Join Early Retirement Today
Reply
 
Thread Tools Display Modes
Old 04-02-2023, 07:25 AM   #21
Give me a museum and I'll fill it. (Picasso)
Give me a forum ...
 
Join Date: Jun 2016
Location: Colorado
Posts: 8,971
Change your passwords and make them unique to each site. I also use a “burner” account for all the non important stuff and then another account for things I want to keep safe. The safe account has stayed pure for years.
COcheesehead is offline   Reply With Quote
Join the #1 Early Retirement and Financial Independence Forum Today - It's Totally Free!

Are you planning to be financially independent as early as possible so you can live life on your own terms? Discuss successful investing strategies, asset allocation models, tax strategies and other related topics in our online forum community. Our members range from young folks just starting their journey to financial independence, military retirees and even multimillionaires. No matter where you fit in you'll find that Early-Retirement.org is a great community to join. Best of all it's totally FREE!

You are currently viewing our boards as a guest so you have limited access to our community. Please take the time to register and you will gain a lot of great new features including; the ability to participate in discussions, network with our members, see fewer ads, upload photographs, create a retirement blog, send private messages and so much, much more!

Old 04-02-2023, 08:23 AM   #22
Give me a museum and I'll fill it. (Picasso)
Give me a forum ...
donheff's Avatar
 
Join Date: Feb 2006
Location: Washington, DC
Posts: 11,327
Quote:
Originally Posted by mpeirce View Post
If you’ve been using Yahoo for a long time, you’ve been “hacked"
.[/INDENT]
Fair enough. We are using the term “you have been hacked” differently. I interpret that to mean someone has gained control of my account and can use it for nefarious purposes. A data breach means the provider has been compromised in some manner and some of my data may have been compromised. That has become so ubiquitous that we should all assume that our social security numbers and identifying information are public properties. I have long kept my credit frozen for that reason. To my knowledge, no one has gained control of any of my accounts although I recognize that a competent hacker who made me a target could undoubtedly do so. If that happens I hope I can catch it in time to limit the damage.
__________________
Idleness is fatal only to the mediocre -- Albert Camus
donheff is offline   Reply With Quote
Old 04-02-2023, 08:31 AM   #23
Thinks s/he gets paid by the post
 
Join Date: May 2019
Posts: 2,809
Unique passwords has always been the case for me, and now use 2FA via phone including a few authenticator apps. Don't trust any links you get in an email that may redirect you to a fraudulent site to phish info from you. I use a desktop computer and Firefox for financial sites. Credit is frozen.
GenXguy is offline   Reply With Quote
Old 04-02-2023, 09:52 AM   #24
Give me a museum and I'll fill it. (Picasso)
Give me a forum ...
Sunset's Avatar
 
Join Date: Jul 2014
Location: Spending the Kids Inheritance and living in Chicago
Posts: 17,078
I use a unique email (and username and password) for my important financial accounts.

A big advantage is, when I get a bank/brokerage email to my other email accounts, I know it's fake/scam or at least not concerning my actual account as that is not the email I gave them.

It's a side benefit of using unique emails for banking.
__________________
Fortune favors the prepared mind. ... Louis Pasteur
Sunset is offline   Reply With Quote
Old 04-02-2023, 11:10 AM   #25
Thinks s/he gets paid by the post
 
Join Date: Jan 2019
Location: Sunny California
Posts: 2,612
Thanks for all your great advice. I agree "hacked" was the wrong word, I should have used compromised. I tried to edit the title but it won't let me so if a moderator can fix it, please do.
I'll create a new gmail address, it's about time I had a more mature one anyway.
RetiredAndLovingIt is offline   Reply With Quote
Old 04-02-2023, 12:01 PM   #26
Administrator
MichaelB's Avatar
 
Join Date: Jan 2008
Location: Chicagoland
Posts: 40,696
Title updated
MichaelB is online now   Reply With Quote
Old 04-02-2023, 02:25 PM   #27
Thinks s/he gets paid by the post
 
Join Date: Jan 2019
Location: Sunny California
Posts: 2,612
Thanks
RetiredAndLovingIt is offline   Reply With Quote
Old 04-02-2023, 05:26 PM   #28
Recycles dryer sheets
 
Join Date: Jan 2020
Posts: 247
Google has been telling me (for years) that my email accounts are compromised. I just ignore. YMMV.

Its always a safe assumption that your emails can be accessed by others (Government, Police, Criminals and so on), so don't use it for anything that may cause trouble later on.

Most security tokens/code sent to email/phone expire in 30-60 minutes. If you want to be extra cautious, use phone for one time tokens, instead of email.
yhoomajor is offline   Reply With Quote
Complete Compromise
Old 04-11-2023, 04:03 PM   #29
gone traveling
 
Join Date: Sep 2018
Location: Vass
Posts: 20
Complete Compromise

This is my story of financial/email/cellphone compromise and what triggered it. Please don’t forget that your email(s) and accounts and passwords associated with them can be hacked at any time. To find out if yours have you can check at haveibeenpawned.com. I found that several online companies I used emails for were hacked and all information including accounts and emails were sold on the dark web at least by 2 separate sites.

Right after the New Year this series of events occurred:

1. My cellphone was hacked. I have Consumer Cellular. The hacker bought a Sim card at a Target retail store and using my phone number, stated he lost “my phone”, had purchased another and needed a CC Sim card to activate it. It was easy for him to do this with virtually no security checks carried out.

2. The consequence of him using a new Sim card for my cellphone effectively “bricked” my phone and rendered it useless for outgoing calls, texts and messages.

3. Somehow, this person even had my bank account information. Specifically, my checking account number which is easily found on your check and on information stored on websites that you’ve purchased from.

4. He also had my primary email account hacked and due to my inability to receive text s, kept changing my password immediately after I logged in on my PC to reset it. He had control.

5. He hijacked my CitiBank credit account and shut my card down while attempting to have a new one issued to him in a different state using my name (probably to be sent to a scam house or P.o. box).

6. He got into my Paypal account and tried to use Xoom, a money transfer system within Paypal to send over $2500 from my checking account to his. Flagged by Paypal fortunately.

7. He attempted to wire transfer funds using my Wells Fargo account to himself.

8. He tried to charge an $800 Apple watch through Best Buy.

9. He tried to purchase over $900 worth of items via Walmart online.

How much money did I lose? $0.0.

Fortunately I had alerts turned on in Wells Fargo and all of the online attempts to cheat me failed.

It took 2 long weeks to get it all straightened out with new credit cards, bank cards and checking account. Since pretty much all of my payments are deducted from a bank account I had to change every payment being sent.

I was lucky. It started out with the cellphone so be aware!
Elliotgb183 is offline   Reply With Quote
Old 04-11-2023, 04:21 PM   #30
Recycles dryer sheets
 
Join Date: Mar 2022
Location: Scottsdale
Posts: 81
Here's a trick so that you don't need a password manager. I use part of the website address plus a PIN and special character so that each website has it's own unique password and I don't have to try and remember anything.
orbops is offline   Reply With Quote
Old 04-11-2023, 04:23 PM   #31
Thinks s/he gets paid by the post
 
Join Date: Dec 2017
Posts: 1,616
Quote:
Originally Posted by Elliotgb183 View Post
This is my story of financial/email/cellphone compromise and what triggered it. Please don’t forget that your email(s) and accounts and passwords associated with them can be hacked at any time. To find out if yours have you can check at haveibeenpawned.com. I found that several online companies I used emails for were hacked and all information including accounts and emails were sold on the dark web at least by 2 separate sites
Glad you got it fixed fairly quickly. I wonder if he got your email first.

My main email address has been on that list for years and periodically I get notified by one of the monitoring companies that my information is on the dark web. I see attempts to log in from around the world but with a strong password and app based 2 factor I think I'm reasonably safe. Companies are too accommodating about sending password resets to an email so I have my important financial accounts set to an email I use just for them. I'm not a big fan of text based 2 factor.
RetMD21 is offline   Reply With Quote
Old 04-11-2023, 04:26 PM   #32
Give me a museum and I'll fill it. (Picasso)
Give me a forum ...
 
Join Date: Jun 2016
Location: Colorado
Posts: 8,971
Aren’t you giving away your email by using the haveibeenpawned site?
COcheesehead is offline   Reply With Quote
Old 04-11-2023, 05:07 PM   #33
Thinks s/he gets paid by the post
 
Join Date: Jan 2019
Location: Sunny California
Posts: 2,612
Quote:
Originally Posted by Elliotgb183 View Post
This is my story of financial/email/cellphone compromise and what triggered it. Please don’t forget that your email(s) and accounts and passwords associated with them can be hacked at any time. To find out if yours have you can check at haveibeenpawned.com. I found that several online companies I used emails for were hacked and all information including accounts and emails were sold on the dark web at least by 2 separate sites.

Right after the New Year this series of events occurred:

1. My cellphone was hacked. I have Consumer Cellular. The hacker bought a Sim card at a Target retail store and using my phone number, stated he lost “my phone”, had purchased another and needed a CC Sim card to activate it. It was easy for him to do this with virtually no security checks carried out.

2. The consequence of him using a new Sim card for my cellphone effectively “bricked” my phone and rendered it useless for outgoing calls, texts and messages.

3. Somehow, this person even had my bank account information. Specifically, my checking account number which is easily found on your check and on information stored on websites that you’ve purchased from.

4. He also had my primary email account hacked and due to my inability to receive text s, kept changing my password immediately after I logged in on my PC to reset it. He had control.

5. He hijacked my CitiBank credit account and shut my card down while attempting to have a new one issued to him in a different state using my name (probably to be sent to a scam house or P.o. box).

6. He got into my Paypal account and tried to use Xoom, a money transfer system within Paypal to send over $2500 from my checking account to his. Flagged by Paypal fortunately.

7. He attempted to wire transfer funds using my Wells Fargo account to himself.

8. He tried to charge an $800 Apple watch through Best Buy.

9. He tried to purchase over $900 worth of items via Walmart online.

How much money did I lose? $0.0.

Fortunately I had alerts turned on in Wells Fargo and all of the online attempts to cheat me failed.

It took 2 long weeks to get it all straightened out with new credit cards, bank cards and checking account. Since pretty much all of my payments are deducted from a bank account I had to change every payment being sent.

I was lucky. It started out with the cellphone so be aware!
Good story and glad they didn't get you but scary nonetheless. I've heard of that website and never used it but after doing a little checking it seems to be well regarded.

The correct website address is one letter off (no a)

https://haveibeenpwned.com/
RetiredAndLovingIt is offline   Reply With Quote
Old 04-11-2023, 05:10 PM   #34
Recycles dryer sheets
 
Join Date: May 2019
Location: Living room couch
Posts: 153
Quote:
Originally Posted by COcheesehead
Aren’t you giving away your email by using the haveibeenpawned site?
Email addresses have NEVER been considered confidential so there is really no such thing as having a hacked email address. I worked in operational cybersecurity, not audit and compliance, for the last 20 years of my career.

haveibeenpwned.com is run by a very reputable person who has been vetted by pretty much everyone.
NXR7 is offline   Reply With Quote
Old 04-11-2023, 05:13 PM   #35
Recycles dryer sheets
 
Join Date: Dec 2018
Posts: 176
My email address is all over the “dark web” but I use a password vault (Bitwarden) for a unique (usually 20 character) password for all accounts.

Wherever practical I also use 2 factor authentication. Text messages are defeated if your cell number is hacked. Be sure that your cell number cannot be ported without you receiving a call!

I use Google Authenticator for the most sensitive accounts, including the password vault.

So far I’ve been lucky, even after some low-life collected unemployment using my name and social security number with a bogus street address. I checked all 3 credit reports, and froze my credit reports (it only freezes for one year).
a60dan is offline   Reply With Quote
Old 04-11-2023, 05:19 PM   #36
Recycles dryer sheets
waynezo's Avatar
 
Join Date: Nov 2016
Location: Margate
Posts: 60
I use 2FA for email and financial accounts. I have all 4 credit bureaus frozen and lifetime fraud alert. I use credit karma and experian to monitor my credit even though it is frozen. All banks and credit cards are set to alert for suspicious activity.
__________________
Retired May 2010 @ 49
"Tomorrow is Promised To No One"
waynezo is offline   Reply With Quote
Old 04-11-2023, 05:52 PM   #37
Give me a museum and I'll fill it. (Picasso)
Give me a forum ...
 
Join Date: Jun 2016
Location: Colorado
Posts: 8,971
Quote:
Originally Posted by NXR7 View Post
Email addresses have NEVER been considered confidential so there is really no such thing as having a hacked email address. I worked in operational cybersecurity, not audit and compliance, for the last 20 years of my career.

haveibeenpwned.com is run by a very reputable person who has been vetted by pretty much everyone.
Ok upon your endorsement I tried it. My burner email was compromised five times, all of them over three years ago which seems about right based on the spam I get. My financial email shows zero issues. So thank you.
COcheesehead is offline   Reply With Quote
Old 04-12-2023, 06:14 AM   #38
Give me a museum and I'll fill it. (Picasso)
Give me a forum ...
target2019's Avatar
 
Join Date: Dec 2008
Location: On a hill in the Pine Barrens
Posts: 9,713
Please lock your SIM to your phone.
target2019 is offline   Reply With Quote
Old 04-12-2023, 07:53 AM   #39
Full time employment: Posting here.
 
Join Date: Jun 2017
Location: Punta del Este
Posts: 642
Quote:
Originally Posted by RetiredAndLovingIt View Post
I'm really concerned about identity theft since it looks like my main e-mail address has been hacked and this is the second time now. I have a bunch of CD's maturing this year and the thought of moving funds around right is scaring me a lot. I'm looking for any suggestions to keep me safe when online so tis does not happen again.

Here's what I have so far



I'm going to create a new separate e-mail address for online banking only and use a new dedicated phone number only for 2FA.

Changing passwords and using a new e-mail address for all my accounts. I'll keep the old one for the junk and subscription e-mails that I get.

I'm going to powerwash one of my Chromebooks and only use it for online banking. I remember reading somewhere I should use it in guest mode as well to stay anonymous. I always use bank websites but then I started to think that their apps might be more secure. I assume the apps might run faster but are they safe? Which method do you use?

I have not ran my credit report in a couple of years either so I need to do that. I will also be freezing my credit.

Is it safe to save my passwords in Google or Microsoft or should I just write them all down moving forward?
I currently have gmail and yahoo addresses, which do you consider safe and use?
Anything else I should do? Basically I would love to completely remove my name and address from the internet and become completely anonymous online if that's possible.
Where ever possible use 2 step verification! Get a VPN!
Retired Expat is offline   Reply With Quote
Old 04-12-2023, 08:07 AM   #40
Full time employment: Posting here.
 
Join Date: Nov 2019
Location: Jersey City
Posts: 522
First, I hope you’re using password manager to protect yourself from that angle. Bitwarden is the one I would recommend. Secondly: SimpleLogin is a great way to create custom emails on the fly - every time you register somewhere. That way you know who sells your data and you can instantly delete/change that one email whenever you want without affecting any others. If you combine that with registering your own domain at a site like namecheap, you can have highly customizable set of emails.

Mine look more or less like that: newblog@firstname.lastname.com .Or chase@firstnamelastname.xyz. I registered my name as domains but you could choose something else to further distance yourself from your online data. If any emails get compromised I just delete them. Similarly to passwords.
tenant13 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What Does It Mean When Sender E-mail Address Not Shown kaneohe Other topics 5 09-05-2017 04:53 AM
Mail Forwarding Service as Resident Address for Tax Purposes FIGuy Other topics 2 05-05-2014 05:47 PM
E-mail not returned yet: still valid address? kaneohe Other topics 6 08-01-2009 08:27 AM

» Quick Links

 
All times are GMT -6. The time now is 07:10 AM.
 
Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2024, vBulletin Solutions, Inc.