free tier — unlimited passwords, unlimited devices, syncs everywhere. Not a crippled demo; millions of people use it permanently. 1Password is nicer; free Bitwarden is sufficient. - Authenticator apps — Aegis, Ente Auth, 2FAS, Google Authenticator. - Operating system updates and disk encryption — already installed, already paid for. The highest-value security habit in this chapter is turning on automatic updates, and it costs a restart. - Credit freezes at all three bureaus — free by federal law, for you and your children. Anyone charging for a freeze is selling you something you can do yourself in twenty minutes. - haveibeenpwned.com, an IRS Identity Protection PIN, Signal, and uBlock Origin — all free. - A family safe word — free, one phone call, and the best available defense against voice cloning.
Skip without guilt: paid VPNs, "identity theft protection" subscriptions (mostly monitoring you can do free, and they prevent nothing), antivirus beyond what Windows and macOS include, and data broker removal services — tedious to do yourself, but free.
If your only computer is your phone: all of it works on a phone — the manager, the authenticator, the credit freezes, the subscription audit through your bank's app, the privacy settings, the name search. Only the data broker opt-outs are genuinely harder; do those ten minutes at a time. Nothing here requires a laptop.
If you're on a shared or public computer — a library, a school lab, a shelter, a job center, a friend's laptop — treat it as a machine reading over your shoulder, because it might be: - Use a private / incognito window for everything. - Say no to every "save password?" and "stay signed in?" prompt. This is the one that strands people. - Sign out of each account explicitly, then close the whole browser — closing the tab is not signing out. Log out of the machine itself and empty the Downloads folder. - Avoid banking on a machine you don't control, because a keylogger defeats even a perfect password. If you have no choice, change that password afterward from a device you do. - Take the 2FA code from your phone's authenticator app, not from SMS on a shared screen.
If your access to a private device is limited, the password manager matters more, not less — you're never retyping a password on an untrusted keyboard.
Phishing and scams
Phishing
An attempt to get you to hand over credentials or money by pretending to be someone you trust.
Descriptions of phishing are less useful than a real one with the tells marked. Here's a composite of the standard bank-impersonation email, numbered.
╔══════════════════════════════════════════════════════════════════════════════╗
║ INBOX ║
╠══════════════════════════════════════════════════════════════════════════════╣
║ ║
║ From: Chase Bank Security ① ║
║ <alerts@chase-secure-verify.com> ② ║
║ To: undisclosed-recipients:; ③ ║
║ Subject: URGENT: Unusual sign-in - account locks in 24 hours ④ ║
║ Date: Saturday, 3:47 AM ⑤ ║
║ Attached: Account_Verification_Form.html (14 KB) ⑥ ║
║ ─────────────────────────────────────────────────────────────────── ║
║ ║
║ [ CHASE ] <- logo image, loaded from a free image host ⑦ ║
║ ║
║ Dear Valued Customer, ⑧ ║
║ ║
║ We have detected an unusual sign-in attempt on you're account ║
║ from a device in another country. For you protection we have ⑨ ║
║ placed a temporary restriction on all transactions. ║
║ ║
║ You must verify your identity within 24 hours or the account ║
║ will be permanently closed and remaining funds forfeited. ④ ║
║ ║
║ ┌──────────────────────────────────┐ ║
║ │ VERIFY MY ACCOUNT NOW > │ hover reveals the real ⑩ ║
║ └──────────────────────────────────┘ destination: ║
║ chase.verify-id-secure ║
║ .co/login?ref=9f2a ║
║ ║
║ If you did not authorize this, confirm your card number, PIN, ║
║ and Social Security number on the secure form above. ⑪ ║
║ ║
║ Sincerely, ║
║ Chase Online Security Department ║
║ ║
║ Questions? Reply here or call our fraud line: (888) 555-0142 ⑫ ║
║ ║
╚══════════════════════════════════════════════════════════════════════════════╝
① The display name is free text. Anyone can type "Chase Bank Security" into that field. It is not verified by anything. Your mail app shows you the display name and hides the address, which is a design decision that helps attackers. On a phone, tap the sender name to expand it. On a computer, hover.
② The actual domain is the whole ballgame. Read it right to left. The real owner is the label immediately before the final .com: in chase-secure-verify.com, the owner is chase-secure-verify, which is not Chase. Compare — chase.com (real), secure.chase.com (real, a subdomain of chase.com), chase-secure-verify.com (not), chase.com.login-verify.net (not; the owner is login-verify). Find the last dot, read backward one label. That's who's really writing to you.
③ You're not the only recipient. Real account alerts are addressed to you. "Undisclosed recipients," a blank To: field, or a list of strangers means bulk mail.
④ Urgency and threat, stacked. Not decoration — this is the actual mechanism of the attack. Urgency shuts down the part of you that would otherwise notice ②. Real banks restrict an account and then wait for you; they don't set a 24-hour clock in an email. Any message that needs you to act right now has just told you why it needs to be fake.
⑤ Sent at 3:47 a.m. on a weekend. Not proof by itself, but campaigns are timed for when you're groggy and support lines are closed.
⑥ An unexpected attachment, specifically an .html file. Opening it renders a fake login page from your own computer, sailing past filters that would have blocked a link. Never open .zip, .iso, .htm, .js, .scr, .exe, or an Office file that asks you to "Enable Content," from an unexpected sender. Banks don't send forms as attachments.
⑦ The logo is real, and means nothing. It was right-click-saved from the bank's site. A correct logo is evidence of a working mouse. Same for the fonts, the colors, and the copied footer full of real legal disclaimers.
⑧ "Dear Valued Customer." Your bank knows your name. It's printed on the card. Generic greetings mean the sender doesn't have your name — which means they don't have your account either. Spear phishing will use your real name, though: a generic greeting is a reliable tell when present; a personal one proves nothing.
⑨ "you're account," "you protection." Grammar tells are dying fast — AI writes clean phishing now — so treat bad grammar as a strong signal when you see it and never treat good grammar as reassurance.
⑩ Hover the link before you click. Always. On a computer, hold the pointer over the button and read the URL in the bottom-left corner. On a phone, press and hold until a preview appears, read it, then cancel. Here the button says Chase and goes to chase.verify-id-secure.co — same backward read, and the owner is verify-id-secure. Button text is a costume; the URL is the identity. Watch for lookalike characters too: paypa1.com, rnicrosoft.com (r-n, not m).
⑪ The ask. No bank, ever, under any circumstance, asks for your full card number, PIN, password, or Social Security number by email, text, or an inbound call. Your PIN isn't information the bank needs from you; they already have it. This line alone identifies the message without reading anything else.
⑫ The number is theirs. Call it and a polite, professional person answers "Chase fraud department" and walks you through handing over everything. The only phone number for your bank is the one on the back of your physical card.
What to do with this email: nothing in it. Open a new tab, type your bank's address yourself, and log in. Anything genuinely wrong will be waiting there. Then report it — use your mail client's "Report phishing" button, and forward scam texts to 7726 (spells SPAM), which works on most US, UK, Canadian, and Australian carriers.
Red flags, condensed:
- Urgency. "Your account will be closed in 24 hours." "Immediate action required." Urgency exists to bypass thinking.
- A generic greeting — "Dear Customer."
- A sender address that's wrong —
service@paypa1-security.com. Check the actual domain, after the last dot before the slash. Display names are trivially faked. - Links that don't match. Hover (or long-press on mobile) to see the real destination.
- Requests for credentials, SSN, or payment info.
- Unexpected attachments.
- Grammar and formatting errors — though AI has made this a much weaker signal than it used to be.
- A too-good offer.
- A threat — legal action, arrest, account closure.
The one rule that beats all of this:
Never click a link in an unexpected message. Go to the site directly by typing the address, or call the number on the back of your card.
If it's real, you'll find it there. If it isn't, you just defeated the attack.
Spear phishing targets you specifically using details from your social media or a breach. It's much more convincing. The same rule still works.
Business email compromise — a message appearing to come from your boss, your landlord, or a title company, changing payment instructions at the last minute. Always verify a change in payment instructions by phone, using a number you already had. This is how people lose home down payments.
The workplace version reads: "Hey, are you at your desk? Going into a meeting — can you grab some gift cards for the team? I'll reimburse you." No manager anywhere has ever legitimately needed you to buy gift cards. New employees get targeted within days of a LinkedIn "excited to announce I've joined…" post (Chapter 21).
Text message scams (smishing)
Texts have become the highest-volume scam channel, because they're cheap, they land on a device you check reflexively, and phone screens hide URLs.
The package one. "USPS: your package could not be delivered due to an incomplete address. Update here: [link]." You probably do have a package coming — everyone always does — which is why it works. The link leads to a real-looking tracking page that asks for a $1.95 "redelivery fee" and your card number. The $1.95 isn't the crime; harvesting your card is. The tell: carriers don't text about address problems from a random number, and they don't charge redelivery fees by text. The verification step: open the carrier's own app, or paste your tracking number into the carrier's real site.
The unpaid-toll text is identical in structure: small believable amount, big threatened penalty, card-harvesting page.
The "wrong number" text. "Hi Jennifer, are we still on for Thursday?" Replying politely is the entire hook — it confirms a live human and opens a conversation that becomes a romance or crypto approach weeks later. Don't reply, not even to say you're not Jennifer.
The "send me the code" message, usually from a friend's hacked account. That code is your 2FA code, and forwarding it hands over your account. Nobody legitimate ever needs a code that was texted to you.
The bank alert text. "Did you authorize a $487.22 charge at Best Buy? Reply Y or N." Replying N triggers a call from the "fraud department," which asks you to move money "to a safe account." Reply to nothing. Open your bank app.
Handle all of it the same way: don't tap, don't reply, don't unsubscribe (STOP confirms a live number). Forward to 7726, then block and delete. iPhone: Settings → Messages → Filter Unknown Senders. Android: Messages → Spam protection.
Phone scams
Government impersonation. "This is the IRS/Social Security Administration/police, you owe money and will be arrested."
The IRS initiates contact by mail. It does not call demanding immediate payment. Social Security does not threaten to suspend your number. No government agency accepts gift cards, wire transfers, or cryptocurrency.
Tech support. Two versions, same ending.
The pop-up: a browser window takes over your screen with sirens, a flashing warning, and "Windows Defender has detected a virus — call this number immediately. Do not restart your computer." It is a web page. It cannot see your computer. It is doing nothing but playing a sound file and refusing to close. The instruction not to restart exists because restarting fixes it.
What to do: close it. Force-quit the browser (Ctrl+Shift+Esc on Windows → End task; Cmd+Option+Esc on Mac). If it's full-screen, press Esc or F11 first. Restart if you need to. When you reopen the browser, decline "restore tabs." Nothing is infected.
The call: "This is Microsoft Support, we've detected suspicious activity on your machine." They walk you through a system log full of routine yellow warnings, present it as proof of infection, then ask you to install AnyDesk, TeamViewer, or LogMeIn so they can "clean it." Once inside, they either lock the machine and demand payment, or open your banking site, fake a "refund" that looks like an overpayment, and ask you to send back the difference in gift cards.
Microsoft, Apple, Google, your ISP, and your bank do not call you about your computer. Never install remote-access software at the request of someone who contacted you first. That one sentence covers every version of this.
If you already gave someone remote access — and plenty of careful people have — in this order: disconnect from the internet; uninstall the remote-access app; from a different device, change your email password and then your banking passwords; call your bank on the number on your card; run a full scan with the built-in tool and update everything; freeze your credit and report at reportfraud.ftc.gov. If they reached your banking, or you can't reconstruct what they did, back up your files and reinstall the operating system. A day of annoyance, and the only way to be certain.
Caller ID is not evidence. Spoofing the number on your screen is free — scammers routinely display your bank's real published number or a government line. Treat every inbound call as a stranger, regardless of what your phone says.
The grandparent scam. "Grandma, I'm in jail, don't tell Mom, send bail money." A second voice usually takes over as the "public defender" with an amount and a payment method. The "don't tell Mom" is doing real work: isolation is the mechanism, and it stops the one phone call that would end the scam in ten seconds. Now enhanced with AI voice cloning — any public clip with your voice in it, a TikTok or a voicemail greeting, is enough.
The defense that works: a family safe word. Agree on one now with parents, grandparents, children, and anyone who might be targeted. If someone calls in distress asking for money, ask for the word. This costs nothing and it is the single best defense against voice cloning.
Utility shutoff. "Pay immediately or your power is cut off." Hang up, call the utility on the number on your bill.
Bank fraud department. "We detected fraud — to reverse it, send yourself money via Zelle." No bank asks this, ever. Hang up, call the number on your card.
The universal defense: hang up and call back on a number you looked up yourself. Not a number they gave you. Not the number on your caller ID. The number on the back of your card, on a statement, or on the organization's real website that you navigated to yourself.
Real organizations have no problem with this. A real fraud department will say "of course, call us back at the number on your card." A scammer will tell you there's no time, that the line is different, that you'll be transferred to a special department, or that calling back will make things worse. That resistance is the confirmation.
You are allowed to hang up on anyone. No explanation, no apology, mid-sentence if you like. Politeness is the lever every one of these scripts pulls, and you are permitted to not have any.
⚠️ THE TRAP: the payment method is the tell
You do not have to identify the scam. You do not have to be clever, or informed, or good with computers. You just have to know which payment methods legitimate organizations never use — because that one fact catches essentially all of them.
If anyone asks you to pay with any of these, it is a scam. No exceptions worth entertaining: - Gift cards — Apple, Google Play, Target, Steam, anything. The back of the card says it isn't for payments. No government agency, utility, bail bondsman, employer, or tech company has ever been paid in gift cards. - Wire transfer — Western Union, MoneyGram, or a bank wire. Instantly final, unrecoverable after a short window, designed for exactly that. - Cryptocurrency, including the "crypto ATM" at a gas station. Irreversible by design. The physical crypto kiosk is now a standard step in phone scams targeting older adults, which is why several states have started capping and regulating them. - Peer-to-peer apps to a stranger — Zelle, Venmo, Cash App. Built to work like cash between people who already trust each other, and your protection when you authorize the payment is far weaker than with a card. - Payment apps to "yourself" to "reverse fraud." Not a real banking operation. It exists only in this scam. - A "refund" that requires you to send money back. Nobody has ever accidentally overpaid you. - A check they mail you, which you deposit and then send part of onward. It bounces two to four weeks later and the bank takes back every dollar (Chapter 3).
Who profits: these methods are chosen precisely because they're irreversible. The scammer isn't picking gift cards for convenience — they're picking them because the money can never come back.
For anything real, use a credit card. It has the strongest dispute rights of any payment method in American law (Chapter 28).
Teach this box to everyone you love. It's the highest-yield thing in the chapter and it fits on an index card.
Romance and "pig butchering" scams
The pattern: 1. Contact from a "wrong number" text, a dating app, or social media 2. Weeks or months of genuine-seeming relationship building 3. Eventually, an investment opportunity — usually crypto, on a platform that looks professional 4. Small "profits" you can withdraw, which builds trust 5. Larger investments 6. When you try to withdraw significant amounts: fees, taxes, "compliance holds" 7. The money was never real and is gone
These are run by industrial-scale criminal operations, many of which are staffed by trafficked workers held in compounds. Losses are typically total and often catastrophic — people lose retirement accounts and homes.
Red flags: a "wrong number" text that turns friendly, someone who won't video call or always has a reason not to, moving quickly off the dating app to WhatsApp or Telegram, professing strong feelings fast, a lifestyle that doesn't match their story, and eventually — always — an investment opportunity.
If someone you've never met in person mentions an investment, it is a scam. No exceptions worth risking.
The verification step: ask for a live video call at a time you pick, right now, and ask them to hold up three fingers. Every excuse — broken camera, work rules, bad connection, "don't you trust me?" — is the answer. Reverse image search their photos too; stolen model and military photos are the norm.
If you're in one now: stop sending money today, screenshot everything before you're blocked, and check whether the "platform" appears on the CFTC's or your state securities regulator's warning lists. Don't tell them you've figured it out until the evidence is saved — accounts get scrubbed fast.
If someone you love is in one, this is the hardest conversation in the chapter. Attacking the relationship makes people defend it. What works better: "I'm not going to tell you what to do. Will you do one thing with me — try to withdraw $500 today and see what happens?" The withdrawal test is the scam's only unavoidable weak point, because the money isn't there. Then be there without saying "I told you so."
Job and money-mule scams
Fake job offers have exploded because remote hiring made "we'll never meet in person" normal (Chapter 19).
- The overpayment check. You're hired, and they mail you a check for $3,800 to buy a laptop from "their approved vendor." You deposit it, the money appears, you send $3,200 onward. Two to four weeks later the check is returned as counterfeit and your bank takes back the full amount — from your account, whether it's there or not (Chapter 3). Tell: any job where money flows out of you. Real employers buy their own equipment, and they don't ask you to pay for training, certification, background checks, or "onboarding software."
- Reshipping, "payment processing," and "financial agent" roles, where parcels bought with stolen cards or funds from other victims move through your address or your bank account. This is a crime you are committing, felony-grade even when you didn't know, and the arrests land on the name on the label.
- Task scams — "rate hotels, earn $200/day" — small payouts, then a demand that you deposit your own funds to "unlock" better tasks.
- The interview held only on Telegram or Discord, by a "recruiter" whose email doesn't match the company's domain.
The verification step: find the company's real website yourself, check whether the job is on their own careers page, then call the main number. Never accept an offer from a company that never interviewed you on video.
Rental and marketplace scams
- Rental scams (Chapter 9) — a listing below market, a "landlord" traveling abroad, keys mailed after you wire the deposit. The photos are copied from a real listing elsewhere. Tell: any pressure to pay before you've stood inside the unit. Verification: look up the property on the county assessor's site and confirm the owner's name matches who you're talking to.
- Marketplace and ticket scams. Meet in daylight at a police department's designated exchange lot — most have one, on camera. Pay cash in person or with something that has dispute rights. Never Zelle a stranger.
- The "verification code" trick on Marketplace. A "buyer" asks you to send back a code they just texted you, to "prove you're real." They're creating an account in your name using your number.
- Fake invoices for antivirus or subscriptions you don't have — a PDF with no link, just a "cancellation" number. Calling it is the scam. Look for the charge on your actual statement. If it isn't there, there's nothing to cancel.
- Charity fraud, especially after a disaster. Check charitynavigator.org or give.org, give through the organization's real site, never by gift card or crypto.
- QR code scams — a sticker over the real code on a parking meter or EV charger. Read the URL your phone previews before you tap.
- Recovery scams, targeting people already scammed, using victim lists sold between operations. Nobody legitimate charges an upfront fee to recover scammed funds, and no government agency charges anything.
If you're scammed
Read this before it happens, because the outcome is decided by how fast you move in the first hour, and the thing that slows people down is embarrassment.
So, the honest part first. These are professional operations running scripts refined across hundreds of thousands of calls, and they successfully take money from doctors, accountants, cybersecurity professionals, and the person who wrote the fraud policy at a bank. Shame isn't incidental to the scam; it's part of the design. The isolation it creates is what stops you from calling the bank for two days, and two days is often the difference between recovering the money and not. Being scammed is something that was done to you.
Now move.
Within the first hour
1. Stop all contact and all payments. Do not send "one more" to unlock the withdrawal. There is no withdrawal.
2. Call your bank or card issuer on the number on your card. Not the app chat. Say this, in these words:
"I need to report fraud on my account. I sent a payment as the result of a scam. I want to know if it can be recalled, and I want to place a fraud alert on my account. Please note the date and time of this call."
If it was a wire, say "wire recall" and ask them to contact the receiving bank immediately — wires are sometimes recoverable within hours if the money hasn't been withdrawn. If it was a card, say "unauthorized charge" if you never gave your number, or "dispute" if you did; those are different processes. If it was Zelle, Venmo, or Cash App, report it in the app and to the bank, and ask whether your bank participates in any imposter-scam reimbursement program.
3. If your card number is out, kill the card. New number, not just a lock.
4. Change passwords from a device you trust — email first, then the compromised account, then anything sharing that password.
The same day
5. Report it. These do different things, so do all of them: - reportfraud.ftc.gov — the FTC's consumer fraud report; feeds law enforcement databases. - ic3.gov — the FBI's Internet Crime Complaint Center. This is the one that matters for crypto and wire fraud, because the FBI's recovery asset team can sometimes freeze funds still sitting in a domestic account — realistically only within days. - Your state attorney general's consumer protection division. - The platform where it happened, and — if mail or a check was involved — the U.S. Postal Inspection Service, which has real jurisdiction over mail fraud.
6. File a police report. People skip this because "they won't do anything." File it anyway — banks, insurers, and credit bureaus frequently require a report number, and it's the paperwork that makes later disputes work.
7. Freeze your credit if any personal information was exposed (Chapter 4).
8. Write it all down while it's fresh — dates, amounts, numbers, usernames, wallet addresses, exact wording. Screenshot before you block, because blocking often hides the history.
The honest expectations
Credit card: good odds; dispute rights are strong. ACH or debit: mixed, and speed matters enormously. Wire: a small window, then gone. Peer-to-peer app you authorized yourself: legally weak — though this area has been the subject of regulatory action and litigation that keeps changing, so ask anyway, in writing, and escalate to the CFPB at consumerfinance.gov/complaint if refused. Crypto or gift cards: almost never recovered, though report gift cards to the issuer immediately in case the balance hasn't been drained.
Nobody who contacts you afterward can get it back. Anyone who says otherwise is the same operation, or one that bought your name from them.
9. Tell someone. A friend, a sibling, a support group. Isolation is what allows the second round. The AARP Fraud Watch Network helpline (1-877-908-3360) is free, open to any age despite the name, and staffed by people who talk to scam victims all day and will not make you feel stupid.
Sextortion and intimate image abuse
This deserves its own section, said plainly.
If someone is threatening to share your intimate images unless you pay or send more: you have not done anything wrong. Taking or sharing a photo with someone you trusted is not a crime and not a character flaw. The crime is theirs. Everything below assumes that, and law enforcement increasingly does too.
The most common version: a stranger on Instagram, Snapchat, or a dating app builds rapport over hours or days, moves to video, and records or fabricates. The demand arrives within minutes, with a countdown and a screenshot of your follower list. It targets teenage boys and young men at enormous volume, and it has driven people to suicide. The speed and the panic are deliberate.
What to do:
- Do not pay. Paying doesn't end it — it marks you as someone who pays, and the demands escalate. This is consistent across essentially every documented case.
- Do not send more images, and stop engaging or negotiating.
- Save evidence before you block: screenshots of the profile, the username, the messages, the payment account they gave you. Don't delete the conversation.
- Then block and report the account on the platform.
- Report it: ic3.gov and your local police. If the victim is under 18, NCMEC's CyberTipline and 1-800-843-5678.
- Get the images blocked from spreading. Under 18 — including if you're an adult now but the images were taken when you were a minor — takeitdown.ncmec.org. 18 or over — StopNCII.org, run by a UK nonprofit and used by Meta, TikTok, Reddit, Bumble, and Snap. Both are free, and both create a digital fingerprint of the image on your own device — you never upload the image itself. Google's removal tool can also pull non-consensual explicit imagery out of search results.
- Tell one person in real life — a friend, a parent, a counselor, an RA. The isolation is the leverage. If you're in crisis, 988, call or text.
- If you're a minor, tell a trusted adult even though it feels impossible. You will not be in trouble. The law treats you as a victim, and the adults who handle these cases see this constantly and know exactly what it is.
Most states criminalize non-consensual distribution of intimate images, and federal law here has expanded, including provisions addressing AI-generated and "deepfake" imagery. An image being faked doesn't mean you have no recourse — increasingly the opposite. Specifics vary by state; check with legal aid or your state AG (Chapter 28).
Identity theft
Covered legally in Chapter 28 and practically in Chapter 4. The consolidated version:
Prevention
- Freeze your credit at all three bureaus. Free. This is the single most effective step and it prevents new accounts from being opened in your name.
- Freeze your children's credit too.
- Don't carry your Social Security card.
- Shred documents with personal information.
- Use a locking mailbox or a PO box; mail theft is a common vector.
- Opt out of pre-approved credit offers at optoutprescreen.com (free, official).
- Be careful what you post — birthdate, hometown, mother's maiden name, pet names, and high school are all common security question answers.
- Watch for the absence of mail — if expected statements stop arriving, someone may have filed a change of address.
Detection
- Unexpected bills or collection notices
- New accounts on your credit report
- Denied credit unexpectedly
- Missing mail
- A tax return rejected as already filed (a strong signal)
- Medical bills for care you didn't receive
- An IRS notice about income from an employer you never worked for
Response
Go to IdentityTheft.gov first. It generates your recovery plan and the FTC Identity Theft Report, which unlocks legal rights (Chapter 28).
Then: freeze credit, contact affected creditors, file a police report, dispute fraudulent items with the bureaus, and keep meticulous records of every call.
For tax identity theft: IRS Form 14039, and get an Identity Protection PIN at irs.gov — a six-digit number required to file your return, which blocks fraudulent filings. Anyone can request one now, not just victims. It's a good idea.
Privacy
You will not achieve perfect privacy and it isn't the goal. The goal is reducing exposure to the level where you're not the easiest target and your data isn't casually available.
What your phone knows
Location history, app usage, contacts, photos with embedded location data, search history, purchases, and — through advertising identifiers — a remarkably detailed behavioral profile shared across apps.
Practical steps (30 minutes):
iPhone: - Settings → Privacy & Security → Tracking → turn off "Allow Apps to Request to Track" - Settings → Privacy & Security → Location Services → review every app; set most to "While Using" or "Never" - Location Services → System Services → Significant Locations — look at this. It's a detailed log of everywhere you've been. Clear it and turn it off if you like. - Settings → Privacy & Security → Analytics & Improvements → turn off sharing - Turn on Advanced Data Protection for end-to-end encrypted iCloud
Android: - Settings → Privacy → Ads → delete advertising ID - Settings → Location → App permissions → review each - myactivity.google.com — review and delete Web & App Activity, Location History, YouTube History. Set auto-delete to 3 months. - Settings → Google → Ads → opt out of personalization
Both: review app permissions periodically. Ask why a flashlight app needs your contacts.
Social media
Do the audit annually.
- Review privacy settings on every platform. They change, and changes frequently default to more public.
- Review who can see past posts. Facebook lets you limit all past posts at once.
- Turn off location tagging.
- Review tagged photos.
- Remove old apps with account access. Every platform has a "connected apps" page and everyone's is full of things they used once in 2019.
- Turn off facial recognition where offered.
- Consider what's public: birthdate, hometown, employer, family relationships, travel plans. Each is a data point for social engineering.
A useful test: look at your profile in a private browser window while logged out. That's what a stranger, an employer, or a scammer sees.
Data brokers
Companies that compile and sell profiles: your address history, phone numbers, relatives, income estimate, property records, and more. Sites like Spokeo, Whitepages, BeenVerified, and dozens more.
You can opt out, and it works, though it's tedious and they re-add you over time.
- Manual: each broker has an opt-out process. Search "[broker] opt out." Budget several hours for the major ones.
- Paid services (DeleteMe, Incogni, Optery) do it continuously for $100–180/year. For most people this is a reasonable purchase, especially for anyone with safety concerns.
- State privacy laws — California, Colorado, Virginia, Connecticut, Utah, Texas, and a growing list give residents the right to request deletion. California's DELETE Act is creating a centralized deletion mechanism. Use your state's rights if you have them.
- If you have a safety concern (stalking, domestic violence), many states have address confidentiality programs that provide a substitute address for public records. Search "[your state] address confidentiality program."
Browsing
- A browser that blocks trackers — Firefox with strict protection, Brave, or Safari.
- uBlock Origin — free, and it blocks ads and trackers, which also blocks a major malware delivery route.
- A privacy-respecting search engine — DuckDuckGo, Startpage — if you want less profiling.
- VPNs are more limited than the marketing suggests. A VPN hides your traffic from your ISP and from the local network, which is useful on public Wi-Fi and for bypassing geographic restrictions. It does not make you anonymous, and you're shifting trust from your ISP to the VPN provider. Avoid free VPNs entirely — if you're not paying, your traffic is likely the product.
- HTTPS is now near-universal. Public Wi-Fi is far less dangerous than it was a decade ago, though a VPN is still reasonable on untrusted networks.
Encrypted messaging
Signal is the standard recommendation — end-to-end encrypted, minimal metadata retention, free, open source. WhatsApp is end-to-end encrypted for message content but retains substantial metadata. iMessage is encrypted between Apple devices (green bubbles to Android are not, though RCS encryption has been improving). SMS is not encrypted at all.
For anything sensitive — medical, legal, financial, or personal — use Signal.
Subscriptions
The average household leaks hundreds of dollars a year to subscriptions nobody uses. It's the easiest money in this book to recover.
Why it happens
Free trials that auto-convert. You intended to cancel. You forgot. That's the business model, not an accident.
Small amounts below the noticing threshold. $4.99 doesn't register on a statement.
Annual renewals that hit once a year when you're not paying attention.
Deliberately difficult cancellation — phone-only, retention scripts, hidden links. The FTC has pursued "negative option" and "click to cancel" rulemaking specifically because of this; the status of those rules has been litigated repeatedly, so the friction may or may not have improved by the time you read this. Verify the current rule at ftc.gov before assuming a right you may not have.
⚠️ THE TRAP: the cancellation maze
These are designed patterns with names, built by teams who measure how many people give up at each step:
- Cancel by phone only, during business hours, with a hold queue.
- The retention gauntlet — four "are you sure" screens, a discount offer, a pause offer, a survey, then a final confirm that's a grey link while "Keep my plan" is a big bright button.
- Confirmshaming — "No thanks, I don't want to save money."
- The buried link, three menus deep under Manage → Plan details → More options.
- "Your cancellation is scheduled" with no confirmation email, so you have no proof.
- Annual plans that renew silently at a higher rate than you first paid.
Who profits: every month of friction is a month of revenue from someone who meant to leave. These flows are A/B tested to maximize exactly that.
How to beat it: decide before you open the flow that you are cancelling, and treat every offer as noise. Say "cancel," then "representative," to the phone menu. Then: "I'm not looking for a different plan. Please cancel the account and send me written confirmation." Repeat that sentence verbatim as many times as needed — you don't have to answer their questions. Screenshot every screen. If they won't send confirmation, get the agent's name and a cancellation reference number.
The option that actually works: a virtual card number you can delete. If the card doesn't exist, the charge doesn't land.
The audit
1. Go through twelve months of every statement. All cards, all bank accounts. Twelve months, because annual charges hide.
2. List every recurring charge. Name, amount, frequency, annual cost.
3. Check the places subscriptions hide: - Apple: Settings → your name → Subscriptions - Google Play: Play Store → Payments & subscriptions - Amazon: Your Account → Memberships & Subscriptions (and check Subscribe & Save) - PayPal: Settings → Payments → Automatic payments - Directly on each service's site
4. For each: keep or cancel. Ask "have I used this in the last 60 days?"
5. Cancel today. Not later. The intention decays and that's what they're counting on.
6. Confirm cancellation — screenshot the confirmation, save the email. Charges continuing after cancellation is common enough that documentation matters.
Preventing recurrence
- A dedicated card for subscriptions, so they're all in one place.
- Virtual card numbers — Privacy.com, or your bank's virtual card feature. Set spending limits or one-time numbers for free trials. This is the best defense: the trial simply cannot charge you.
- A calendar reminder two days before every free trial ends. Set it the moment you sign up.
- Annual plans only for things you're certain about.
- A yearly audit, calendared.
If a charge won't stop
- Cancel through the service, keep proof.
- If it charges again, dispute with your card issuer (Chapter 28), in writing through the secure message center so there's a record, with your cancellation screenshot attached: "I cancelled this subscription on [date] and the merchant continued to bill me. I am disputing this charge and revoking authorization for any future charges from this merchant."
- Ask the issuer to block future charges from that merchant. It's a separate action from the dispute, and they usually won't offer it.
- If it's a bank debit rather than a card, you have a different tool: under the electronic transfer rules you can stop a preauthorized recurring debit by telling your bank at least three business days before the scheduled date (Chapter 3). In writing.
- Complain at reportfraud.ftc.gov and to your state AG — complaint volume is genuinely how these companies end up in consent decrees.
- Do not just cancel the card if you have other things on it. And know that a new card number doesn't reliably stop recurring charges — the networks update stored numbers for merchants automatically. Revoking authorization is what stops it.
Your digital footprint
Employers search for you. So do landlords, dates, and occasionally opposing counsel.
Audit it
Search your name in a private window. Variations, with your city, with your employer. Check images. Check pages two and three.
Set a Google Alert for your name.
Clean it up
- Delete or lock down old accounts. Old blogs, forums, dead social media. justdelete.me catalogs how to delete accounts on hundreds of services.
- Ask for removal where you can. Some sites will comply.
- Google's removal tools can remove certain personal information (phone numbers, addresses, ID numbers, explicit imagery) from search results. This is a real and under-used option — search "Google results about you."
- Push it down by creating positive results: a LinkedIn profile, a personal site, professional profiles.
- Non-consensual intimate images: StopNCII.org (adults) and takeitdown.ncmec.org (minors) create hashes that platforms use to block distribution. Most states now criminalize this, and federal law has expanded here.
Build it
LinkedIn is the profile most likely to appear first for a professional. Make it good (Chapter 19).
A personal site — even a single page — gives you a result you control.
Be deliberate about what you post. Assume permanence, assume screenshots, assume it will be read by the person you'd least want reading it. That's not paranoia; it's just what the medium is.
AI safety
New and worth a section.
What not to put into a chatbot
Assume anything you type may be stored, reviewed by humans for quality, or used for training unless you have specific assurances otherwise. Terms vary by product and by tier.
Don't paste: - Your Social Security number, account numbers, or passwords - Other people's personal information without their consent - Confidential work material, unless your employer has an approved tool — this is now a common way people get fired - Medical information you'd want to stay private - Anything covered by a professional confidentiality obligation
Check the settings. Most major AI products let you turn off training on your conversations and delete history.
AI-generated scams
- Voice cloning from a few seconds of audio — hence the family safe word.
- Deepfake video, including live video calls, which has been used in large corporate fraud.
- Convincing phishing — the bad-grammar tell is largely gone.
- Fake profiles and fake reviews at scale.
- AI-generated news and images, especially around elections and disasters.
Defenses: verify through a second channel, use the safe word, be skeptical of urgency, and reverse image search anything suspicious.
Verification habits
- Consider the source. Does this outlet exist? Is this account new?
- Reverse image search.
- Check whether other outlets report it.
- Be most skeptical of things that confirm what you already believe — that's the vector that works best on everyone, including you.
🎓 GOING DEEPER: Device hygiene
- Update everything. OS, apps, browser. Most successful attacks exploit known vulnerabilities that were patched months earlier. Turn on automatic updates.
- Encrypt your devices. On by default on modern phones. On computers: FileVault (Mac), BitLocker (Windows Pro) or Device Encryption.
- Screen lock with a strong PIN or biometrics. Six digits or more, not four, and not your birthday.
- Back up. The 3-2-1 rule: three copies, two different media, one off-site. Cloud backup plus an external drive. Test that you can actually restore.
- Ransomware defense is backups. Nothing else works as well.
- Public charging ports: "juice jacking" risk is largely theoretical but a $10 data-blocker or your own wall adapter eliminates it.
- Wipe devices before disposal. Factory reset, and sign out of accounts first — a phone still signed into your Apple or Google account is not usable by the next owner and is still linked to you.
- Router: change the default admin password, update firmware, use WPA3 or WPA2, and turn off WPS. Your router is the most-neglected device in your house.
- Home cameras and smart devices: change default passwords, enable 2FA, and think about what a compromise would expose.
🎓 GOING DEEPER: Helping someone else without taking over
At some point you become the family's tech person. How you handle it determines whether they call you when something goes wrong — and whether they call you before they send the money.
The thing that ruins it: taking over. If you set everything up on their behalf with passwords they don't know, you've made them dependent, embarrassed, and less likely to tell you when they've clicked something. A person who feels stupid hides the problem. That's how a $200 mistake becomes a $20,000 one.
What works better:
- Ask permission before changing anything, and let them do the clicking. Slower, and it's the only version that lasts.
- Explain the why once, in one sentence: "so one stolen password doesn't unlock everything."
- Never say "how did you not know that." Nobody taught any of us this.
- Give them the one rule, not the twelve. For most people the whole curriculum is: hang up and call back on a number you looked up yourself, and never pay anyone in gift cards.
- Make yourself the emergency line. "If anything ever feels urgent about money, call me first, and I will never be annoyed. Not once, not at 3 a.m."
For aging parents specifically: set the family safe word, add a carrier port-out lock, freeze their credit, and ask their bank about adding a trusted contact to the account — which lets the bank call you if they see something alarming, without giving you any control of the money. Under-used and free. Watch for the early signs: new secretiveness about money, a sudden online "friend," unexplained gift card purchases.
For kids: parental controls are a floor, not a plan. What actually protects a kid is believing they can tell you. Say it out loud before anything happens: "If someone online ever gets a picture of you or threatens you, you can tell me, you will not be in trouble, and we will fix it." Sextortion works on children specifically because they're certain they'll be blamed. Remove that in advance and you've done more than any filter can.
And accept the limit. You cannot make another adult secure. You can make the safe path easier than the unsafe one and be the person they call. That's the job.
🌍 OUTSIDE THE US
GDPR (EU/UK) gives residents genuinely strong rights: access your data, correct it, delete it, port it, and object to processing. Companies must respond within a month. These rights are powerful and dramatically under-used — you can email any company holding your data and require them to delete it.
Similar laws: Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, India's DPDP Act, and a growing number of US state laws.
How to actually use it — one email, sent to the company's privacy or data protection address:
"Under Article 17 of the GDPR I am requesting erasure of all personal data you hold relating to me, and under Article 15 a copy of the data you hold. My account email is [address]. Please confirm within one month."
Where to report fraud, by country:
- UK — Action Fraud (actionfraud.police.uk); Police Scotland 101 in Scotland. Forward scam emails to report@phishing.gov.uk, texts to 7726. UK banks operate under authorised push payment (APP) fraud reimbursement rules that give scam victims materially better recovery odds than US victims have — ask for reimbursement explicitly, and escalate free to the Financial Ombudsman Service if refused. Instead of a credit freeze, use a CIFAS Protective Registration.
- Canada — the Canadian Anti-Fraud Centre (antifraudcentre.ca); fraud alerts with Equifax Canada and TransUnion Canada; privacy complaints to the Office of the Privacy Commissioner.
- Australia and New Zealand — Scamwatch (scamwatch.gov.au) and the National Anti-Scam Centre, ReportCyber, CERT NZ, and Netsafe. IDCARE (idcare.org) is a free identity-recovery service covering both countries. Credit bans through Equifax, Experian, and illion.
- India — the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the cyber-fraud helpline 1930. Reporting within the first hours materially improves the odds of freezing the receiving account.
- EU — your national data protection authority for privacy, your national police cybercrime unit for fraud.
Several countries now require confirmation-of-payee name checks before a transfer completes, which kills a whole category of fraud. Find out what your country gives you before assuming you have nothing.
VPN legality varies; a few countries restrict, license, or ban them. Encrypted messaging is also restricted in some jurisdictions — check local law before assuming Signal is uncontroversial where you live.
Common mistakes
- Reusing passwords.
- No password manager.
- Answering security questions truthfully.
- Leaving a dead email address as the recovery address for live accounts.
- Sending someone a code that was texted to you.
- No 2FA on email.
- Using SMS 2FA for financial accounts without a carrier port-out lock.
- Not saving 2FA backup codes.
- Clicking links in unexpected messages.
- Calling back a number the caller gave you.
- Giving remote computer access to someone who called you.
- Not freezing credit.
- No family safe word.
- Never auditing subscriptions.
- Signing up for free trials without a calendar reminder or virtual card.
- Never searching your own name.
- Pasting confidential work material into a chatbot.
- Not updating devices.
- No backups.
- Paying a "recovery service" after being scammed.
Key numbers
| Number | What it is |
|---|---|
| 1 | Passwords you should have to remember |
| 4–5 words | A good master passphrase |
| 3-2-1 | Backup rule: 3 copies, 2 media, 1 off-site |
| 12 months | Statements to review in a subscription audit |
| 6+ digits | Minimum phone PIN |
| $0 | Cost of a credit freeze, Bitwarden, and an IRS IP PIN |
| reportfraud.ftc.gov / ic3.gov | Where to report fraud |
| haveibeenpwned.com | Check whether your credentials are breached |
| 7726 | Forward scam texts here (spells SPAM) |
| 1-800-843-5678 | NCMEC (minors, image removal) |
| 1-877-908-3360 | AARP Fraud Watch helpline — free, any age |
| 988 | Crisis line, if any of this has you in crisis |
Chapter recap
- Password reuse is the biggest security risk most people have. A password manager fixes it in an afternoon.
- Turn on 2FA everywhere, save the backup codes, and add a carrier port-out lock.
- Lie on security questions. They aren't secrets; they're public records.
- Audit the recovery path — the old email, the old phone number, the forwarding rules. That's the door attackers actually use.
- If a scam happens, move in the first hour and skip the shame. Speed is the whole game.
- Never click a link in an unexpected message. Go to the site directly or call the number on your card.
- Hang up and call back on a number you looked up. That defeats most phone scams.
- Set a family safe word. Voice cloning is real and cheap.
- If someone you've never met in person mentions an investment, it's a scam.
- Freeze your credit — and your children's. Free.
- Audit twelve months of statements for subscriptions and cancel today, not later.
- Search your own name in a private window. That's what everyone else sees.
- Don't paste confidential work material into a chatbot.
Exercises
Do this right now (30 minutes)
32.1 — Check haveibeenpwned.com. Every email address you've ever used, including the dead ones. Deliverable: a written list of which addresses are breached and, for each, whether that password is still in use anywhere. That second column is your actual to-do list.
32.2 — Install a password manager. Bitwarden is free and sufficient. Create a generated five- or six-word master passphrase, write it down once, and put it somewhere safe. Save the recovery code with it. Install the browser extension and the phone app in the same sitting — a manager you can't autofill from is one you'll abandon in three weeks.
32.3 — Change your email password to a unique generated one, and turn on 2FA on your email. If you do only one thing from this chapter, this is it.
32.4 — Call your phone carrier and add a port-out PIN / number lock. Ask for it by name. Ten minutes, and it's the SIM-swap defense. Deliverable: the date you did it, in your Operating System.
32.5 — Turn on automatic updates on your phone, your computer, and your browser. Then restart, because the pending update doesn't count until you do. Highest-value five minutes in the chapter.
32.6 — Set the family safe word. One group text or one call. Tell parents, grandparents, siblings, children. Say why: "If anyone ever calls sounding like me and asking for money, ask for the word. Voices can be faked now." Free, and it beats a technology you can't otherwise defend against.
This week (3 hours)
32.7 — Freeze your credit at all three bureaus, and your children's if you have children. Free (Chapter 4). Store the PINs in your password manager.
32.8 — Change your top 10 passwords. Email, banking, phone carrier, anything with a stored payment method. Unique, generated, in the manager. Everything else can wait and be done as you log in over the coming months.
32.9 — Turn on 2FA everywhere it's offered, using an authenticator app where you can. Save every backup code into the password manager as you go — that's the step people skip and regret.
32.10 — Audit the recovery path on your email and your top five accounts: recovery email, recovery phone, active sessions, forwarding rules and filters, connected apps. Deliverable: one line per account saying what you found and what you changed. Look hardest at the forwarding rules.
32.11 — Do the subscription audit. Twelve months of every statement, plus the four hiding places (Apple, Google Play, Amazon, PayPal). List each: name, amount, frequency, annual cost. Cancel everything you haven't used in 60 days — today, and screenshot each confirmation. Deliverable: the annual total you just recovered. Write that number down; it's usually larger than people expect.
32.12 — Write your rules card. One note on your phone, in your own words, with the three things you will do under pressure: hang up and call back on a number I look up myself; never pay in gift cards, wire, or crypto; never click a link in a message I didn't expect. Deciding in advance is what makes you resistant in the moment, because in the moment you will be rushed on purpose.
32.13 — Go find a real phishing email in your spam folder. Don't click anything. Expand the sender address, hover the link without clicking, and write down which of the twelve tells from this chapter it uses. Do this once and you will recognize the pattern for the rest of your life.
This month (4 hours)
32.14 — Search your own name. Private window, several variations, with your city and employer, images too, pages one through three. Deliverable: a list of what you want removed and what you want to outrank.
32.15 — Do the privacy settings pass. Phone location and tracking settings, ad identifier, every social platform's privacy settings, connected apps, past post visibility. Then look at your own profile logged out — that's what a stranger sees.
32.16 — Start data broker opt-outs. The ten largest manually, or pay a removal service. Calendar it as an annual repeat, because they re-add you.
32.17 — Set up backups. Cloud plus an external drive. Then restore one file — an untested backup is not a backup.
32.18 — Get an IRS Identity Protection PIN at irs.gov. Free, and it blocks fraudulent tax filings in your name.
32.19 — Set up digital legacy (Chapter 30): password manager emergency access, and legacy contacts on Apple, Google, and Facebook.
32.20 — Close or secure your dead accounts. Old email addresses, old forums, services you used once. justdelete.me tells you how. Before closing an old email, remove it as the recovery address everywhere it's listed.
32.21 — Help one person. A parent, a grandparent, a younger sibling, a friend who finds this exhausting. Sit next to them, let them do the clicking, and do just three things: password manager on email, 2FA on email, safe word. Then tell them to call you first about anything urgent involving money, and mean it.
Reflection
32.22 — How many places is your reused password? Walk the chain: if someone had it, what would they reach first, and what would that unlock next?
32.23 — Have you or someone you know been scammed? What happened? At which specific moment could it have been interrupted, and what would have interrupted it?
32.24 — What's in your search results that you'd rather wasn't? What would it actually take to change that — removal, or burying it?
32.25 — Which of these did you already know you should do, and haven't? What's the real reason — time, or the feeling that it's already too late to start? It isn't.
32.26 — Who in your life would a scammer target first, and what would they lose? What's the one conversation you could have with them this month?
📋 ADD TO YOUR OPERATING SYSTEM
Create Section 32: Digital Life — and note that this section is sensitive. Keep it in your password manager's secure notes, not an open document.
- Password manager: which one, where the master password backup is stored (a location, not the password)
- Emergency access contact configured
- Accounts with 2FA enabled, and where backup codes are stored
- Recovery email and recovery phone on file for your email and top accounts, plus the date you last audited them
- Your rules card — the three things you do under pressure
- Carrier port-out lock: confirmed, and the date
- Credit freeze status at all three bureaus and where the PINs are
- IRS Identity Protection PIN
- Family safe word (agreed, not written where a stranger finds it)
- Subscription inventory: service, cost, renewal date, keep/cancel
- Annual subscription audit date
- Data broker opt-outs completed and the annual repeat date
- Backup setup: what, where, last tested
- Devices: what you own, encryption status, what's on them
- Fraud reporting: reportfraud.ftc.gov, ic3.gov, your bank's fraud line
- Router admin credentials location and last firmware update
Next: Chapter 33 closes Part VII with something completely different — the commitment nobody warns you about, and the joy nobody can quite explain.