Earlier this year, I had two attempts to withdraw funds from different financial institutions within a couple of days of each other. The first was an annuity. The hacker submitted a withdrawal form either by fax or US mail. I discovered it when I got an email asking me to resubmit the request with the correct SS#. I informed the company that I did not submit the request and they immediately locked my account.
This may have been an inside job because I submitted a request to change beneficiaries a few days earlier which was the first time I had contacted the company since the annuities were setup 2 years ago. The hacker listed a NYC phone number and asked for the funds to be sent to a FL credit union.
The 2nd attempt was an online request to a credit union where I hold CDs in VA. I was informed via email that they had received my request to withdraw funds. I contacted the CU immediately and informed them that I did not request an early withdrawal of funds. They had me set up a verbal passphrase which I must use anytime I contact them via phone. I learned that the person who gained access to my account called claiming to have “forgot” my password. The CU authenticated them using my personal identity information which I believe this person obtained on the darkweb.
After receiving the email, I was able to logon to my account but discovered that an unknown phone number had been added and my mobile number was deleted. I was able to reset my id/password using my landline, added my mobile phone number and deleted the unknown phone number. Once I informed the CU, they locked the account. One person at the CU said the PID for the online request came from either NY or CT. The annuity company is in NYC and the CU is in VA.
I reported this to my investment company. They thought my PC had been hacked. They transferred me to their security people who reviewed my security. They said my security was very sound. I got limited information from the two companies where the hacks were attempted. My annuity account is still locked which is fine because I plan to hold my annuities until maturity. I will still need to use my verbal password with the CU which is a minor inconvenience. I wonder how many other people are vulnerable to someone gaining access to their accounts using personal identity information obtained from the dark web?
I use strong passwords and non obvious ids for logon to sensitive accounts, so I am unclear how someone got into this annuity account, although I suspect an inside job. I am a widower and live alone. I have not shared my logon credentials with anyone. I use 2 factor authentication or better wherever possible.
I use Malwarebytes Premium and a top tier security product and do scans daily. No suspicious activity has been detected.
I have tightened my already tight accounts by setting text and/or email notifications for any changes or activity with my accounts.
The person attempting to hack my CU CDs must have used my personal identity information that is readily available on the dark web, including my SS#. I discovered that a large amount of information had been recently made available on the dark web that included some of my personal identity information.
Given this reality, I think that I and others need to assume that fraudsters can easily obtain our personal identity information on the dark web. There have been too many hacks of information from companies that we all use to assume otherwise. We need to do the things that are necessary to prevent damage to our identity and accounts. For example, freezing our credit which is easy to do. Also, setting alerts for all financial activity, monitoring account activity, using two factor authentication or other higher levels of authentication. I have considered switching to a password manager but have never pulled the trigger on that although I probably should.
Is your personal identity information for sale on the dark web?
Excellent article in Washington post
https://www.washingtonpost.com/home/2026/09/21/how-protect-yourself-fraud-scammers/
Free Newsletter
Arrives weekly.