My Mom just had her phone number and email account stolen

Which reminds me... don't tell the world you are traveling! (Not attacking you, tenant13, I speak in general.)

Don't mention it here. Don't mention it on Instagram, Facebook, X, Reddit, Bumble, Grinder, whatever. Even if you have an "anonymous" name.

But for goodness sake, don't mention it on Facebook where you likely have your real name. I'd even recommend you get off Facebook or really reduce your use of it.

Save the picture postings for later when you come back.

Paranoid? No. With the new A.I. tools, we all have profiles out there on the dark web. A scamster can set up a trigger to attack you when they notice you are traveling. This is a perfect time for them to attack. Going further, it is a good time to rob your house too, but that's too much work compared to letting an A.I. agent go off and do its thing.
Yep, we no longer post when gone. I’ll do a recap when we are back home.
 
I don't post anything on any social media sites. The only social media site where I have an account is on FB, but only keep it so that my friends can PM me and I can see what is going on in their lives. I have several friends who asked me to post something occasionally so that they know that I am alive. I told them to just PM me with that question instead. :)

Within the community where we live in, alot of folks have 2nd and 3rd homes and we know roughly when someone is away or not, snowbirds and sunbirds, or just plain extended travel. No one seems to be worried about break-ins. We also live in a 24x7 guard gated community, with "rover" security cars going around the community 24x7.
 
I don't post anything on any social media sites. The only social media site where I have an account is on FB, but only keep it so that my friends can PM me and I can see what is going on in their lives. I have several friends who asked me to post something occasionally so that they know that I am alive. I told them to just PM me with that question instead. :)

Within the community where we live in, alot of folks have 2nd and 3rd homes and we know roughly when someone is away or not, snowbirds and sunbirds, or just plain extended travel. No one seems to be worried about break-ins. We also live in a 24x7 guard gated community, with "rover" security cars going around the community 24x7.
We had private security. He told me if I told him we were out of town, he’d drive slower past my house. LOL. Useless.
 
One of the things I think that is very important -- on smart phones you can go onto your phone app and toggle the silence unknown callers. I think in the latest update on iPhone IOS 26 it's not a slider anymore, it's a checkmark... at least it is on iPhone 16...

Silence unknown callers, they will still get the call, it will go straight through to voicemail. Anyone who needs to get in touch with them will leave a voicemail, scammers will not, they will just move onto the next person. You will have to update phone numbers and enter them into known contacts every once in a while. But at this point pretty much everybody I know, doesn't answer their phone anymore they answer voicemails.
I do still get a ton of scammer voicemails but It is much better using the setting you described.
 
It sucks that it happened, but this was part of the issue.

“ I was travelling and never noticed PayPal emails alerting me to the activity that resulted in the hack”

All the security in the world doesn’t help if we don’t do our part too.

I am not blaming the victim, just pointing out where the collapse could/should have been caught.
Really? You're not blaming the victim? Do you sleep with your phone next to your ear, and jump out of bed for every email you get? And even if you do, you're still screwed.

In five minutes, I received 8 emails from AOL on various security breeches, password changes, and email backup changes. And of 11 phone calls to AOL, the SOONEST they answered was 10 minutes. And even when they answer, they do NOTHING to help.

Tenant13 was diligent, but we can't be near our phones constantly. Just like we are not home 100% of the time, but we count on locks, cameras, and other items doing their best.

The fact is, these scammers and criminals are good. And until the FBI or someone in DOJ does something about it, this is going to continue in my opinion.
 
Last edited:
Really? You're not blaming the victim? Do you sleep with your phone next to your ear, and jump out of bed for every email you get? And even if you do, you're still screwed.

In five minutes, I received 8 emails from AOL on various security breeches, password changes, and email backup changes. And of 11 phone calls to AOL, the SOONEST they answered was 10 minutes. And even when they answer, they do NOTHING to help.

Tenant13 was diligent, but we can't be near our phones constantly. Just like we are not home 100% of the time, but we count on locks, cameras, and other items doing their best.

The fact is, these scammers and criminals are good. Andy until the FBI or someone in DOJ does something about it, this is going to continue in my opinion.
I have an Apple Watch and I get texts as well as emails when it involves security and yes I do sleep with my watch. You can do things via websites (if you are familiar with them) without making phone calls. You know that don’t you? If someone is hacking my accounts I am not going to sit on hold.
I also would move from AOL ASAP. They were cutting edge in 1993.
 
Last edited:
Really? You're not blaming the victim? Do you sleep with your phone next to your ear, and jump out of bed for every email you get? And even if you do, you're still screwed.

In five minutes, I received 8 emails from AOL on various security breeches, password changes, and email backup changes. And of 11 phone calls to AOL, the SOONEST they answered was 10 minutes. And even when they answer, they do NOTHING to help.

Tenant13 was diligent, but we can't be near our phones constantly. Just like we are not home 100% of the time, but we count on locks, cameras, and other items doing their best.

The fact is, these scammers and criminals are good. And until the FBI or someone in DOJ does something about it, this is going to continue in my opinion.
Agree. The relatively new technique is an absolute carpet bombing of the victim which creates a huge noise to signal ratio. And they choose their time wisely. While you are away. On a Saturday evening making it difficult to contact your bank. Overnight. It is very different than a simple credit card compromise.

These criminals are becoming very clever. They'd rather do this than physically break into your house - leave that to the meth heads.

Agree something has to be done.
 
Last edited:
I have an Apple Watch and I get texts as well as emails when it involves security and yes I do sleep with my watch.

Agree. The relatively new technique is an absolute carpet bombing of the victim which creates a huge noise to signal ratio. And they choose their time wisely. While you are away. On a Saturday evening making it difficult to contact your bank. Overnight. It is very different than a simple credit card compromise.

These criminals are becoming very clever. They'd rather do this than physically break into your house - leave that to the meth heads.

Agree something has to be done.
Thanks, it's pretty absurd to think that strapping my 88 year-old Mom with her Apple Watch at night, expecting her to read every text/email/notification in the dead of night, then leap out of bed to jump on some website to counteract sophisticated scammers has any chance in hell of working. She's lucky if she makes it to the bathroom in the middle of the night.
 
There are online solutions that do not require a phone call. You can revoke access from unauthorized devices, shut down third part apps, change a password, delete filters, etc.
I suggest everyone become familiar with the online security levers associated with their accounts and not rely on making a phone call to a likely clueless customer rep.
 
Thanks, it's pretty absurd to think that strapping my 88 year-old Mom with her Apple Watch at night, expecting her to read every text/email/notification in the dead of night, then leap out of bed to jump on some website to counteract sophisticated scammers has any chance in hell of working. She's lucky if she makes it to the bathroom in the middle of the night.
Going back to your OP you said you made numerous calls to AOL after coffee etc. So you had time to stop the damage, but kept calling instead of trying a different route. Your Mom didn’t need to react in the middle the night. By the morning probably would have stopped most of the damage.
 
So about those passkeys.

I'm flummoxed.

I guess I've been retired from tech too long. I don't get passkeys. I tried them, and it turned into a mess when trying to use my desktop. I like my desktop.

Passkeys seem very phone focused. I don't like to do my heavy lifting on the phone.

I'm going to let passkeys mature a bit more before I try them again. This attitude of mine may be a sign of the beginning of the end for me.
Passkeys work fine on my Win11 PC. There's no fingerprint sensor or facial recognition but the pin for the PC works for confirmation
 
So about those passkeys.

I'm flummoxed.

I guess I've been retired from tech too long. I don't get passkeys. I tried them, and it turned into a mess when trying to use my desktop. I like my desktop.

Passkeys seem very phone focused. I don't like to do my heavy lifting on the phone.

I'm going to let passkeys mature a bit more before I try them again. This attitude of mine may be a sign of the beginning of the end for me.
You’re right that not all sites that offer passkeys are easy to use. I have two banks that offer passkeys, but I don’t use them because they require using an app on the phone instead of a website. There are some sites where passkeys are easy to use. So, as passkeys become more common, they will accommodate more devices. I don’t think it’s a user-end issue.

On a side note, the way our phones and phone numbers have become central to our financial identities by default means that there’s no comprehensive approach to protect information. I can’t think a way out of it, but it seems like few have tried beyond a patchwork approach.
 
Great thread, though scary. I apologize for beating a dead horse, but it's a long thread and I may have missed that this has been discussed already. I'm still trying to get my head around passkeys. I recently had to put Mozilla Thunderbird on my ancient android phone because MS stopped playing with Samsung email. During the setup process, Outlook had me set up a passkey. The three options were photo, fingerprint, or a four digit PIN. I think I get the device-specific aspect of passkeys, but those don't really seem comparable levels of security to me. And if they are, why would anyone go to the trouble of facial recognition or fingerprint?
 
Passkeys work fine on my Win11 PC. There's no fingerprint sensor or facial recognition but the pin for the PC works for confirmation
I've got some learning to do. I've been putting it off, but it is time. I wonder if there is a site I can use to experiment and test with passkeys. The few times I tried activating them I was on a site that I needed, and then I had to scramble to get back in due to my incompetence in using the passkey.
 
Great thread, though scary. I apologize for beating a dead horse, but it's a long thread and I may have missed that this has been discussed already. I'm still trying to get my head around passkeys. I recently had to put Mozilla Thunderbird on my ancient android phone because MS stopped playing with Samsung email. During the setup process, Outlook had me set up a passkey. The three options were photo, fingerprint, or a four digit PIN. I think I get the device-specific aspect of passkeys, but those don't really seem comparable levels of security to me. And if they are, why would anyone go to the trouble of facial recognition or fingerprint?
I don’t see much trouble in setting up or using fingerprint or facial. I actually prefer it. They take seconds to set up and seconds to use.
 
I don’t see much trouble in setting up or using fingerprint or facial. I actually prefer it. They take seconds to set up and seconds to use.
No doubt they're easier for some than for me, but they can't be easier than a four digit pin, can they? An aside, DW tends to "doom scroll." When I discussed fingerprint passkeys, she claims she read that bad guys were cutting off people's fingers so they could "steal" the fingerprints. Glad I'm anonymous. 😄
 
No doubt they're easier for some than for me, but they can't be easier than a four digit pin, can they? An aside, DW tends to "doom scroll." When I discussed fingerprint passkeys, she claims she read that bad guys were cutting off people's fingers so they could "steal" the fingerprints. Glad I'm anonymous. 😄
The pins are easy, yes, but likely take longer to activate than a one second scan of my face. Plus someone can hack a pin. It’s harder to hack a face.

There are a host of things people can do to protect their accounts. Some chose not to use these or are unaware of them. The low hanging fruit gets hacked.

I will add that I average at least one hack attempt on one or more of my accounts every year and I have caught every one with the security features I have in place. The only thing that has happened to me in the last 10 years was someone got my credit card number but had the wrong expiration and CVC code. I got text notices of the two declined transactions, contacted my CC and they shut the card down and I had a new one in my hands in 24 hours.
 
The pins are easy, yes, but likely take longer to activate than a one second scan of my face. Plus someone can hack a pin. It’s harder to hack a face.....
I can't use finger prints or face id on my pc but my 6 digit pin that's located only on the pc seems pretty safe to me.
 
I can't use finger prints or face id on my pc but my 6 digit pin that's located only on the pc seems pretty safe to me.
Aren’t they intended for mobile devices? I use passkeys on my cell and tablet.
 
Is there some reason not to use them on pc if they work?
 
Is there some reason not to use them on pc if they work?
The question I have is can you? I don’t know the answer. I never had that option available when I had a PC, but it is super common on mobile. The finger and face technology already exists for mobile.
 
Just a quick reply to everyone who mentioned that I should have paid more attention to emails and/or text messages alerting me to "suspicious activity". I do but 80% of those alerts are scams that are to be avoided and certainly not used for clicking anywhere. And thanks to AI they look and sound better and better. I normally scrutinize them and check the accounts independently but in this case (because I was traveling, my bad... ) I just bulk deleted them. TBH, I blame PayPal for this mess.
 
Just a quick reply to everyone who mentioned that I should have paid more attention to emails and/or text messages alerting me to "suspicious activity". I do but 80% of those alerts are scams that are to be avoided and certainly not used for clicking anywhere. And thanks to AI they look and sound better and better. I normally scrutinize them and check the accounts independently but in this case (because I was traveling, my bad... ) I just bulk deleted them. TBH, I blame PayPal for this mess.
1,000% in my obsession on this issue, I found the following video last night. It's long, but start at 20 minute part. He is very much like you, and even more so.

He did his own sluething, and he discovered an employee at his mobile phone carrier SIM ported his number and a couple others on his last day at work 🤮🤮

Source: YouTube - YouTube
 
Back
Top Bottom